What does user auditor mean on the CPA exam?
User auditor. The auditor of an entity that uses a service organization. Distinct from the service auditor, who reports on the service organization's own controls.
Defined against AU-C 402.08.
Which CPA exam sections use user auditor?
User auditor appears in the ISC section of the CPA exam.
Other terms defined against AU-C 402
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- user entities: The customers of a service organization, whose own financial reporting or systems depend on the service organization's controls.
Related terms
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.
- complementary user entity controls: Controls a service organization assumes its customers are running.
- inclusive method: Brings a subservice organization's controls inside the description and the scope of the service auditor's report, so one report covers both organizations.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- internal audit: An in-house function that evaluates controls and processes and reports to those charged with governance.
- performance obligation: A promise in a contract to transfer a distinct good or service.