What does user entities mean on the CPA exam?
User entities. The customers of a service organization, whose own financial reporting or systems depend on the service organization's controls. They are the audience for a SOC report.
Defined against AU-C 402.08.
Which CPA exam sections use user entities?
User entities appears in the ISC section of the CPA exam.
Other terms defined against AU-C 402
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- user auditor: The auditor of an entity that uses a service organization.
Related terms
- complementary user entity controls: Controls a service organization assumes its customers are running.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.
- inclusive method: Brings a subservice organization's controls inside the description and the scope of the service auditor's report, so one report covers both organizations.
- reporting entity: The unit whose statements are being presented, including everything it controls.