Welcome to Planning for and Using the Work of Others!

Hello future CPAs! Today, we are diving into a crucial part of Area II: Assessing Risk and Developing a Planned Response. As an auditor, you are a superhero, but even superheroes need a team. You can’t be an expert in everything—from the valuation of a diamond mine to the complex coding of a global payroll system. That is why we use the work of "others."

In this chapter, we will learn how to properly plan for and use the work of Internal Auditors, Specialists, and Service Organizations. The goal is to make your audit more efficient without sacrificing quality. Don't worry if this seems like a lot of responsibility; we'll break it down step-by-step!

1. Using the Work of an Auditor's Specialist

Sometimes, the evidence we need is outside the world of "debits and credits." If you need to value a Picasso painting held by a museum or estimate the remaining oil in an underground well, you need an Auditor’s Specialist.

Who are they? They are experts in a field other than accounting or auditing (e.g., appraisers, engineers, actuaries, or geologists).

How to Evaluate a Specialist

You can't just pick anyone off the street. You must evaluate three things (Memory Aid: "C-C-O"):
1. Competence: Do they have the right certifications and experience?
2. Capability: Do they have the time and resources to do this specific job?
3. Objectivity: Are they independent? If the specialist is the CEO’s brother, that’s a red flag!

Working with the Specialist

You must have a written agreement with them. Think of it like a "contract" that covers:

  • The nature, scope, and objectives of their work.
  • The roles and responsibilities of both the auditor and the specialist.
  • The communication style (how will they report findings to you?).
  • The need for confidentiality.

Important Rule: Even though you used a specialist, YOU (the auditor) are solely responsible for the audit opinion. You should not mention the specialist in an unmodified (clean) opinion unless required by law. You only mention them if their work leads you to modify your opinion (like a qualified or adverse opinion).

Quick Review: An auditor's specialist helps with non-accounting matters. You check their C-C-O and you remain 100% responsible for the final report.

2. Using the Work of Internal Auditors (IA)

Most large companies have their own Internal Audit department. They are employees of the client, but they spend their days testing controls and checking for errors. Why do the same work twice if they’ve already done it?

Two Ways to Use Internal Auditors

1. Use their existing work: You look at the reports they have already finished during the year.
2. Direct Assistance: You ask them to help you perform specific audit procedures under your supervision.

Can We Trust Them?

Before using them, you must assess:
1. Objectivity: Who do they report to? If they report to the CFO (the person whose work they are checking), they aren't very objective. They should ideally report to the Audit Committee.
2. Competence: Are they professionally qualified (e.g., CIAs or CPAs)? Do they have a good training program?
3. Systematic and Disciplined Approach: Do they use checklists and documented procedures?

What Can They NOT Do?

Internal auditors are not independent. Therefore, you cannot let them make "high-stakes" decisions.
Common Mistake to Avoid: Never let internal auditors make judgments about:

  • Significant accounting estimates.
  • The assessment of Inherent Risk or Control Risk.
  • Materiality levels.
  • The "sufficiency" of tests performed.

Analogy: Think of an Internal Auditor like a student teacher. They can help grade multiple-choice quizzes (routine tasks), but the Lead Teacher (the External Auditor) must be the one to grade the final essays and decide the final grade (judgmental tasks).

Key Takeaway: The more judgment involved, the less you should rely on internal auditors. Always supervise and test their work!

3. Using a Service Organization (SOC Reports)

Many clients "outsource" parts of their business. For example, a small company might hire ADP to handle their payroll or Amazon Web Services (AWS) to host their data.

If the outsourced service is part of the client's Information System (meaning it affects their financial statements), you as the auditor need to know if the controls at that outside company are working. But you can't just fly to ADP headquarters and start auditing them! Instead, you use a SOC Report.

The Two Main Types of SOC 1 Reports

1. SOC 1, Type 1 Report: This reports on the design of the controls at a specific point in time. It tells you if the controls "look good on paper."
Does it help you reduce Control Risk? No. It only helps you understand the system.

2. SOC 1, Type 2 Report: This reports on the design AND operating effectiveness of the controls over a period of time (usually 6 months).
Does it help you reduce Control Risk? Yes! This report provides evidence that the controls actually worked.

Did you know? "SOC" stands for System and Organization Controls. When you are the auditor of the client, you are called the User Auditor. The auditor who audits the service organization (like ADP) is called the Service Auditor.

Quick Review: If your client outsources payroll, look for a SOC 1 Type 2 report to see if you can rely on their controls.

4. Summary of Planning and Using Others

When planning your response to risks, using others is a great way to be efficient, but it requires careful oversight.

Summary Table for the Exam:

Internal Auditors: Assess Objectivity & Competence. Use for routine tasks, NOT for high-judgment areas.
Auditor’s Specialist: Assess C-C-O (Competence, Capability, Objectivity). Agree on scope in writing.
Service Auditor: Use SOC 1 Type 2 reports to get evidence that outsourced controls are working.

Final Word of Encouragement: Audit planning is like a puzzle. Using the work of others is just finding the right pieces to fit into the big picture. You've got this! Keep practicing those multiple-choice questions on SOC reports—they are a favorite on the CPA exam!