SOC Audit Procedures and Evidence Gathering 3 — Questions and Answers
Question 1: What is the primary purpose of an auditor obtaining a management representation letter in a SOC engagement?
- To replace the need for other substantive procedures
- To obtain written confirmation of management's assertions and disclosures made during the audit (Correct answer)
- To document the service auditor's independence
- To satisfy the requirement for third-party confirmations
Correct answer: To obtain written confirmation of management's assertions and disclosures made during the audit
A management representation letter is written evidence confirming statements management made verbally during the engagement.
Question 2: When an auditor traces a transaction from its origination through the system to the final record, this technique is called:
- Vouching
- Tracing (Correct answer)
- Confirmation
- Walk-through
Correct answer: Tracing
Tracing follows a transaction forward from source documents through the system to ensure completeness of recording.
Question 3: What is 'vouching' as an audit procedure in a SOC engagement?
- Selecting a recorded item and tracing it back to its source document to verify occurrence (Correct answer)
- Selecting a source document and tracing it forward to the final record
- Confirming balances with third parties
- Observing a control being performed in real time
Correct answer: Selecting a recorded item and tracing it back to its source document to verify occurrence
Vouching selects a recorded transaction and traces it back to supporting documents to confirm it actually occurred.
Question 4: Which of the following is a characteristic of 'sufficient' audit evidence under attestation standards?
- The evidence must come exclusively from external sources
- There is enough of it to support the auditor's conclusion (Correct answer)
- It must be obtained through observation procedures
- It must be documented in the working papers before any testing begins
Correct answer: There is enough of it to support the auditor's conclusion
Sufficiency refers to the quantity of evidence — enough must be gathered to support the auditor's conclusion.
Question 5: An auditor discovers that change management logs for a cloud service provider are incomplete for two months of a six-month review period. What should the auditor do first?
- Issue a qualified opinion immediately
- Inquire with management about the gap and seek alternative evidence (Correct answer)
- Expand the sample for the remaining four months
- Terminate the engagement
Correct answer: Inquire with management about the gap and seek alternative evidence
The auditor should first inquire with management and seek alternative evidence before concluding on the impact of the gap.
Question 6: Which evidence type is generally considered most reliable in a SOC audit?
- Oral responses from management during interviews
- Documents created internally and provided by management
- Externally generated documents obtained directly by the auditor (Correct answer)
- Screenshots emailed to the auditor by a system administrator
Correct answer: Externally generated documents obtained directly by the auditor
Evidence obtained directly from external sources is most reliable because it has not passed through the service organization's hands.
Question 7: In attribute sampling used during a SOC audit, the 'tolerable deviation rate' represents:
- The percentage of controls that may fail and still receive an unmodified opinion
- The maximum rate of deviations from a control procedure the auditor is willing to accept (Correct answer)
- The expected error rate in the financial statements
- The minimum sample size required by AICPA standards
Correct answer: The maximum rate of deviations from a control procedure the auditor is willing to accept
The tolerable deviation rate is the highest acceptable rate of control failures before the auditor concludes the control is ineffective.
What is the primary purpose of an auditor obtaining a management representation letter in a SOC engagement?