Skip to content

Outsourced Accounting Functions

VIVA Subject Guide
YouTube video

1 Introduction

Outsourcing can be defined as:

Hiring a party outside the organisation to perform services and to create goods that would otherwise be performed internally by the organisation’s own employees.

Outsourcing is often accompanied by off-shoring where the outsourced function is provided by a supplier based overseas.

Examples of outsourcing functions include:

  • Logistics (eg delivery of products to customers)

  • Marketing

  • Recruitment

  • Legal services

  • Production/assembly

  • Information technology (facilities management)

  • Receivables ledger management (factoring)

  • Tax planning and calculations

  • Payroll

  • Accounting

  • Internal audit

This chapter deals particularly with the last six functions on this list.

2 Potential advantages and disadvantages of outsourcing

Advantages

  • Access to specialist expertise

  • Reduction in cost with efficiency gains

  • Flexibility in responding to uneven demand

  • Greater cost certainty through fixed-fee arrangements

  • Transfer of risk

  • Unburdens management from having to closely manage the out-sourced function (though the process of out-sourcing does itself have to be managed).

  • For internal audit, greater independence.

Disadvantages

  • Loss of control

  • Damage to reputation if the outsource company does not perform well

  • Difficult to reverse (and hence, prices can be steep because the outsource company knows this)

  • Lack of responsiveness to new requirements

  • Different aims of the outsourcer and the outsource company leading to a lack of goal congruence

  • Confidentiality. Company and client data are held by another party.

3 Impact on the audit

Often, the outsource company (the service company) simply becomes a supplier. For example, outsourcing delivery of products to a logistics company will have little effect on audit work. However, if IT and finance functions are outsourced that means that the financial information, records and processing are controlled by a third party and this will have implications for the audit. The auditor cannot ignore what happens to the client's data at the service company. For example, when assessing the valuation of receivables, the auditor would typically examine the client’s aged receivables analysis and ensure that it was properly prepared so that it could be used reliably (e.g. to evaluate the adequacy of an allowance for credit losses). If a service provider, such as a factor, produces that analysis instead, the auditor simply cannot assume that it has been prepared correctly and base the carrying amount of receivables on that.

The auditor needs an understanding of the processing and maintenance of client data by the service organisation to be able to draw conclusions about the risk of material misstatement. There are two situations:

  1. The service company simply processes client’s transactions. Here, the client should be able to implement its own controls (e.g. comparing output against input to ensure all transactions processed).

  2. The service company additionally executes and takes responsibility for the client’s transactions. Then the client company will have to rely on the controls and procedures within the service company.

The auditor can obtain the required understanding and audit evidence through:

  • A contract or service agreement between the audit client and service organisation.

  • User manuals and/or technical manuals.

  • Reports by the service organisation (eg internal auditor’s reports).

  • Reports by the service auditor (such as letters highlighting internal control weaknesses).

  • Knowledge derived from previous dealing with the service organisation (eg was it reliable in the past).

  • Comparing data submitted to the service company to information and data received back.

If the above sources of information available from the client are not sufficient, the auditor may, for example:

  • Obtain and assess a Type 1 or Type 2 Report (see below).

  • Ask the service organisation for information.

  • Visit (with permission) the service organisation and carry out audit procedures there.

  • Use (with permission) another auditor to cary out audit procedures at the service organisation.

ISA 402 Audit Considerations Relating to an Entity Using a Service Organisation, describes two types of report:

  • A Type 1 report comprises:

A description, prepared by the management of the service organisation about the service company’s control objectives and related controls that have been implemented.

A report prepared by the service auditor giving reasonable assurance on the suitability of the service company’s systems and control objectives.

  • A Type 2 report comprises:

A description, prepared by the management of the service organisation about the service company’s control objectives and related controls that have been implemented and sometimes a description of their operating effectiveness.

A report prepared by the service auditor giving reasonable assurance on the suitability of the service company’s systems and control objectives, the effectiveness of the controls and a description of the service auditor’s tests of the controls and the results of those tests

So only a Type 2 report provides assurance on the effectiveness of the service organisation's controls.

The auditor can also ask management about problems and irregularities in the service company’s work.

If the auditor cannot obtain sufficient appropriate evidence about the quality and reliability of the processing being carried on by the service organisation, then the audit opinion will have to be modified.