8.4 Service Auditor vs. User Auditor Responsibilities

Key Takeaways

  • The service auditor is engaged by the service organization to examine controls under AT-C 320/SSAE 18, while the user auditor is engaged by the user entity to audit financial statements under AU-C 402.
  • Prior to relying on a SOC 1 Type 2 report, the user auditor must evaluate the service auditor's professional competence, independence, and the professional standards governing the examination.
  • Under AU-C 402 and AU-C 700, the user auditor is strictly prohibited from referring to the service auditor's report in an unmodified (clean) financial statement audit opinion, as doing so would improperly imply a division of responsibility.
  • When a timing gap (stub period) exists between the SOC 1 report period-end and the user entity's fiscal year-end, the user auditor must obtain a Bridge Letter (Gap Letter) issued and signed exclusively by service organization management, not the service auditor.
  • If the stub period exceeds 3 to 6 months, or if material control changes occurred during the gap, a bridge letter alone is insufficient, requiring the user auditor to perform direct procedures at the service organization or expand substantive audit testing.
Last updated: September 2026

Service Auditor vs. User Auditor Responsibilities

Quick Summary: In outsourced financial processing environments, audit responsibilities are divided between two independent CPA practitioners: the service auditor (who examines controls at the service organization under AT-C 320) and the user auditor (who audits the user entity's financial statements under AU-C 402). When evaluating a SOC 1 Type 2 report, the user auditor must independently assess the service auditor's competence and independence, test Complementary User Entity Controls (CUECs), and evaluate any timing misalignments. When a "stub period" separates the SOC report end-date from the user entity's fiscal year-end, the user auditor obtains a management-signed Bridge Letter, while adhering to the absolute prohibition against referencing the service auditor in an unmodified audit opinion.


1. Conceptual Framework & Role Differentiation

A common area of confusion for CPA candidates is conflating the professional obligations of the two independent auditors involved in SOC 1 reporting. Each practitioner operates under distinct standards, answers to a different client, and executes a unique scope of work:

                          SERVICE AUDITOR VS. USER AUDITOR

                SERVICE AUDITOR                         USER AUDITOR
   ┌─────────────────────────────────────┐   ┌─────────────────────────────────────┐
   │ Standard: SSAE 18 / AT-C 320        │   │ Standard: AICPA GAAS / AU-C 402     │
   │ Client: Service Organization        │   │ Client: User Entity                 │
   │ Objective: Examine design and       │   │ Objective: Audit annual historical  │
   │ operating effectiveness of controls │   │ financial statements (Form 10-K)    │
   │ Output: SOC 1 Type 2 Report         │   │ Output: Financial Audit Opinion     │
   │ Reliance: Examines vendor directly  │   │ Reliance: May rely on SOC 1 report  │
   │ Distribution: Restricted under      │   │ Distribution: Public or Private     │
   │ AU-C 905                            │   │ Financial Statement Users           │
   └─────────────────────────────────────┘   └─────────────────────────────────────┘

Master Role Comparison Matrix

Engagement DimensionIndependent Service AuditorIndependent User Auditor
Governing StandardSSAE 18 / AT-C Section 320 (Attestation Standards)AICPA GAAS / AU-C Section 402 (Auditing Standards)
Who Engages the Auditor?Management of the service organizationAudit committee / board of the user entity
Subject Matter ExaminedInternal controls at the service organization relevant to user ICFRAnnual historical financial statements of the user entity
Primary Work ProductSOC 1 Examination Report (Type 1 or Type 2)Independent Auditor's Report on Financial Statements
Evaluation of Other AuditorsNone (evaluates subservice organizations if using inclusive method)Must evaluate professional competence, reputation, and independence of service auditor
Responsibility for Financial StatementsZero. Assumes no responsibility for user entity financial balancesSole Responsibility. Retains full, undivided responsibility for the audit opinion

2. AU-C 402: The User Auditor's Audit Decision Workflow

When a corporate client outsources operational functions to a third-party service bureau, the user auditor cannot simply ignore the outsourced operations. Under AU-C 402, the user auditor must execute a structured decision protocol:

                        AU-C 402 USER AUDITOR DECISION WORKFLOW

        Step 1: Obtain an understanding of outsourced services
        • Are services part of the user entity's information system relevant to ICFR?
        • What transaction classes, records, and accounts are affected?
                         │
                         ▼
        Step 2: Assess interaction and user entity internal controls
        • Can the user entity monitor and reconcile all transactions internally?
        • (e.g., Reconciling independent bank statements against outsourced ledger)
                         │
          ┌──────────────┴──────────────┐
          ▼                             ▼
     YES (Sufficient)              NO (Insufficient Evidence)
     User auditor tests            User auditor must obtain evidence
     internal user controls;       regarding controls at the service org
     No SOC 1 needed               (Step 3)
                                        │
                                        ▼
        Step 3: Execute service organization audit procedures
        • Primary Option: Obtain and evaluate a SOC 1 Type 2 Report
        • Alternative Option A: Perform tests of controls directly at service org
        • Alternative Option B: Engage another practitioner to test service org controls

In modern corporate practice, performing on-site audits at third-party vendors is commercially impractical. Consequently, obtaining a SOC 1 Type 2 report represents the standard mechanism for satisfying AU-C 402 requirements.


3. Due Diligence: Evaluating the Service Auditor and the SOC 1 Report

A user auditor is legally and professionally prohibited from blindly accepting a SOC 1 report. AU-C 402 mandates that the user auditor perform rigorous due diligence across eight critical dimensions:

  1. Professional Competence and Reputation: The user auditor must verify that the service auditor is a licensed, reputable CPA firm in good standing. This involves checking state licensing boards, inspecting the firm's most recent AICPA Peer Review report, and confirming membership in professional organizations.
  2. Practitioner Independence: The user auditor must confirm that the service auditor is independent of both the service organization and the user entity in accordance with the AICPA Code of Professional Conduct.
  3. Adequacy of Standards: The user auditor must verify that the report was issued under appropriate professional attestation standards (SSAE 18 / AT-C 320 in the United States, or ISAE 3402 internationally).
  4. Alignment of Scope: The user auditor must verify that the systems, applications, data centers, and modules described in Section III match the exact services utilized by the user entity during the audit period.
  5. Period Coverage and Timing: The user auditor must assess whether the period examined by the service auditor overlaps sufficiently with the user entity's financial reporting period.
  6. Complementary User Entity Controls (CUECs): The user auditor must test the user entity's implementation of CUECs. If the service organization's controls assume that the client reconciles monthly reports, and the client failed to do so, the service organization controls cannot be relied upon.
  7. Subservice Organization Treatment: The user auditor must check whether the service organization utilized the carve-out method or inclusive method. If carve-out was used, the user auditor must evaluate whether Complementary Subservice Organization Controls (CSOCs) are relevant and tested separately.
  8. Evaluation of Test Exceptions: The user auditor must examine Section IV for deviations. If exceptions occurred, the user auditor determines whether compensating controls mitigated the risk or if substantive testing at the user entity must be expanded.

[!IMPORTANT] The CUEC Audit Requirement: A common CPA exam scenario presents a service organization that received a completely unmodified (clean) SOC 1 Type 2 report. However, during the user entity's audit, the user auditor discovers that the client never performed the monthly transaction reconciliations listed as CUECs in Section III. In this case, the user auditor cannot rely on the service organization's controls. Internal control is a shared responsibility; failure of user-side controls negates the assurance provided by the SOC report.


4. The "Stub Period" Dilemma and Management Bridge Letters

In financial statement audits, a frequent operational challenge is the timing misalignment between the service organization's SOC report reporting cycle and the user entity's fiscal year.

The Stub Period Defined

Consider a user entity with a fiscal year spanning January 1, 2026 to December 31, 2026. The service organization provides a SOC 1 Type 2 report covering October 1, 2025 to September 30, 2026.

  • The three-month period from October 1, 2026 to December 31, 2026 represents the stub period (also termed the gap period).
  • During these three months, the service auditor performed no audit procedures.
                           THE STUB PERIOD / GAP LETTER TIMELINE

    Jan 1, 2026                   Sep 30, 2026                   Dec 31, 2026
         ├──────────────────────────────┼──────────────────────────────┤
         │◄───── 9 Months Covered ─────►│◄────── 3-Month Gap ─────────►│
         │     by SOC 1 Type 2 Report   │       ("Stub Period")        │
         │    (Tested by Service CPA)   │  Covered by Management       │
         │                              │       BRIDGE LETTER          │
         ▼                              ▼                              ▼
    User Entity                    SOC Report                     User Entity
     Fiscal Year                   Period-End                     Fiscal Year
      Begins                                                        End-Date

The Bridge Letter (Gap Letter) Architecture

To bridge the gap between the SOC report end-date and the user entity's balance sheet date, the user auditor requests a formal Bridge Letter (or Gap Letter).

  • Who Issues the Bridge Letter? The Bridge Letter is authored and signed EXCLUSIVELY BY MANAGEMENT OF THE SERVICE ORGANIZATION.
  • The Service Auditor Never Signs a Bridge Letter: The independent service auditor never issues, signs, or co-signs a Bridge Letter! The service auditor has not conducted audit procedures during the stub period and professional standards strictly forbid a CPA from attesting to periods they have not examined.

Core Representations in a Bridge Letter

In the Bridge Letter, service organization management formally warrants to the user entity and user auditor that:

  1. The internal controls described in the SOC 1 Type 2 report have continued to operate effectively throughout the stub period.
  2. No material modifications, architectural shifts, or major disruptions have occurred in the system infrastructure, software, or operating policies.
  3. No significant control failures, security compromises, data breaches, or regulatory enforcement actions have occurred during the intervening period.

User Auditor Evaluation of the Stub Period Duration

  • Short Gap (1 to 3 Months): If the stub period is 3 months or less, the SOC report covers the majority of the fiscal year, a clean bridge letter is received, and user entity monitoring controls show no errors, the user auditor can generally conclude that control risk remains low.
  • Extended Gap (4 to 6+ Months): A bridge letter alone is insufficient for an extended gap. Management representations cannot substitute for audit testing over a substantial portion of the reporting year. The user auditor must perform additional procedures: interviewing service organization personnel, testing user-side monitoring controls, or performing expanded substantive transaction testing.

5. AU-C 402 Rule on Reference to the Service Auditor

One of the most heavily tested, non-negotiable rules in AICPA auditing standards governs whether the user auditor can mention the service auditor in the financial statement audit opinion:

                     AU-C 402 RULE ON REFERENCING THE SERVICE AUDITOR

                 What type of audit opinion is the User Auditor issuing
                         on the client's financial statements?
                                          │
                         ┌────────────────┴────────────────┐
                         ▼                                 ▼
                UNMODIFIED OPINION                 MODIFIED OPINION
                     (Clean)                     (Qualified / Adverse)
                         │                                 │
                         ▼                                 ▼
               STRICT PROHIBITION                CONDITIONAL PERMISSION
             The user auditor SHALL             User auditor MAY reference
            NOT refer to the service            the service auditor ONLY if
            auditor in the report!              necessary to explain the
            (Implies divided responsibility)    basis for modification

The Unmodified Opinion Absolute Prohibition

Under AU-C 402.21 and AU-C 700, the user auditor SHALL NOT refer to the work of the service auditor in a financial statement audit report containing an unmodified (clean) opinion.

  • Rationale: The user auditor bears sole, undivided responsibility for the audit opinion expressed on the financial statements. Referring to the service auditor would improperly imply a division of responsibility between two CPA firms, misleading financial statement readers into believing the user auditor is disclaiming responsibility for outsourced financial processing.

The Exception for Modified Opinions

Under AU-C 402.22, if the user auditor issues a modified opinion (a qualified opinion, adverse opinion, or disclaimer of opinion) because:

  • The user auditor was unable to obtain sufficient appropriate audit evidence regarding the service organization (a scope limitation); or
  • The service auditor identified material control breakdowns that caused undetected material misstatements at the user entity; the user auditor may refer to the service auditor, but only if such reference is essential to explain the reason for the audit modification. Even in this scenario, the user auditor must explicitly state in the report that the reference does not diminish the user auditor's sole responsibility for the audit opinion.

6. Practical Exam Scenarios & Core Exam Traps

Practical Scenario 1: The Misattributed Bridge Letter

During an audit of an investment management firm, the user auditor notes a four-month gap between the custodian's SOC 1 Type 2 report date and the client's fiscal year-end. The user auditor requests that the service auditor draft, sign, and issue an official bridge letter guaranteeing that no control failures occurred.

  • Auditor Evaluation: The service auditor must refuse. Service auditors do not issue bridge letters. Management of the investment custodian is the sole party authorized to execute a bridge letter. If the user auditor requires independent CPA assurance over the stub period, the custodian must engage the service auditor to perform a separate examination engagement or extend the testing period.

Practical Scenario 2: Sharing Responsibility in the Audit Report

A user auditor completes the audit of a regional bank. Because 60% of the bank's transaction volume is processed by an outsourced core banking service organization, the engagement partner inserts a paragraph into the clean audit opinion stating: "We relied upon the examination report of Firm X, CPAs, who audited the internal controls of the core banking service bureau, and our opinion is based solely on their testing results for core loan processing."

  • Auditor Evaluation: This is a direct violation of AU-C 402. A user auditor cannot refer to the service auditor in an unmodified opinion. The partner's wording improperly attempts to divide audit responsibility, rendering the audit report defective under AICPA professional standards.

Summary of Common Exam Traps

ConceptCorrect CPA UnderstandingCommon Exam Distractor / Trap
Bridge Letter SignerAuthored and signed EXCLUSIVELY by service organization management.Believing the service auditor signs or co-signs the bridge letter.
Report ReferenceStrictly prohibited in unmodified opinions; permitted in modified opinions only to explain the modification.Claiming the user auditor must always disclose the service auditor's identity in the audit report footnotes.
Divided ResponsibilityFinancial statement audits involving service organizations NEVER involve divided responsibility under AU-C 402.Confusing AU-C 402 (no division of responsibility) with AU-C 600 group audits (where component auditors can be referenced).
CUEC EnforcementA clean SOC report is ineffective if the user entity fails to implement and test its CUECs.Assuming that an unmodified SOC 1 report exempts the user auditor from testing any user entity internal controls.
Loading diagram...
Timeline and Alignment: SOC 1 Period, Stub Period, Bridge Letter, and Fiscal Year
Test Your Knowledge

During the annual audit of a corporate client's financial statements, the user auditor relies on a SOC 1 Type 2 report issued by an independent service auditor to test controls over outsourced inventory warehousing. The user auditor determines that all controls operated effectively and issues an unmodified (clean) opinion. How should the user auditor reference the service auditor in the financial statement audit report?

A
B
C
D
Test Your Knowledge

A user entity has a calendar fiscal year-end of December 31, 2026. The service organization providing its core investment accounting platform issues a SOC 1 Type 2 report covering the period from November 1, 2025 to October 31, 2026. Which of the following procedures is most appropriate regarding the two-month stub period?

A
B
C
D
Test Your Knowledge

Which of the following entities is legally and professionally authorized to issue and sign a Bridge Letter (Gap Letter) covering a stub period between a SOC report period-end and a user entity's fiscal year-end?

A
B
C
D