Back to all articles
Systems Governance

Third-Party Assurance: What to Ask When Your Finance Processes Sit Outside the Business

Outsourced payroll, cloud accounting and managed IT do not outsource your control responsibility. Here is how to evidence it.

Growth-stage businesses outsource more of the finance function than they realise. Payroll runs through a bureau. The ledger sits in a cloud platform. Infrastructure is managed by a third party. Expenses, banking and reporting all depend on providers the business does not control.

The accounting responsibility does not transfer with the process. If a service provider makes an error, it is still your misstatement, and the auditor will still ask how management gained comfort.

The question auditors actually ask

For any process performed by a service organisation, the auditor needs to understand the controls at that organisation and whether they can rely on them. In practice they will ask one of three things: is there a service auditor report, and what does it cover; if not, what controls does management perform over the provider; or can we test the underlying transactions directly?

If management has no answer, the audit becomes a substantive exercise, which is slower and more expensive.

Service auditor reports and what they do not cover

Providers may hold an ISAE 3402, SOC 1 or SOC 2 report. These are useful, but three points are routinely missed.

First, coverage period. A report covering a period that does not align with your financial year leaves a gap you must bridge.

Second, scope. A SOC 2 focused on security says little about the accuracy of a payroll calculation. Read what was actually tested.

Third, complementary user entity controls. Every report lists controls the provider assumes you perform. If you do not perform them, the provider's assurance does not carry. This section is the most commonly ignored part of the report and the most commonly raised in audit.

When there is no report

Most SME providers do not hold one. That is workable, provided management performs and evidences its own controls over the service. Typically:

  • Reconciliation of provider output to internal records each period.
  • Review of a sample of underlying calculations, not just the totals.
  • Authorisation of inputs before they are sent to the provider.
  • Review of exception and error reports from the provider.
  • Confirmation that access to the provider's platform is restricted to current staff.

The evidence requirement is the same as for any internal control: who did it, when, what they looked at, and what they did about differences.

Access is the gap nobody owns

When a process moves outside the business, user access tends to follow. Provider platforms accumulate accounts for people who left, consultants who finished, and generic logins shared during implementation.

Include every material third-party platform in the periodic access review. Auditors treat externally hosted financial systems exactly as they treat the ERP.

Building a provider register

A single register listing each provider, the process performed, the financial statement areas affected, whether assurance exists, the review controls management performs and the person who owns the relationship answers most audit questions in one document.

It also makes an uncomfortable point visible: how much of the financial reporting process depends on organisations the business cannot direct.

Practical next step

List the providers touching payroll, banking, revenue billing and the general ledger. For each, write down how you would prove to an auditor that the output was accurate this month. The ones where you cannot answer are the ones to fix first.