Search
Program Calendar
Browse By Day
Search Tips
Virtual Exhibit Hall
Personal Schedule
Sign In
A Service Organization Control (SOC) engagement is an information technology (IT) intensive assurance engagement where auditors identify and assess risks that threaten SOC objectives. Auditors can identify and assess an IT risk then subsequently dedicate audit budget hours to IT specialist to perform tests associated with the IT risk. Alternatively, auditors could initially delegate the identification and assessment of IT risk, in addition to the associated testing, to IT specialists. The direct labor costs of auditors, however, tend to be lower than the direct labor costs of IT specialist. If auditors could demonstrate that they could identify and assess IT risks just as well as IT specialists, audit firms could reduce the costs of SOC engagements by allowing auditors to identify and assess IT risks. I investigate whether specialized domain experience and the influence of nondiagnostic evidence affect auditors’ ability to identify risks that threaten control objectives. I conduct a repeated-measures experiment in the post-SOX era where fifty auditors assess an IT risk with and without nondiagnostic evidence. I use the IT risk assessments of thirty-seven IT specialists as a control to analyze auditors’ IT risk assessments. I find that auditors assess risk best when they have specialized domain experience. However, auditors’ assessments of IT risk are not significantly different than the IT risk assessments provided by IT specialists. These results suggest that auditors may do just as well as IT specialists in identifying IT risk during SOC engagements. Thus, firms may be able to reduce the cost of SOC engagements by budgeting IT risk identification tasks to their auditors instead of their IT specialists. Firms could then use IT specialists to test controls specific to the identified risk.