ICAEW Registered Auditors  ·  90+ UK-Based Experts

AAF Reports: Assurance for Clients You Will Never Meet

AC
Acumon Chartered Accountants ·4 min read

When a pension trustee outsources administration, or an asset manager hands custody to a third party, somebody has to give them comfort that the provider's controls actually work. Sending a hundred clients a hundred separate audit teams is unworkable. The answer is a controls report — AAF in the UK, ISAE 3402 internationally, SOC 1 in the United States — in which a reporting accountant examines the provider's controls once and issues a report every client can rely on.

What an AAF report is

AAF reports follow the ICAEW's Audit and Assurance Faculty guidance, and the most widely used is AAF 01/20, which covers internal controls at service organisations. The report contains three things: the service organisation's own description of its systems and control objectives, a statement by its directors that the description is fair and the controls were suitably designed, and the reporting accountant's opinion on whether the controls operated effectively throughout the period.

Two types exist, and the difference is the whole point. A type 1 report covers the design of controls at a point in time. A type 2 covers both design and operating effectiveness across a period, normally twelve months, with testing evidence behind each control objective. A type 1 is a starting position for a new service line; a type 2 is what an institutional client actually wants, and a provider offering only a type 1 in year three will be asked why.

ISAE 3402 does the same job under an international standard and is more familiar to overseas clients; SOC 1 is the US equivalent. Many providers issue against more than one framework, and the underlying testing is largely common.

Who needs one

The trigger is almost always commercial rather than regulatory. Pension scheme administrators and investment platforms are the classic populations — trustees and their auditors need assurance over the records they rely on. Fund administrators, custodians, payroll bureaux, managed IT and cloud providers, and outsourced finance providers increasingly find that large clients will not contract without one.

The economics are straightforward: one report, produced annually, replaces client-by-client due diligence visits that cost more in disruption than the report costs to produce. For a provider bidding for institutional business, the absence of a report is frequently a disqualification at the procurement stage.

How the process runs

The sequence is predictable and the first year is the hard one:

  • Scoping — which services, which locations, which period. Too wide and the cost is unnecessary; too narrow and clients ask why their service is excluded;
  • Defining control objectives and controls — this is the provider's own work, and it determines everything. Objectives should map to what clients actually rely on: completeness and accuracy of processing, authorisation, data security, and the integrity of what is reported back;
  • Readiness assessment — a dry run identifying controls that are not documented, not performed consistently, or not evidenced. Almost every first-year engagement finds controls that exist in practice and cannot be proven;
  • The testing period, during which the reporting accountant tests samples across the whole period;
  • Reporting, including any exceptions, and the provider's response to them.

Exceptions, and complementary controls

An exception is not a failure. Reports routinely include them, and a report with none across hundreds of controls invites more scepticism than one with a handful properly explained. What matters to a reader is whether the exception affects a control objective they rely on, whether the cause was systemic, and what the provider did about it.

The other section readers skip and should not is complementary user entity controls — the things the report assumes the client does. A report may assume the client checks the data it submits, reviews reports it receives, and maintains its own access controls. Where the client does none of those, the assurance it thinks it has does not exist. Any organisation relying on a controls report should read that section first and confirm it actually performs what is listed.

Using one properly

For a recipient: check the period covered and that it aligns with your own reporting year; read the opinion, the exceptions and the complementary controls; and document your conclusion, because your auditors will ask what you did with it. A report filed unread is a control failure of your own.

For a provider: start the readiness work at least six months before the intended period, because retrofitting evidence into a period that has already run is impossible. Keep the control descriptions honest — describing a control more strongly than it operates guarantees an exception. And treat the annual cycle as continuous rather than seasonal, since the testing covers every month.

Acumon acts as reporting accountant on controls assurance engagements and prepares service organisations for their first report, through internal audit and pension scheme audit work, with IT audit support where the control environment is largely technical. If a client has asked whether you hold an AAF report, the readiness assessment is the place to start.

Get in Touch

Ready for Accountants Who Move Your Business Forward?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch