Expert Knowledge to Your Inbox - SignUp Now!

Complementary User Entity Controls (CUECs) for Leases

John J. Meedzan

Co-Founder and Managing Partner, iLease Management LLC

Questions this article answers

  • What are Complementary User Entity Controls (CUECs) in the context of lease software?
  • How do CUECs ensure the reliability of lease accounting data?
  • What is the role of CUECs in an ASC 842 audit?
  • Why are CUECs important for lease software users and auditors?
  • How do CUECs mitigate risks associated with using third-party lease software?

Understand CUECs for Effective Lease Accounting Software

Lease accounting under ASC 842 often gets complex, most of all when you rely on third-party software. Controllers, accounting managers and auditors all need the lease data these systems process to be accurate and complete. Strong complementary user entity controls support that goal directly.

CUECs are controls your company (the user entity) must run so the lease software vendor's controls can meet the control objectives in its SOC 1 report. KPMG describes them as controls the service organization "assumes, in the design of its system, will be implemented by user entities"1. The vendor's SOC 1 report lists them. These controls are critical to keeping lease data sound, from first identification through ongoing accounting and disclosure.

Without effective CUECs, even the most advanced lease accounting software can't fully guarantee compliance with complex standards such as ASC 842. Knowing these controls is also key to assessing ASC 842 controls well during an audit. This article covers what CUECs involve and why they're vital for lease accounting compliance. It also covers how auditors judge whether they work, as a way to manage audit risk in lease accounting.

How Auditors Read a SOC 1 Report Alongside Your Controls

When they audit an entity that uses third-party lease accounting software, auditors put heavy weight on the design and operating effectiveness of related controls. That covers both the service organization's controls and the CUECs. The vendor's SOC 1 report describes the design of its controls and, in a type 2 report, their operating effectiveness2. A type 1 report covers design only, as of a single date.

Auditors aren't just looking for proof that the software is in use. They look hard at the processes a company uses to make sure the software handles data accurately and completely.

The completeness assertion refers to the auditor's goal to verify that the financial statements include all transactions and accounts that should be recorded. In lease accounting, this means making sure every lease agreement is captured, including through embedded lease discovery. Auditors apply a risk-based approach to confirm the lease population is complete. That includes inquiries, reviews of lease agreements, and tests of reconciliation procedures.

✅ Best Practice: Proactive companies run regular self-assessments of their CUECs, often against the same criteria auditors use. This helps them find and fix weaknesses before the external audit looks at them.

Auditors typically look at the five components of internal control in the COSO Framework. They apply them to lease accounting: the control environment, risk assessment, control activities, information and communication, and monitoring activities.

Q: How do auditors test complementary user entity controls? A: Auditors test CUECs by examining documentation of control design and walking through the controls with the staff who run them. They inspect evidence that the controls were performed (e.g., reconciliations, review sign-offs), and they re-perform control activities on a sample basis. This includes checking that inputs to the software are accurate and complete, and that outputs are reviewed and reconciled.

Key Audit Focus Areas for Lease Software

Here’s a summary of what auditors prioritize:

Audit Focus AreaDescriptionAudit Procedure Examples
CompletenessAssurance that all leases are identified and entered into the software.Review lease abstraction process, trace new contracts to software, lease identification testing.
AccuracyVerification that lease data (start dates, payments, rates) is correctly entered and processed.Reconcile software output to source documents, recalculate samples of lease schedules.
ValidityConfirmation that all recorded leases are real and authorized.Review lease approvals, match lease entries to physical contracts.
Period Cut-offEnsuring leases and associated expenses are recorded in the correct accounting period.Examine effective dates, review journal entry posting dates.
DisclosureChecking that all required ASC 842 disclosures are accurate and adequately supported by the software.Compare disclosures to software reports and underlying data, verify footnote completeness.
Segregation of DutiesEvaluating whether incompatible functions are separated within the lease accounting process.Observe roles and responsibilities, review access rights within the software.
Change ManagementAssessing controls over modifications to lease terms or software configurations.Review change logs, verify approval processes for lease amendments.

To fully meet audit expectations, companies really should review detailed guidance on their ASC 842 internal control framework. That way, their CUECs line up with industry best practices and with what auditors expect.

Where User and Provider Responsibilities Get Confused

Weak CUECs expose a company to serious financial reporting risks. These risks often come from confusing what the user entity is responsible for with what the software provider is responsible for.

  • Incomplete Lease Population: Failing to identify all leases that fall under ASC 842 can lead to material misstatements. The risk is especially high with embedded leases. People often miss them because contracts don't label them as "leases" by name. For example, a cloud services contract might give you the right to use specific servers for a set period. If you also control how those servers are used, the contract contains an embedded lease (ASC 842-10-15-3).
  • Inaccurate Lease Data: Data entry errors, wrong lease classifications, or out-of-date data can result in miscalculated ROU asset and lease liability balances. If the initial data taken from a lease agreement is wrong, the software will process flawed data. That leads to incorrect accounting.
  • Lack of Reconciliation: If software outputs aren't reconciled to the general ledger and supporting documents at regular intervals, differences can go unnoticed. This can hide deeper problems with data integrity or software processing.
  • Ineffective Review Processes: Just running reports from lease software, with no thorough, documented review by qualified staff, is a control weakness. Financial statements can then hold undetected errors in lease expenses, ROU asset amortization, and liability accretion.
  • Insufficient Change Management: Changes to lease terms (e.g., extensions, modifications, terminations) or software settings made without proper authorization and testing can lead to inaccurate financial reporting. This is a common pitfall that often results in audit findings.

⚠️ Risk Alert: A common audit finding is that companies overlook service contracts in embedded lease discovery. Many companies only review traditional real estate or equipment leases, and they miss large embedded lease exposures. This can directly affect the completeness assertion.

Take a retail company with hundreds of store leases and vehicle leases. Suppose its process for on-boarding new leases involves only the real estate department. Suppose, too, that accounting doesn't explicitly review the underlying documents for lease components. Then there's a high risk that material leases or modifications won't make it into the lease software.

This is a failure of the company's own controls, whether or not the vendor's SOC 1 report lists lease identification as a CUEC. It impairs the accuracy of ROU assets and lease liabilities on the balance sheet. For more, see common mistakes in lease control documentation.

Calculation Example: Impact of an Unidentified Embedded Lease

Scenario: A company signs a five-year contract for dedicated warehouse space inside a larger logistics facility. The operations team classifies the contract as a service agreement. But the company implicitly controls the use of an identified asset (specific, physically distinct bays in the warehouse; ASC 842-10-15-16) for a period of time.

That makes the contract an embedded lease under ASC 842. The annual lease payments are $60,000, paid at the end of each year (in arrears), and the incremental borrowing rate is 5%. A company that is not a public business entity may elect a risk-free rate in place of its incremental borrowing rate, by class of underlying asset (ASC 842-20-30-3).

ComponentValueCalculation
Annual Lease Payment$60,000Given
Number of Years5Given
Incremental Borrowing Rate5%Given
Present Value Factor (5 yrs, 5%)4.329477Ordinary annuity, payments at year-end: PVAF = (1 - (1 + i)^-n) / i
Initial Lease Liability$259,769$60,000 x 4.329477 (present value of the lease payments not yet paid, discounted at the rate for the lease, ASC 842-20-30-1)
Initial ROU Asset Value$259,769Equal to the lease liability here: no payments at or before commencement, no incentives, no initial direct costs (ASC 842-20-30-5).

Key Takeaway: Suppose this embedded lease isn't identified and recorded in the lease software. The company's balance sheet will then be understated by $259,769 for both the ROU asset and lease liability. Whether that is material depends on the company's own materiality, which weighs quantitative and qualitative factors. Lease identification testing exists to find this kind of gap, which is why effective user-side controls matter.

Practical Checklist for Effective CUECs

Putting strong CUECs in place takes a structured approach. This checklist gives controllers and accounting managers a framework. It helps them make sure their controls work and meet audit expectations.

Start with the CUECs your vendor's SOC 1 report lists and map each to a control below. Controls such as lease identification are your company's responsibility whether or not the report lists them.

Control AreaChecklist ItemEvidence of Control Performance
Lease IdentificationEstablish formal procedures for reviewing ALL new and existing contracts for embedded lease discovery.Documented contract review checklists, meeting minutes, communication with procurement/legal.
Data Input & AbstractionImplement a standardized lease abstraction process, capturing all required data elements accurately.Abstraction templates, completed abstraction forms, dual-reviewer sign-offs.
Classification & RemeasurementEnsure criteria for lease classification (operating/finance) and remeasurement events are uniformly applied.Documented classification decision trees, audit logs of software changes, review records.
Software ConfigurationMaintain documentation of all critical software configurations and settings, with authorized changes only.Configuration logs, change request forms, documented approval for changes.
Output ReconciliationPerform monthly/quarterly reconciliation of lease software outputs (e.g., journal entries) to the general ledger.Reconciliation worksheets, variance analysis, GL tie-out documentation.
Financial Reporting ReviewImplement a multi-level review process for all lease-related financial statements and disclosures.Reviewer sign-offs on reports, management review meeting minutes.
Data Security & AccessEnsure appropriate user access controls are in place for the lease software, adhering to company policies.User access reviews, access matrices, audit logs for sensitive data changes.
Training & CompetenceProvide regular training to personnel involved in lease accounting on ASC 842 and software usage.Training logs, competency assessments.

💡 Key Takeaway: For lease accounting compliance, just owning software is not enough. How well it works depends on the human processes around its use, including the CUECs. This checklist helps make those processes strong.

Q: How to identify embedded leases in contracts?

A: Finding embedded leases takes a systematic review of all service, supply, and outsourcing agreements. Look for terms that grant the right to use a specific asset for a period of time (e.g., particular manufacturing equipment, designated data center servers, specific transportation vehicles). Then check whether your entity controls how and for what purpose that asset is used. Keywords like "dedicated," "exclusive use," or "specific capacity" can be indicators.

Confirming Your CUECs Operate as Designed

Checking CUECs is an ongoing process, not a one-time event. Accounting teams must set a clear method to confirm their controls work as intended and produce reliable lease accounting data. This proactive check is critical for a smooth audit and for accurate financial reporting.

One key part of this check is lease identification testing. At set intervals, you take a sample of contracts that were first not classified as leases, and you re-check them for lease components. This helps confirm that the first screening for embedded lease discovery works. For instance, an internal audit team or an independent accounting function could sample 25-50 new service contracts each year and verify the first lease assessment.

Essential validation steps include:

  1. Documentation Review: Review and update all control documentation at set intervals, including process narratives, flowcharts, and control matrices. Make sure they reflect current operations accurately.
  2. Walkthroughs: Run regular walkthroughs of the lease accounting process with the relevant staff. They confirm that people perform the controls as documented. They also reveal possible gaps between policy and practice.
  3. Independent Recalculation: Select a sample of lease agreements. Independently recalculate the initial ROU asset and lease liability measurements, and the later amortization and accretion schedules. Compare these to the software's output. Any material differences should trigger further investigation.
  4. Reconciliation Verification: Don't just perform reconciliations; also verify the reconciliation process itself. This means reviewing prior reconciliations for open items, unresolved differences, and timely follow-up.
  5. Output Review & Analytical Procedures: Critically review the financial reports and disclosures the lease software produces, alongside financial statement analytics. Large swings or unexpected trends in lease expense, ROU assets, or lease liabilities should be investigated.
  6. User Access Reviews: At set intervals, review who has access to the lease software and what permissions they hold. This keeps segregation of duties appropriate.

The Financial Accounting Standards Board (FASB) defines a lease in ASC 842-10-15-33. That definition decides what enters the software, and so what needs to be controlled. Following it, together with strong internal controls, forms the backbone of reliable lease accounting.

For example, one key check is making sure the software's classification output matches the finance lease criteria in ASC 842-10-25-2. A lease that meets none of them is an operating lease (ASC 842-10-25-3).

Assuming the Software Vendor Owns the Control

Even with dedicated lease software, companies often make common mistakes in their CUECs. Those mistakes can lead to audit scrutiny and financial misstatements. Knowing these pitfalls is the first step to avoiding them and to strengthening overall lease accounting compliance.

Common MistakeHow to Avoid / Best PracticeAudit Impact
Reliance solely on software vendor's SOC 1 report.Understand the scope of the SOC 1 report and explicitly define internal CUECs to cover what the report doesn't.Auditor will question the completeness and adequacy of user controls for areas not covered by SOC 1.
Lack of formal control over data input.Implement a standardized, documented lease abstraction and input process with review/approval steps. Make sure lease controls procedures are followed.Risk of material misstatement due to inaccurate ROU assets and lease liabilities.
Ignoring lease modifications or remeasurements.Establish clear triggers and processes for capturing and processing lease modifications promptly within the software.Incorrect lease expense, ROU asset, and liability balances; non-compliance with ASC 842 guidance.
Inadequate reconciliation of software output to general ledger.Perform and document regular, detailed reconciliations. Investigate and resolve variances immediately.Undetected errors in lease accounting; auditor difficulties in vouching balances.
Insufficient review of generated reports and disclosures.Mandate and document a robust review process by knowledgeable personnel for all lease reports and disclosures.Inaccurate financial statement disclosures, potentially misleading users of financial statements.
Poor change management over lease terms or software settings.Implement formal change control procedures for lease software configurations and lease agreements.Inconsistency in lease accounting, potential for unauthorized changes or errors.
Lack of clear roles and responsibilities for lease accounting.Define specific roles, responsibilities, and segregation of duties for all lease accounting activities.Control environment weaknesses, increased risk of error or fraud.

🚨 Critical: Failing to identify all leases, most of all embedded leases, is a common and significant audit finding. It affects the completeness assertion. It can also lead to material understatement of both assets and liabilities on the balance sheet.

Q: What documentation is required for complementary user entity controls? A: Key documentation includes detailed process narratives, control matrices, and evidence of control performance (e.g., signed reconciliation reports, review checklists). Training records, change logs for software settings and user access review reports belong here too. The narratives and control matrices show how the controls are designed, and the evidence of performance is what auditors test for operating effectiveness.

What Well-Implemented CUECs Deliver at Audit

Companies that excel at CUECs have smoother audits and more reliable financial reporting. Strong execution means fewer audit findings, quicker sign-offs, and more confidence from stakeholders. It goes beyond just having the controls in place. It shows that they operate consistently and effectively.

A well-executed CUEC environment means:

  • Timely Lease Identification: All new contracts get a systematic review. Any lease components are identified and abstracted into the lease software within a set timeframe, e.g., 30 days of contract execution. That includes embedded lease discovery. This prevents the "what are the risks of incomplete lease population" scenario.
  • Accurate Data Entry: Lease data is consistently abstracted and checked against source documents with a low error rate (e.g., less than 1% detected errors upon review).
  • Automated Workflows with Human Oversight: The software's automation features handle calculations and journal entries. A strong, documented human review and approval step comes before posting.
  • Proactive Issue Resolution: Any differences found during reconciliation or review are investigated, documented, and resolved promptly. Root causes are fixed so they don't recur.
  • Continuous Improvement: Teams assess CUEC effectiveness regularly. This leads to step-by-step improvements in processes and documentation. This might involve an internal audit review every 12-18 months.
  • Clear Communication with Auditors: Giving auditors ready, complete documentation of CUECs, including proof of execution, greatly streamlines the audit.

Take a manufacturing company that processes hundreds of equipment leases and has many embedded leases within supply contracts. With strong CUECs, its accounting team uses a central contract review system. The system automatically flags contracts over a certain dollar threshold for lease component analysis. Abstracted lease data is peer-reviewed before it goes into the software.

Each month, the lease accounting manager reviews the software-generated journal entries. The manager also reconciles them to the general ledger and investigates any variance over $500. This disciplined process keeps the ROU assets and lease liabilities accurate and supports a clean audit. This commitment results in strong lease accounting compliance.

Reviewing Your Lease Software Control Assignments

Setting up and keeping effective CUECs is an ongoing process. To strengthen your organization's lease accounting and be ready for audit, consider these immediate actions:

  • Review your current lease identification process for completeness. Pay special attention to service contracts that may contain embedded leases.
  • Document or update your CUECs. Make sure they cover the data input, processing, and output reconciliation work your accounting team performs.
  • Plan and run a walkthrough of your end-to-end lease accounting process, from contract inception to financial statement disclosure. Challenge each control point.

Related Articles

Sources and further reading

  1. KPMG, Internal control over financial reporting Handbook, Question 8.7.10 ↩

  2. AICPA & CIMA — Maintaining high standards for SOC engagements ↩

  3. FASB ASC 842-10-15-3 (definition of a lease) and ASC 842-10-25-2 to 25-3 (lease classification), as quoted in Deloitte, Roadmap: Leases, section 3.2 and section 8.3 ↩