SimplyCPA
CPA/AUD/Attestation & SOC Engagements

Attestation & SOC Engagements

The attestation standards, examination vs. review vs. AUP, and SOC 1/SOC 2 reporting.

Medium 50 minArea IV: Forming Conclusions and Reporting

Three attestation engagement types

TypeAssuranceConclusion wording
ExaminationReasonableOpinion — positive assurance
ReviewLimitedConclusion — negative assurance
Agreed-upon proceduresNoneFindings only

SOC reports at a glance

ReportSubjectPrimary users
SOC 1Controls at a service organization relevant to user entities' internal control over financial reporting (ICFR)User entities and their auditors
SOC 2Controls relevant to the Trust Services Criteria: security, availability, processing integrity, confidentiality, privacyRestricted — management, customers, regulators
SOC 3Same criteria as SOC 2, summarizedGeneral use — public distribution

IMPORTANT — Type 1 vs. Type 2: A Type 1 report covers the fairness of the description and the suitability of design of controls at a point in time. A Type 2 report adds operating effectiveness over a period. Only a Type 2 gives the user auditor evidence to rely on the controls for a period.

Security is the only mandatory criterion

In a SOC 2, the security ("common") criteria must always be included; availability, processing integrity, confidentiality, and privacy are included only if relevant to the engagement scope.

Complementary user entity controls

A service organization's description often assumes that user entities implement certain controls of their own (e.g., promptly notifying the service organization of terminated employees). The user auditor must determine whether those complementary controls actually exist at the user entity — otherwise the service organization's controls may not achieve their objectives.

EXAM TIP: The service auditor reports on the service organization. The user auditor audits the user entity and may use a Type 2 SOC 1 report as evidence — and must not reference the service auditor in an unmodified user-entity opinion.