SimplyCPA
CPA/ISC/SOC Engagements

SOC Engagements

SOC 1, SOC 2, and SOC 3 reports, Type 1 vs. Type 2, and the trust services criteria.

Hard 1 hr 5 minArea III: SOC Engagements

The three SOC reports

ReportSubject matterUsers / distribution
SOC 1Controls relevant to user entities' internal control over financial reportingRestricted — user entities and their auditors
SOC 2Controls relevant to the Trust Services CriteriaRestricted — management, customers, regulators, business partners
SOC 3Same criteria as SOC 2, but a summarized reportGeneral use — can be posted publicly

The five Trust Services Criteria

  • Security — the "common criteria"; always required in every SOC 2
  • Availability — the system is available as committed
  • Processing integrity — processing is complete, valid, accurate, timely, and authorized
  • Confidentiality — information designated confidential is protected
  • Privacy — personal information is handled per the entity's privacy notice

IMPORTANT — Type 1 vs. Type 2:
Type 1 = fairness of the description + suitability of design of controls, as of a point in time.
Type 2 = all of the above plus operating effectiveness over a period, with detailed tests and results.
Only a Type 2 lets a user auditor rely on the controls for a reporting period.

What's inside a SOC report

  1. Service auditor's report (the opinion)
  2. Management's assertion
  3. System description prepared by management
  4. Tests of controls and results (Type 2 only)
  5. Other information provided by management (unaudited)

Key participants

  • Service organization — provides services affecting user entities' systems
  • Service auditor — reports on the service organization's controls
  • User entity — uses the service
  • User auditor — audits the user entity and may use a Type 2 report as evidence

EXAM TIP: The user auditor must never reference the service auditor in an unmodified opinion on the user entity's financial statements — using the SOC report is obtaining evidence, not dividing responsibility.