The three SOC reports
| Report | Subject matter | Users / distribution |
|---|---|---|
| SOC 1 | Controls relevant to user entities' internal control over financial reporting | Restricted — user entities and their auditors |
| SOC 2 | Controls relevant to the Trust Services Criteria | Restricted — management, customers, regulators, business partners |
| SOC 3 | Same criteria as SOC 2, but a summarized report | General use — can be posted publicly |
The five Trust Services Criteria
- Security — the "common criteria"; always required in every SOC 2
- Availability — the system is available as committed
- Processing integrity — processing is complete, valid, accurate, timely, and authorized
- Confidentiality — information designated confidential is protected
- Privacy — personal information is handled per the entity's privacy notice
IMPORTANT — Type 1 vs. Type 2:
Type 1 = fairness of the description + suitability of design of controls, as of a point in time.
Type 2 = all of the above plus operating effectiveness over a period, with detailed tests and results.
Only a Type 2 lets a user auditor rely on the controls for a reporting period.
What's inside a SOC report
- Service auditor's report (the opinion)
- Management's assertion
- System description prepared by management
- Tests of controls and results (Type 2 only)
- Other information provided by management (unaudited)
Key participants
- Service organization — provides services affecting user entities' systems
- Service auditor — reports on the service organization's controls
- User entity — uses the service
- User auditor — audits the user entity and may use a Type 2 report as evidence
EXAM TIP: The user auditor must never reference the service auditor in an unmodified opinion on the user entity's financial statements — using the SOC report is obtaining evidence, not dividing responsibility.