SOC 1 Report
A SOC 1 report assesses a service organisation's controls related to user entities' financial reporting, following AICPA's SSAE No. 18 standards. It targets a specific audience: user entities outsourcing significant financial processes and their auditors.
- Audit & Assurance
A SOC 1 report is an examination of a service organization's controls that are relevant to its user entities' internal control over financial reporting, performed under the AICPA's SSAE No. 18 attestation standards. The audience is deliberately narrow: the user entities that outsource a financially significant process, and the auditors of those user entities.
SOC 1 reports come in two types. A Type 1 report expresses an opinion on the fairness of management's description of the system and the suitability of the design of controls as of a specified date. A Type 2 report covers a period - usually six or twelve months - and additionally opines on whether the controls operated effectively throughout that period, including detailed descriptions of the tests performed and the results. Type 2 is what user auditors almost always need, because design without operating effectiveness provides no basis for reliance.
Typical SOC 1 issuers include payroll processors, third-party claims administrators, loan servicers, custodians and fund administrators, and cloud-based accounting and billing platforms. The control objectives are financial in orientation: completeness and accuracy of transaction processing, authorization, cutoff, and the integrity of reports provided to user entities.
Two features matter for user auditors. Complementary user entity controls are controls the service organization assumes the customer performs, and the report's conclusions depend on them - the user auditor must confirm they are actually in place. Subservice organizations may be handled by the inclusive method, bringing them into scope, or the carve-out method, excluding them and leaving the user auditor to obtain separate assurance. CPA firms both issue SOC 1 reports and evaluate them on behalf of audit clients.