SOC Reports
System and Organization Controls reports on a service organization's controls relevant to its clients.
AUD loves to make you choose the report number and the type. The “tell” is who reads it and why: a financial-statement auditor whose client outsourced payroll needs a SOC 1 (controls over financial reporting, examined under SSAE No. 18 / AT-C 320); a buyer evaluating a vendor’s security, availability, processing integrity, confidentiality, or privacy needs a SOC 2 (the five Trust Services Criteria, under AT-C 205). Marketing-grade, general-use distribution gets a SOC 3. Then nail Type 1 vs Type 2: Type 1 tests design at a point in time; Type 2 tests operating effectiveness over a period—that’s the answer when the user auditor wants reliance.
The classic trap is treating SOC like an opinion on the service organization’s financial statements—it isn’t; it reports on a service organization’s controls, the system the entity in internal control relies on. Don’t confuse the service auditor (writes the report) with the user auditor (relies on it), and know the carve-out vs inclusive method for subservice organizations. Hook: “1 = financials, 2 = security.”
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →