Auditen
Home / Frameworks / SOC 1

SOC 1 (System and Organization Controls 1, SSAE 18)

SOC 1 is an audit report that evaluates the controls at a service organization relevant to its clients' internal control over financial reporting (ICFR). It exists so that clients can rely on these audited controls rather than performing their own manual audits of the service provider.

Who it applies to

  • Payroll and human resources outsourcing providers.
  • Cloud service providers hosting financial applications or sensitive accounting data.
  • Payment processing and transaction gateways.
  • Loan servicing, trust administration, or escrow companies.

How it works

SOC 1 is based on the SSAE 18 standard issued by the AICPA. It focuses exclusively on controls that impact a client's balance sheet or income statement. The process involves an independent CPA firm evaluating whether the service organization's described controls are designed and operating effectively to prevent or detect financial misstatements.

There are two types of reports: Type I and Type II. A Type I report evaluates the design of controls at a specific point in time, confirming that they exist as described. A Type II report is more rigorous; it evaluates both the design and the operational effectiveness of those controls over a period, typically six to twelve months.

The final output is an attestation report. This document includes a description of the system, management's assertion that the controls are effective, and the auditor's opinion based on their testing results. Clients then provide this report to their own auditors as evidence of third-party control compliance.

Getting started

  1. Identify which internal controls directly impact your customers' financial reporting processes.
  2. Document these control activities in written policies and standard operating procedures.
  3. Conduct a gap analysis to identify where current practices deviate from the required controls.
  4. Remediate identified gaps by implementing new controls or updating existing ones.
  5. Select an independent CPA firm licensed to perform SSAE 18 audits.
  6. Define the "review period" for your Type II audit and begin collecting evidence of control execution.

Controls & requirements

Common misconceptions

  • Confusing SOC 1 with SOC 2; while SOC 2 focuses on security, availability, and privacy (the Trust Services Criteria), SOC 1 is strictly concerned with financial reporting controls.
  • Viewing it as a "certification"; unlike ISO standards, SOC 1 results in an attestation report rather than a certificate of compliance.