Auditen
Home / Frameworks / SOC 1 / Why customers ask for it: ICFR

Why customers ask for it: ICFR

SOC 1 focuses on Internal Control over Financial Reporting (ICFR). It requires a service organization to identify and test controls that significantly impact the financial statements of its clients, ensuring those clients can rely on the provider's data for their own regulatory financial reporting.

What it means

While SOC 2 is about security and availability, SOC 1 is specifically about financial integrity. Customers ask for this because they are often subject to regulations (such as Sarbanes-Oxley in the US) that require them to certify the accuracy of their financial reports. If a customer outsources a process—such as payroll, billing, or investment management—to you, your internal controls become an extension of their own ICFR.

In practice, this means you must isolate which parts of your system touch "financial" data or influence the calculations used in a client's general ledger. The scope is not your entire infrastructure, but rather the specific processes that could lead to a material misstatement in a customer's financial records if they were to fail.

How to meet it

Evidence an auditor asks for

  • Change tickets showing approval, testing, and deployment for updates to financial modules.
  • User access review logs proving that permissions to financial systems are reviewed and revoked timely.
  • Signed-off reconciliation reports or "exception logs" where errors were identified and corrected.
  • System-generated audit trails showing who modified a specific financial record and when.

Common pitfalls

  • Confusing SOC 1 with SOC 2: Implementing general security controls (like firewalls) without implementing the specific financial accuracy controls required for ICFR.
  • Vague Control Objectives: Writing objectives that are too broad, making it impossible for an auditor to test them concretely.
  • Ignoring CUECs: Failing to tell the customer which controls they are responsible for, which can lead to a qualified audit opinion if the "hand-off" between provider and client is broken.