Auditen
Home / Frameworks / SOC 1 / SOC 1 Type I vs Type II

SOC 1 Type I vs Type II

SOC 1 Type I evaluates whether a service organization's controls are appropriately designed and implemented at a specific point in time. SOC 1 Type II goes further by testing the operating effectiveness of those same controls over a defined period, typically six to twelve months.

What it means

The primary intent of a SOC 1 report is to provide assurance to your clients' auditors that your internal controls over financial reporting (ICFR) are reliable. It focuses on the processes you manage that could materially impact the financial statements of your customers.

A Type I audit is essentially a "snapshot." The auditor verifies that you have documented your control environment and that the described controls actually exist. It answers the question: "Is the system designed correctly to achieve its objectives?"

A Type II audit is a "movie" rather than a snapshot. The auditor examines evidence from across the entire review period to ensure controls were applied consistently. It answers the question: "Did the system actually work as intended every time it was supposed to over the last several months?"

How to meet it

Evidence an auditor asks for

  • A Control Matrix that maps each financial reporting objective to the specific controls used to satisfy it.
  • Current, approved policy documents and procedure manuals describing how the system is managed.
  • Sampled evidence of execution from across the period (e.g., if you review access monthly, the auditor will ask for 12 separate signed reviews).
  • System-generated configuration reports or screenshots proving that security settings match your documented policies.
  • Change management tickets showing a clear path from request to testing and final approval for every production change in the window.

Common pitfalls

  • Evidence gaps: Failing to produce evidence for a specific month within the Type II window, which results in an "exception" or failure for that control.
  • Process drift: Having documented policies (Type I) but failing to follow them consistently in practice (Type II).
  • Over-scoping: Including systems or departments in the report that do not actually impact financial reporting, unnecessarily increasing the audit workload and risk of failure.