Auditen
Home / Frameworks / SOC 1 / What a SOC 1 report is

What a SOC 1 report is

A SOC 1 report is an independent auditor's assessment of the internal controls at a service organization that are relevant to their clients' internal control over financial reporting (ICFR). It provides assurance to a client's auditors that the services provided by the vendor do not create undue risk for the client's own financial statements.

What it means

Unlike SOC 2, which focuses on security and availability, SOC 1 is specifically concerned with the financial impact of your service. If your organization processes payroll, manages billing, or handles data that feeds into a customer’s general ledger, you are in scope for SOC 1. The goal is to prove that your internal processes prevent material misstatements in your customers' financial reports.

There are two types of reports: Type I and Type II. A Type I report evaluates the *design* of controls at a specific point in time (i.e., "do you have the right rules on paper?"). A Type II report evaluates both the design and the *operating effectiveness* over a period, typically 6 to 12 months (i.e., "did you actually follow those rules consistently?").

The scope of a SOC 1 report is defined by the specific services provided that impact financial reporting. This includes identifying Complementary User Entity Controls (CUECs)—the specific actions your customers must take on their end for your controls to be effective.

How to meet it

Evidence an auditor asks for

  • A detailed description of the system, including the controls in place and the CUECs required from the customer.
  • Sampled evidence of control execution, such as signed approval forms for changes or screenshots of completed quarterly access reviews.
  • Change management logs showing that every production change was tested, approved, and documented before deployment.
  • Evidence of onboarding and offboarding processes to prove that terminated employees' access to financial systems was revoked promptly.

Common pitfalls

  • Confusing SOC 1 with SOC 2 by focusing on general cybersecurity instead of the specific controls that impact financial reporting accuracy.
  • Failing to maintain a consistent "audit trail" for Type II reports, resulting in gaps where no evidence exists for certain months of the review period.
  • Poorly defined scope, which leads to either an overly expensive audit covering unnecessary systems or a failed audit because critical financial paths were omitted.