A SOC 1 Report (System and Organization Controls Report) is a report on Controls at a Service Organization which are relevant to user entities’ internal control over financial reporting. The SOC1 Report is what you would have previously considered to be the standard SAS70 (or SSAE 16), complete with a Type I and Type II reports, but falls under the SSAE 18 guidance (as of May 1, 2017).
Please see the following articles discussing the SSAE 18 guidance and additional information related to the SOC 1 (Type I and Type II) Reports:
Below is a history of key changes made to the audit standard over time to enhance the overall audit and final report.
Differences between SAS 70, SSAE 16 and ISAE 3042:
- Management of the Service Organization will be required to provide the service auditor with a written assertion about the following, when performing either a Type I or Type II engagement, which the service auditor will then attest to:
- The fairness of the presentation of the description of the service organization’s system;
- The suitability of the design of the controls to achieve the related control objectives stated in the description; and
- The operating effectiveness of those controls to achieve the related control objectives stated in the description (Type II Only)
- During the process of understanding the service organization’s system, the Service Auditor would be required to obtain information that would identify risks that the description of the service organization’s system is not fairly presented or that the control objectives stated in the description were not achieved due to intentional actions by service organization personnel.
SSAE 18 adds an additional set of requirements to further enhance SSAE 16 standard:
- Requires the inclusion of a Complementary Subservice Organization Controls section (similar to what is currently required for SOC 2).
- Requires the performance of a detailed Risk Assessment based on the control objectives defined in the report.
Remember: Although the reporting standard is soon to be, SSAE 18, the SSAE 16 and ISAE 3204, are all still considered to be a SOC 1 Report!
The latest changes are meant to give the end user a clearer picture of their vendor’s subservice organizations and the responsibilities of the end user as well (Complementary User Entity Controls), which, will help to provide an all around higher level of assurance and understanding to all involved.
SOC 2 and SOC 3 – Additional Reporting Options
In addition to the SOC 1 report which is restricted to controls relevant to an audit of a user entity’s financial statements, the SOC 2 and SOC 3 reports have been created to address controls relevant to operations and compliance.
- SOC 2 Report – Trust Services Principles – The Service Organization Control (SOC) 2 Report will be performed in accordance with AT 101 and based upon the Trust Services Principles, with the ability to test and report on the design (Type I) and operating (Type II) effectiveness of a service organization’s controls (just like SOC 1 / SSAE 18)….read more
- SOC 3 Report – WebTrust and SysTrust – The SOC 3 Report is also based upon the Trust Service Principles and performed under AT101, the difference being that a SOC 3 Report is permitted to be freely distributed (general use) and only reports on if the entity has achieved the Trust Services criteria or not (no description of tests and results or opinion on description of the system)….read more