[Verse 1] When a company outsources their operations To a service organization they rely upon Payroll processing or data center hosting User entities need to know what's going on The service org controls affect their reporting Internal controls over financial data So we need assurance, we need some testing SOC One report shows us what really matters [Chorus] SOC One engagement, Type One or Type Two Service Organization Control for me and you Type One's a point in time, design effectiveness Type Two adds operating, nine months or more to test Controls at the service org, relevant to user entities Financial reporting impacts, that's the key dependency [Verse 2] Management assertion about their control system Service auditor comes in to examine Complementary controls at the user entity Bridge controls that fill the gaps in the remedy Carve-out method excludes certain functions Inclusive method covers all operations The scope definition matters for the audit User auditor needs to know what's included [Chorus] SOC One engagement, Type One or Type Two Service Organization Control for me and you Type One's a point in time, design effectiveness Type Two adds operating, nine months or more to test Controls at the service org, relevant to user entities Financial reporting impacts, that's the key dependency [Bridge] Restricted use report for user auditors Not for general distribution or investors Service auditor's testing reduces substantive procedures User auditor can rely when the report assures Subservice organizations add complexity Testing cascades through the hierarchy [Verse 3] Control objectives tied to financial assertions Completeness, accuracy, proper authorizations Cut-off procedures and classification standards The service org maintains what user demands Exception reporting shows the deficiencies Qualified opinion when there's inadequacies Clean report means controls are operating User entity audit risk we're mitigating [Chorus] SOC One engagement, Type One or Type Two Service Organization Control for me and you Type One's a point in time, design effectiveness Type Two adds operating, nine months or more to test Controls at the service org, relevant to user entities Financial reporting impacts, that's the key dependency [Outro] Trust but verify through SOC One testing Service organization controls worth investing User entity audits depend on this foundation SOC One reports build audit validation
← Attestation for Non-Financial Information | SOC 2 and SOC 3 Engagements →