SOC 1 Engagements - Service Organizations

IT General Controls Fundamentals · 4:36

Listen on 93

Lyrics

[Verse 1]
When a company outsources their operations
To a service organization they rely upon
Payroll processing or data center hosting
User entities need to know what's going on
The service org controls affect their reporting
Internal controls over financial data
So we need assurance, we need some testing
SOC One report shows us what really matters

[Chorus]
SOC One engagement, Type One or Type Two
Service Organization Control for me and you
Type One's a point in time, design effectiveness
Type Two adds operating, nine months or more to test
Controls at the service org, relevant to user entities
Financial reporting impacts, that's the key dependency

[Verse 2]
Management assertion about their control system
Service auditor comes in to examine
Complementary controls at the user entity
Bridge controls that fill the gaps in the remedy
Carve-out method excludes certain functions
Inclusive method covers all operations
The scope definition matters for the audit
User auditor needs to know what's included

[Chorus]
SOC One engagement, Type One or Type Two
Service Organization Control for me and you
Type One's a point in time, design effectiveness
Type Two adds operating, nine months or more to test
Controls at the service org, relevant to user entities
Financial reporting impacts, that's the key dependency

[Bridge]
Restricted use report for user auditors
Not for general distribution or investors
Service auditor's testing reduces substantive procedures
User auditor can rely when the report assures
Subservice organizations add complexity
Testing cascades through the hierarchy

[Verse 3]
Control objectives tied to financial assertions
Completeness, accuracy, proper authorizations
Cut-off procedures and classification standards
The service org maintains what user demands
Exception reporting shows the deficiencies
Qualified opinion when there's inadequacies
Clean report means controls are operating
User entity audit risk we're mitigating

[Chorus]
SOC One engagement, Type One or Type Two
Service Organization Control for me and you
Type One's a point in time, design effectiveness
Type Two adds operating, nine months or more to test
Controls at the service org, relevant to user entities
Financial reporting impacts, that's the key dependency

[Outro]
Trust but verify through SOC One testing
Service organization controls worth investing
User entity audits depend on this foundation
SOC One reports build audit validation

← Attestation for Non-Financial Information | SOC 2 and SOC 3 Engagements →