A SOC 1 or SOC 2 report is an independent auditor's report that provides customers and international business partners with assurance regarding your control environment.
SOC 1 and SOC 2 reports are independent auditor's reports based on US assurance standards and criteria issued by the AICPA. They are used particularly by US and international customers, investors and business partners seeking assurance regarding a company's internal controls.
The structure and purpose of these reports are similar to those of the international ISAE reports:
- SOC 1 is closely aligned with ISAE 3402 and concerns controls that may be relevant to customers' financial reporting.
- SOC 2 can be compared with an ISAE 3000 report and concerns controls relating to areas including security, availability, confidentiality and data processing.
RSM helps you determine the report type, scope, criteria and process and performs the independent assurance engagement. The process is designed to provide high professional quality and efficiency while keeping unnecessary documentation to a minimum.
Advisory, preparation and assurance services are planned in accordance with the applicable auditor independence requirements. The extent of any preparatory assistance therefore depends on the specific engagement.
SOC 1 or SOC 2?
A SOC 1 report is relevant when your services or systems may affect customers' financial reporting or internal control over financial reporting.
SOC 1 is primarily used by the company's customers and their auditors when assessing controls relevant to the customers' financial reporting.
A SOC 2 report is relevant to companies that process, store or transmit customer data and need to demonstrate an effective control environment around their systems and services.
SOC 2 is based on the AICPA's Trust Services Criteria. Security is always included. Depending on the agreed scope, the report may also cover Availability, Processing Integrity, Confidentiality and Privacy.
SOC 2 is particularly relevant to SaaS companies, cloud and hosting providers, fintech companies, data processors, platform providers and other technology companies.
Type 1 or Type 2?
A Type 1 report documents the design and implementation of the controls as at a specified date.
A Type 2 report covers a period and also documents whether the controls operated effectively throughout that period.
How RSM helps you
We make the process straightforward and manageable, without unnecessary complexity.
- Clarification: We determine the report type, scope, criteria and timetable.
- Overview: You receive a clear overview of the process and the documentation required.
- Preparation, if required: We identify gaps and help you address them through a targeted GAP analysis.
- Review and testing: We review the documentation and test the controls in scope.
- Finalisation: You receive a draft and the final report.
Start with a readiness engagement
Are you unsure whether you are ready?
We offer an initial assessment in which we:
- Determine the report type, scope and customer requirements
- Identify gaps in your current control environment
- Advise on the controls and documentation required
- Prepare a specific plan leading up to the assurance engagement
This provides a clear basis for decision-making and reduces the risk of unnecessary delays in the formal audit.
Contact us about SOC 1 and SOC 2
Contact us for an initial discussion about your customer requirements, control environment and need for a SOC 1 or SOC 2 report.