A SaaS provider asks its auditor whether a System and Organization Controls (SOC) 2 Type 1 report will satisfy enterprise customers conducting vendor due diligence. The auditor's answer depends on what those customers need: evidence that controls are designed properly at a point in time, or evidence that controls operated effectively over a period. The distinction drives engagement planning, testing scope, and the assertions management must make.
AICPA Representative Tasks (verbatim). 1. Remembering & Understanding, Explain the purpose of the Trust Services Criteria and its organization (e.g., alignment with the COSO Internal Control, Integrated Framework, supplemental criteria, common criteria, additional specific criteria). 2. Remembering & Understanding, Recall the types of subject matters a practitioner may be engaged to report on using the Trust Services Criteria. 3. Remembering & Understanding, Identify management assertions specific to the different categories and types (Type 1 and Type 2) of SOC engagements (SOC 1®, SOC 2®, SOC 3®). 4.
HIGH-FREQUENCY: The Trust Services Criteria (TSC) provide a framework for evaluating controls over systems. The TSC intentionally align with the COSO Internal Control-Integrated Framework (IC-IF) to leverage an established, widely-accepted...
Common mistakes
- Confusing SOC 1 and SOC 2 purposes. SOC 1 addresses ICFR-relevant controls; SOC 2 addresses trust services criteria. A cloud storage provider needs SOC 2 (security, confidentiality); a claims processor affecting insurance reserves needs SOC 1.
- Assuming Type 1 tests operating effectiveness. Type 1 covers design and implementation only. Operating effectiveness testing requires Type 2: sampling transactions across the period, not just verifying controls exist at a point in time.
- Overlooking CUECs when evaluating SOC reports. A clean SOC 2 report is insufficient if user entities fail to implement CUECs. User entity auditors must test their organization's CUECs to complete the control evaluation.
Bottom line
- Trust Services Criteria align with COSO IC-IF through nine common criteria, plus category-specific criteria for availability, processing integrity, confidentiality, and privacy; security is foundational and always in scope for SOC 2
- SOC 1 addresses controls relevant to user entities' financial reporting (ICFR); SOC 2 addresses trust services categories; SOC 3 is a general-use SOC 2 summary; SOC for Cybersecurity reports on an entity's cybersecurity risk management program
- Type 1 reports test design and implementation at a point in time; Type 2 reports test operating effectiveness over a period (typically 6-12 months)
- Subservice organizations may be handled via the inclusive method (their controls tested within the report) or the carve-out method (excluded, with CSOCs identified for separate assurance)
Exam shortcut
SOC 1 = ICFR; SOC 2 = TSC. When the scenario involves financial statement audit reliance, think SOC 1. When it involves operational security, availability, or privacy concerns, think SOC 2. Type 1 = snapshot; Type 2 = movie. Type 1 tells you controls were designed as of a date. Type 2 tells you controls worked over a period.
The full lesson (about 6,143 words, 41 min read) adds 10 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- III.A1
Browse all free CPA ISC lessons or jump into free CPA ISC practice questions.