, ,

How to Review a SOC 1 Report: A User Entity’s Working Method

A SOC 1 report arrives as a PDF of eighty to two hundred pages, is filed in the vendor folder, and is cited in the workpapers as “SOC 1 obtained, no issues noted.” In a surprising number of those files nobody read past the opinion. The report covered nine months of a twelve-month year and no bridge letter was obtained. It listed six complementary user entity controls, of which the user entity operated two. It carved out the data-center provider that hosts the whole service. It disclosed exceptions in the very control objective the user entity was relying on. None of this is hidden; it is all in the report, in sections that were designed to be read by exactly the person who did not read them.

This guide is the user entity’s working method for a SOC 1 report: what the report is under SSAE 18 and what it is not, how its five sections are built and what to look for in each, a ten-question review that produces a defensible reliance conclusion, how to map complementary user entity controls to your own controls and test them, how to evaluate the service auditor’s exceptions for your purposes, what to do about period gaps and bridge letters, a review memo template, and a worked example at MidState Beverage, whose internal audit function reviewed its payroll provider’s report and found that two of four required user controls were not operating and the hosting provider was carved out with nothing behind it. It is written for internal auditors and SOX teams; the SOX ITGC scoping guide explains how service organizations enter scope in the first place, and the Third-Party Topical Requirement guide sets the minimum assessment expectations when third parties are the subject of an engagement.

In this guide

What a SOC 1 report is, and what it is not

A SOC 1 report is the product of an attestation engagement performed by a service auditor under AT-C section 320 of the AICPA’s attestation standards, as amended by SSAE 18, which applies to reports dated on or after 1 May 2017 and replaced SSAE 16. The section’s full title says what the report is for: reporting on an examination of controls at a service organization relevant to user entities’ internal control over financial reporting. That last phrase is the boundary. A SOC 1 report addresses controls at the service organization that matter to its customers’ financial statements: processing payroll, custodying assets, administering claims, hosting an ERP, running a loan servicing platform. It does not address security, availability or privacy for their own sake; that is the territory of a SOC 2 report under the Trust Services Criteria, and the two are not interchangeable however often a vendor offers one in place of the other. The international equivalent of SOC 1 is ISAE 3402, and reports issued under it are read the same way.

Two further distinctions decide what the report can do for you. A Type 1 report gives the service auditor’s opinion on whether the description of the system is fairly presented and whether the controls were suitably designed and implemented as of a specified date. A Type 2 report adds the auditor’s tests of operating effectiveness over a specified period and the results of those tests. Only a Type 2 report supports reliance on operating effectiveness; the auditing standards that govern the user side, AU-C section 402 for AICPA audits and AS 2601 for PCAOB audits, say so directly, and AS 2601 describes a Type 1 style report as providing understanding sufficient to plan but no evidence of operating effectiveness, and describes six months as the minimum useful period for a report on operating effectiveness. In practice Type 2 reports cover six to twelve months, and the review question is whether that period covers enough of your own year.

ReportStandardSubjectWho should read itWhat it supports
SOC 1 Type 1AT-C 320 (SSAE 18); ISAE 3402 internationallyDesign and implementation of controls relevant to user entities’ financial reporting, as of a dateUser entities and their auditorsUnderstanding and planning; no reliance on operating effectiveness
SOC 1 Type 2AT-C 320 (SSAE 18); ISAE 3402Design, implementation and operating effectiveness over a period, with tests and resultsUser entities, their internal auditors and SOX teams, their external auditorsReliance on the service organization’s controls for the period covered, subject to CUECs and exceptions
SOC 2 Type 1 or 2AT-C 205 with the Trust Services CriteriaSecurity and, optionally, availability, processing integrity, confidentiality, privacySecurity, risk and vendor management functionsAssessment of the vendor’s security program; not financial reporting reliance
SOC 3Trust Services Criteria, general-use reportSummary opinion without test detailMarketing and general assuranceVery little for an auditor; ask for the SOC 2

What the report is not is a substitute for your own controls. Every SOC 1 report assumes that the user entity operates certain controls of its own, lists them, and tells you that the service organization’s control objectives cannot be achieved unless you do. The report also covers only the service and system described in it, only the period stated, only the locations and entities named, and only the subservice organizations that were included rather than carved out. Reading a SOC 1 report is the process of finding each of those limits and deciding what to do about it.

The anatomy of the report: five sections and what to read in each

SOC 1 reports follow a standard structure: the service auditor’s report, management’s assertion, management’s description of the system, the auditor’s tests of controls and results, and other information provided by the service organization that is not covered by the opinion. The order of reading is not the order of the document. Start with the opinion for scope, period and modifications; go to the description for the boundaries, the control objectives and the complementary user entity controls; then read every line of the tests and results; and only then read the other information, which is where the service organization puts management responses, planned changes and anything else it wants you to see without the auditor’s opinion attached. The table gives, for each section, what to extract and what should stop you.

SectionWhat to extractWhat should stop you
1. Service auditor’s report (opinion)Report type; period or date; entity, system and locations covered; opinion type (unmodified, qualified, adverse, disclaimer); emphasis-of-matter and other paragraphs; subservice organizations and the method used; reference to CUECsQualified or adverse opinion; period ending more than three months before your year-end; a system or entity name that is not the one you use; the phrase “carve-out” against a provider that hosts the whole service
2. Management’s assertionConfirmation that management asserts the description is fair and the controls were designed and operated effectively; the criteria used; the same subservice and CUEC statementsAssertion scope narrower than the opinion; qualifications in the assertion
3. Description of the systemServices and system boundaries; processing flow; control objectives; controls; complementary user entity controls; complementary subservice organization controls; significant changes during the periodControl objectives that do not cover the process you rely on; CUECs you do not recognize; changes to systems during the period; the service you use described as out of scope
4. Tests of controls and resultsFor every control: the test performed, the sample, the result; every exception with the auditor’s description and management’s responseExceptions in objectives you rely on; “no exceptions noted” on controls tested by inquiry only; sample sizes inconsistent with the frequency described
5. Other informationManagement’s responses to exceptions; business continuity statements; planned system changes; anything presented as assurance that the auditor did not opine onMaterial claims about controls that appear only here; responses that dispute the exception rather than remediate it

One reading habit pays for itself: match the control objectives in section 3 to the tests in section 4 before you read any results. Each objective should have controls beneath it and each control should have a test with a stated result. Objectives with controls that were tested only by inquiry, controls described in section 3 that do not appear in section 4, and tests whose sample size is one for a control described as operating daily are all signs that the assurance is thinner than the page count suggests. The service auditor’s testing is evidence; the depth of it is something you assess, not something you assume.

The ten-question review

The review reduces to ten questions answered in order, each with evidence, ending in a reliance conclusion. Answering all ten takes two to four hours for a typical report and produces a memo that will satisfy an external auditor, a regulator and an external quality assessment; skipping to the opinion takes five minutes and produces the workpaper described in the first paragraph of this guide. The questions are laid out in the table with the evidence each requires and the action if the answer is wrong. They are the skeleton of the memo template later in the guide.

#QuestionWhere the answer isIf the answer is wrong
1Is this the right report: the legal entity we contract with, the service and system we actually use, the locations that process our data?Opinion paragraph 1; description section 3 boundariesObtain the correct report; if the service used is out of scope, no reliance and alternative procedures
2Is it a Type 2 report, and does the period cover enough of our financial year?Opinion; period stated on the cover and in the assertionType 1: planning only. Gap over three months: bridge letter plus inquiry, or additional procedures, or the next report
3Is the opinion unmodified, and are there emphasis or other-matter paragraphs?Opinion sectionQualified or adverse: identify the affected objectives and treat them as untested for our purposes
4Do the control objectives cover the processes, transactions and assertions we rely on the provider for?Section 3 control objectives mapped to our risk and control matrixUncovered processes are our own control gap; design compensating controls or test the provider directly
5What did the auditor test under each relevant objective, how, with what samples, and what were the results?Section 4, line by lineInquiry-only or trivial samples on controls we rely on: reduced reliance; exceptions evaluated under question 6
6What does each exception mean for us, given our own controls and the transactions affected?Section 4 exceptions; section 5 responses; our own control matrixExceptions with no compensating user control affecting material amounts: additional procedures and possibly a deficiency of our own
7Which complementary user entity controls are we expected to operate, and do we, with evidence?Section 3 CUEC list; our control inventoryUnoperated CUECs are our deficiencies; the service organization’s objectives are not achieved on our side
8Which subservice organizations are carved out, what do they do for the service, and what assurance covers them?Opinion and section 3 subservice statements; CSOCsObtain the subservice organization’s report or accept an assurance gap explicitly
9What changed: during the period per section 3, after it per the bridge letter, and in our own use of the service?Section 3 changes; bridge letter; our vendor management recordsSignificant changes after the period: inquiry and additional procedures until the next report
10What is our conclusion on reliance, what additional procedures does it require, and who owns them?The review memoConclusion documented as full, partial or no reliance with the procedures listed and assigned

Question 4 is the one most reviewers underestimate. A payroll provider’s report may have twelve control objectives covering input, processing, output, tax filing, access, change and operations. If the user entity relies on the provider to calculate withholding but not to approve pay-rate changes, the objectives that matter are the calculation, processing and output ones, and an exception in tax filing may be irrelevant while an exception in output distribution is central. The mapping of objectives to the user entity’s own risk and control matrix is what makes the rest of the review specific rather than generic, and it is the mapping an external auditor will ask to see.

Complementary user entity controls: the part of the report that is about you

Complementary user entity controls are the controls the service organization’s description says the user entity must operate for the control objectives to be achieved. They are listed because the service organization cannot operate them: it cannot approve your employees’ pay rates, decide who at your company may submit files, review your output reports for reasonableness, or remove your terminated staff from its portal. The list is short, usually five to fifteen items, and it is the single most actionable part of the report, because every item is either a control you can evidence or a gap you own. It is also the part most often ignored, on the reasoning that the report is about the vendor. It is about the vendor’s controls and yours together; the auditor’s opinion is explicitly conditional on the CUECs operating.

The method is a mapping table, one row per CUEC, that identifies the user entity control that satisfies it, the owner, the evidence, whether it was tested in the period and the result. Where no control exists, the row records a gap and the compensating action. Where a control exists but has not been tested, the CUEC becomes a test in the user entity’s own program, using the ordinary design and operating effectiveness approach. The table below is an illustrative mapping for a payroll service; the CUEC wording is typical of what such reports contain. Note that several CUECs are ordinary user access and review controls that the user entity may already test elsewhere; the mapping simply makes the connection explicit and points at the evidence.

CUEC as stated in the reportUser entity controlOwnerEvidenceTested in periodResult
User entities are responsible for approving payroll input, including new hires, terminations and pay-rate changes, before submissionDepot manager and HR approval of change forms; HR reconciles submitted file to approved formsHR managerApproved change forms; reconciliation sign-offYes2 of 40 rate changes lacked HR approval; finding raised
User entities are responsible for reviewing payroll registers and output reports for accuracy and completeness prior to fundingPayroll accountant reviews register against submitted input and prior period; controller approves fundingControllerSigned review checklist; funding approvalYesNo exceptions
User entities are responsible for restricting access to the service portal to authorized personnel and for timely removal of terminated usersPortal access requests approved by HR manager; quarterly review of portal users against HR recordsHR managerAccess request records; quarterly review evidenceNot testedGap: no quarterly review performed in the period; three terminated users active
User entities are responsible for the accuracy of master data, tax jurisdictions and general ledger mappings provided to the service organizationAnnual review of mappings by the controllerControllerSigned mapping reviewNoGap: no review since implementation
User entities are responsible for reviewing and responding to exception and rejection reports provided by the service organizationPayroll accountant clears rejection report each cyclePayroll accountantCleared reports with initialsYesNo exceptions

Evaluating the service auditor’s exceptions for your purposes

An exception in section 4 is a fact about the service organization; what it means for you is a judgment you have to make and document. The service auditor evaluated it against the control objective and concluded, in most reports, that the objective was still achieved, which is why the opinion stayed unmodified. That conclusion was reached for the population of all user entities and all transactions, and it is not yours. Your evaluation asks four things: whether the exception falls within an objective you rely on, whether the transactions or period affected include yours, whether a control on your side would have caught the consequence, and what the exposure is in your financial statements if nothing caught it. The control deficiency evaluation guide supplies the framework; the specific application is that the compensating control is usually a CUEC, which is why questions 6 and 7 are answered together.

Exception as reportedRelevant to us?Compensating user controlEvaluation and action
For 2 of 40 program changes sampled, evidence of testing prior to implementation was not retainedYes: changes to the payroll calculation engine affect our payPayroll register review against prior period and input would detect a calculation error above a small thresholdLimited reliance on the change objective; confirm the register review operated in the affected months; no additional procedures if it did
For 1 of 25 terminated service organization employees sampled, portal access was removed 9 days after terminationPartly: internal access at the providerNone on our side for provider staffNote as a provider weakness; consider whether the provider’s monitoring controls were tested without exception; no user-side action
Quarterly reconciliation of tax deposits to filings was not performed for one quarterYes if we rely on the provider for tax filingOur review of quarterly tax filing confirmationsIf we performed the review, reliance maintained; if not, obtain filing confirmations for the quarter
Backup restoration test was not performed during the periodYes: availability of our payroll dataOur own retention of submitted files and registersConfirm we could re-run from our copies; raise with the provider through vendor management

Period gaps, bridge letters and what they do not cover

Service organizations choose their report periods for their own convenience, and the period rarely ends on your year-end. A report covering 1 October to 30 September read by a company with a 31 December year-end leaves a three-month gap during which the tested controls may or may not have continued to operate. The conventional instrument for the gap is the bridge letter, also called a gap letter: a letter from the service organization’s management, not from its auditor, stating that management is not aware of material changes in the control environment since the end of the report period, or describing the changes that have occurred. Its limits should be understood precisely. It is a management representation; the service auditor has performed no procedures on the gap period and does not sign it. It is generally accepted for a gap of up to about three months; beyond that, the user entity and its auditors expect additional procedures. And it is not a substitute for the report: it contains no description, no tests and no results, and it is read alongside the report, never instead of it.

Where the gap is longer, where the bridge letter discloses changes, or where the user entity’s own knowledge suggests something changed, a system migration, a new module, a change of ownership at the provider, the review documents additional procedures: inquiry of the provider about the nature of the changes, evidence that user-side controls operated through the gap, and where the reliance is material, waiting for the next report before concluding. The same logic applies at the start of the period. If the prior report ended on 30 September of the previous year and this one begins on 1 October, continuity is fine; a provider that changed auditors and left an uncovered quarter has left you an uncovered quarter.

Subservice organizations: carve-out, inclusive and the report behind the report

Most service organizations use other service organizations: a cloud provider for hosting, a data center, a payment processor, a print-and-mail vendor. The report handles them in one of two ways. Under the inclusive method, the subservice organization’s relevant controls are included in the description and tested, and the opinion covers them. Under the carve-out method, the description identifies the subservice organization and the services it provides, states that its controls are excluded, and lists the complementary subservice organization controls, the controls the service organization assumes the subservice organization operates. Carve-out is far more common, and it means that the report you are reading says nothing about the controls at the company that physically holds your data.

The user entity’s response is to follow the chain. For each carved-out subservice organization, identify what it does for the service, decide whether that matters to your reliance (hosting usually does; print-and-mail may not), and obtain its own SOC report, mapping the CSOCs in the primary report to controls tested in the subservice report. Where the subservice organization is a major cloud provider, its SOC 1 report is available on request and the mapping is largely a matter of confirming that the services and regions used are in scope. Where it is a small data center with no report, the gap is real and should be recorded as such, with whatever alternative assurance exists: the service organization’s own vendor management evidence over the subservice organization, or direct inquiry. The cloud audit guide covers reading a cloud provider’s report, and the backup and recovery guide is the reference for what the hosting layer must demonstrate.

The SOC 1 review memo template

The memo is one to three pages, completed for every SOC 1 report relied on, filed with the report and the bridge letter, and updated when the next report arrives. It follows the ten questions. Two attachments carry the detail: the control objective mapping and the CUEC mapping table. The version below is written to be copied into the workpaper system as it stands; the bracketed text is guidance to delete. The workpaper example shows how a completed memo sits in a file, and the templates directory lists the companion documents.

SOC 1 report review memo. Service organization: ________ Service and system: ________ Report type and period: ________ Service auditor: ________ Reviewed by: ________ Date: ________ Approved by: ________ Date: ________

1. Reliance context. [Which of our processes, accounts and assertions depend on this service; reference to our risk and control matrix; materiality of the transactions processed.]

2. Report identification (question 1). [Legal entity, system, locations and services covered, compared with our contract and actual use. Conclusion: the report covers / does not cover the service we use.]

3. Type and period (question 2). [Type 2 confirmed. Period ________ to ________ against our financial year ________ to ________. Gap of ________ months. Bridge letter dated ________ obtained / not obtained; changes disclosed: ________. Continuity with the prior report: ________.]

4. Opinion (question 3). [Unmodified / qualified / adverse / disclaimer. Emphasis or other-matter paragraphs and their effect on us.]

5. Control objective coverage (question 4). [Attachment A maps each control objective to our processes and assertions. Objectives relied on: ________. Processes we rely on that no objective covers: ________ and the compensating control or additional procedure for each.]

6. Tests and results (question 5). [For the objectives relied on: nature of testing, sample sizes, results. Controls tested by inquiry only: ________. Exceptions: see section 7.]

7. Exception evaluation (question 6). [Each exception: relevance to us, transactions and months affected, compensating user control and whether it operated, exposure, conclusion and action.]

8. Complementary user entity controls (question 7). [Attachment B maps each CUEC to our control, owner, evidence, testing and result. CUECs not operated: ________ and the deficiency raised for each.]

9. Subservice organizations (question 8). [Each carved-out organization, its service, relevance to our reliance, the report obtained or the gap accepted, CSOC mapping.]

10. Changes (question 9). [Changes during the period per the description; after the period per the bridge letter; in our own use of the service.]

11. Conclusion (question 10). [Full reliance / reliance limited to objectives ________ / no reliance. Additional procedures required, owner and due date. Findings raised on our side. Date the next report is due and who will obtain it.]

Worked example: MidState Beverage reviews its payroll provider’s report

MidState Beverage, the three-state drinks distributor that appears throughout this site’s examples, runs payroll for roughly 1,400 employees through a cloud payroll provider that calculates pay, files payroll taxes and produces the general ledger interface file. The provider’s SOC 1 Type 2 report covers 1 October to 30 September; MidState’s financial year ends 31 December. As part of the FY27 ICFR support engagement, the six-person internal audit function reviewed the report for the first time using the ten questions, having previously recorded it in the vendor file with the note that it had been obtained. The review took the senior auditor a day and a half including the CUEC testing.

Questions 1 to 3 were clean: the correct entity and platform, a Type 2 report, an unmodified opinion with one emphasis paragraph noting a platform migration completed during the period. Question 2 also identified a three-month gap to year-end with no bridge letter on file; the provider supplied one within a week, disclosing no material changes. Question 4, the mapping of the eleven control objectives to MidState’s own matrix, showed that MidState relied on five: input processing, calculation, output and distribution, tax filing and payments, and logical access. Question 5 found two exceptions in relevant objectives: 2 of 40 sampled program changes lacked retained test evidence, and for 1 of 25 sampled provider employees portal access was removed nine days after termination. Question 6 concluded that MidState’s payroll register review would have detected a material calculation error and that the provider-side access exception had no user-side consequence; both were recorded with the reasoning.

Question 7 was where the review earned its keep. The report listed four complementary user entity controls: approval of payroll input before submission, review of registers and output before funding, restriction and timely removal of portal access, and maintenance of master data and mappings. MidState operated the first two with evidence. The quarterly portal access review required by the third had never been performed; a comparison of the 23 portal users to HR records found three terminated depot staff with active accounts, one of them a former depot administrator with the right to submit files, which connected directly to the access-removal finding already being pursued in the FY27 ERP user access engagement. The mapping review required by the fourth had not been done since implementation four years earlier, and the general ledger mapping still directed one benefit expense to an account that had been retired. Question 8 found the provider’s hosting carved out to a cloud infrastructure provider; MidState obtained that provider’s report and confirmed the relevant regions and services were in scope. Question 9 noted the platform migration and confirmed through the register review evidence that MidState’s controls had operated through it.

QuestionResultAction
1 Right reportCorrect entity, platform and locationsNone
2 Type and periodType 2; 1 Oct to 30 Sep; three-month gap; no bridge letter on fileBridge letter obtained (no material changes); vendor file updated with the due date for next report
3 OpinionUnmodified; emphasis paragraph on platform migrationChange evaluated under question 9
4 Objective coverage5 of 11 objectives relied on; all relevant processes coveredMapping filed as Attachment A
5 Tests and resultsRelevant objectives tested with samples of 25 to 40; two exceptionsEvaluated under question 6
6 ExceptionsProgram change evidence gap detectable by register review; provider access exception not relevant to user sideRegister review evidence for the affected months verified; no further action
7 CUECs2 of 4 operated; portal access review never performed (3 terminated users active); mapping review never performed (retired account mapped)Two findings raised (Medium, Low); access removed same day; mapping corrected and annual review assigned to the controller
8 Subservice organizationsHosting carved out; cloud provider report obtained and scopedCSOC mapping filed
9 ChangesPlatform migration in period; no post-period changes per bridge letterUser controls confirmed through migration months
10 ConclusionReliance on the five objectives for the period, conditional on the two CUEC findings being remediatedMemo approved by the CAE; next review scheduled for report delivery

The two findings were small in isolation and significant in pattern: the payroll portal was the third system in FY27 where terminated staff had kept access, which is why the root cause recorded for the finding was the absence of a termination feed from HR to system owners rather than a payroll-specific lapse, and why the recommendation was the enterprise one already in progress. The CAE’s note to the audit committee made a different point: the report had been in the vendor file for four years, and this was the first year anyone had read section 3.

Common mistakes

  • Reading only the opinion. The opinion tells you the auditor’s conclusion for all user entities. Your conclusion depends on sections 3 and 4.
  • Accepting a SOC 2 for financial reporting reliance. Different standard, different subject. A SOC 2 says nothing about the control objectives that matter to your financial statements.
  • Ignoring the period. A report ending three months before your year-end with no bridge letter leaves a quarter uncovered; longer gaps need procedures, not letters.
  • Treating the bridge letter as assurance. It is a management representation about changes. The service auditor did nothing for the gap period.
  • Not mapping control objectives to your own matrix. Without the mapping you cannot say which exceptions matter or which processes are uncovered.
  • Skipping the CUECs. They are your controls. Every CUEC you do not operate is your deficiency and undermines the opinion you are relying on.
  • Accepting the service auditor’s evaluation of exceptions as your own. Re-evaluate each exception against your transactions and your compensating controls.
  • Stopping at the carve-out. Follow the chain to the subservice organization’s report, especially for hosting.
  • Filing without a memo. A report in the vendor folder is not a review. The memo with its two attachments is the workpaper.
  • Reviewing once and never again. Reports are annual; the review, the bridge letter and the CUEC testing recur every year.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading