The cost most teams miss
The attestation fee is not the only cost of SOC 1.
Internal time can become the larger burden when scope is unclear, evidence is requested repeatedly or business-process and IT teams are not coordinated.
SOC 1 Attestation Services
SC US performs independent SOC 1 examinations for service organizations whose systems and processes may affect their customers' financial reporting.
Our auditors evaluate relevant business-process controls and supporting IT controls, then issue formal reports that customers and their financial statement auditors can use when assessing outsourced activities.
Independent assurance over outsourced processes that affect financial reporting
When customers outsource transaction processing, payroll, claims, fund administration, billing or other financially relevant activities, their auditors still need evidence that the supporting controls are appropriately designed and operating.
A SOC 1 report provides that evidence in a format designed for management, user entities and user auditors.
Senior assurance judgment, specialist depth and a process designed to reduce disruption
SOC 1 work must connect operational processes, financial reporting risks and supporting technology. Our approach focuses on producing a report that is technically reliable and practical for the teams responsible for supplying evidence.
The cost most teams miss
Internal time can become the larger burden when scope is unclear, evidence is requested repeatedly or business-process and IT teams are not coordinated.
How SC US reduces the burden
Experienced professionals remain involved from scoping and walkthroughs through issue resolution, technical review and report issuance.
As an independent CPA firm focused on assurance and compliance engagements, SC US delivers authoritative SOC reports supported by technical expertise, independence and rigorous execution. Our Ontario CPA firm registration can be verified through CPA Ontario's public directory.
Our professionals bring major-firm experience while providing the accessibility, guidance and personal attention that a focused boutique practice can deliver.
Our partner contributed to CPA Canada's SOC guidance, our SOC 1 reporting is used in university case studies to train future auditors, and our cybersecurity thought leadership has appeared through leading professional and business publications. Explore these materials in our resources section.
Coordinate SOC 1 and SOC 2 when customers need assurance over both financial and technology controls
SOC 1 and SOC 2 are separate examinations, but they may rely on the same systems, people, access controls, change processes and service providers. Coordinated planning reduces duplicate requests while preserving the distinct purpose and reporting requirements of each engagement.
Discuss Combined SOC ReportingAn independent report on controls relevant to user entities' financial reporting
A SOC 1 report describes a service organization's system and evaluates controls that may be relevant to customers' internal control over financial reporting.
The report is commonly used by customer management and their financial statement auditors to understand outsourced processes, evaluate control design and, for Type II, consider the results of operating-effectiveness testing.
SOC 1 is not a general cybersecurity certification. Its scope is driven by the services performed and how those services could affect customers' financial statements.
Both reports address the description and design of controls. Type II adds evidence about whether those controls operated effectively throughout a defined period.
Evaluates whether the system description is fairly presented and controls are suitably designed as of a specific date.
Evaluates design and tests whether controls operated effectively throughout the specified review period.
The examination follows the financial reporting risks created by the services you perform
SOC 1 does not use a fixed list of criteria like SOC 2. The report is organized around control objectives that reflect the service, transaction flows and risks relevant to customer financial reporting.
Controls over authorization, completeness, accuracy, timeliness and recording of transactions processed for customers.
Controls restricting logical and privileged access to applications, infrastructure and financially relevant data.
Controls over the development, approval, testing and deployment of changes affecting the service.
Controls supporting job processing, monitoring, incident management, backups and service continuity.
Controls identifying processing errors and supporting management review of financially relevant information.
SOC 1 support built around your current reporting requirement
Some organizations are preparing their first report. Others are moving into Type II, improving an established annual cycle or transitioning from another auditor. We shape the engagement around the stage you are in and the assurance your customers and their auditors need next.
Define the service, transaction flows, control objectives and reporting boundary for a credible first examination.
Build on the documented control environment and demonstrate that controls operated effectively throughout the review period.
Protect reporting continuity while improving how evidence, scope changes and customer requirements are managed.
Detailed guidance on scope, testing, reporting and customer reliance
The answers below are written to help management, customers and user auditors understand how a SOC 1 engagement works.
A SOC 1 attestation is an independent examination of controls at a service organization that are relevant to user entities internal control over financial reporting. The auditor evaluates management's description of the system and the design of the controls. For a Type II report, the auditor also tests whether those controls operated effectively throughout a defined period.
A SOC 1 report is commonly needed when a service organization performs processes that can affect how customers record transactions, maintain accounting records or prepare financial statements. Common examples include payroll processors, claims administrators, payment processors, fund administrators, loan servicers, benefits administrators, data centers and technology platforms that process financially relevant information.
SOC 1 focuses on controls relevant to customer financial reporting. SOC 2 focuses on controls related to Security and, where relevant, Availability, Processing Integrity, Confidentiality and Privacy. The correct report depends on the risks customers and their auditors need addressed. Some service organizations require both reports because they support financial processes and also handle sensitive systems or data.
A Type I report evaluates whether the system description is fairly presented and the controls are suitably designed as of a specified date. A Type II report covers a defined period and also evaluates whether the controls operated effectively throughout that period. User auditors generally place greater reliance on Type II because it includes tests of operating effectiveness.
Not always. Type I can be useful for a first-time examination, a newly implemented control environment or an immediate customer requirement. An organization may proceed directly to Type II when the controls are established, have operated throughout the proposed review period and supporting evidence is available. The appropriate path depends on the maturity of the controls, customer expectations and the required reporting date.
Control objectives state the outcomes that the service organization's controls are intended to achieve in relation to customer financial reporting. For example, a control objective may address whether transactions are authorized, processed completely and accurately, or whether system access is restricted appropriately. Management defines the objectives based on the services provided and the financial reporting risks relevant to user entities.
The scope is based on the services, systems, processes, people, locations and third parties that support the control objectives relevant to user entities financial reporting. The scope should include what customers and their auditors rely on, while excluding unrelated activities that do not affect the relevant financial reporting risks.
Evidence depends on the controls in scope and may include approvals, reconciliations, access listings, change records, exception reports, transaction samples, review sign-offs, system reports, incident records, vendor oversight documentation and management review evidence. The evidence should show that the control occurred, who performed it, when it occurred, what was reviewed and how exceptions were resolved.
Complementary user entity controls are controls that customers are expected to implement so the service organization's controls can achieve the stated control objectives. Examples may include reviewing reports provided by the service organization, approving user access, reconciling transactions or notifying the service organization of changes. These responsibilities are described in the SOC 1 report so customers and their auditors understand the complete control environment.
A subservice organization is a third party that performs functions relevant to the services or controls described in the SOC 1 report. Examples may include cloud hosting providers, data centers, payment processors or outsourced operational providers. Management determines whether the third party is addressed using the carve-out method or the inclusive method, depending on the nature and significance of the services provided.
Under the carve-out method, the functions performed by a relevant subservice organization are described, but the subservice organization's controls are excluded from the service auditor's examination. The report identifies complementary subservice organization controls that are expected to operate at that provider. User entities and their auditors may need the subservice organization's own assurance report to complete their evaluation.
Timing depends on the report type, system complexity, number of control objectives, evidence readiness and responsiveness of the teams involved. A Type I examination can begin once the controls are implemented and the system description is ready. A Type II examination includes an observation period, followed by fieldwork, evaluation of results and report preparation. The timeline should distinguish readiness work, the review period, control testing and final reporting.
The appropriate period depends on customer and user auditor expectations, the maturity of the control environment and the reporting objective. First-time reports may use a shorter period, while established annual programs commonly cover a longer period. Controls must operate throughout the period, and evidence should be retained at the frequency stated in the control description.
An exception occurs when a control did not operate as described or the evidence did not support its operation. The auditor evaluates the nature, frequency, cause and potential effect of the exception, including whether compensating controls exist. An exception does not automatically result in a modified opinion, but relevant exceptions are generally described in a Type II report together with management's response where appropriate.
SC US can explain the reporting requirements, provide general observations and perform permitted readiness activities while preserving the independence required for the attestation engagement. Management remains responsible for defining the system, selecting control objectives, designing and operating controls, preparing the system description and making management's assertion.
Yes. The reports address different risks, but many controls and evidence sources may overlap, particularly in access management, change management, system operations, vendor oversight and incident response. A coordinated approach can align schedules and evidence requests while preserving the separate scope, testing and reporting requirements of each examination.
A SOC 1 Type II report may allow customers and their auditors to use the service auditor's testing as part of their assessment of controls relevant to financial reporting. The degree of reliance depends on the report period, scope, control objectives, test results, complementary user entity controls and the user auditor's professional judgment.
Organizations should consider whether the firm is appropriately licensed, experienced with SOC reporting and familiar with the financial processes and technology environment being examined. Other important factors include senior involvement, the quality of scoping, clarity of evidence requests, communication during fieldwork, report quality and the firm's ability to coordinate related SOC 2, ITGC or financial audit requirements.
Be prepared to discuss the services provided, customer and auditor requirements, report type, proposed review period, legal entity, systems and locations in scope, key financial processes, major service providers, existing controls, prior reports and target issuance date. This information allows SC US to define the scope, timeline and level of effort accurately.
Start Your SOC 1 Attestation
Tell us whether you need Type I, Type II or help determining whether SOC 1 is the right report. We will discuss the services in scope, control objectives, customer expectations and target report date.
Your inquiry has been captured in this prototype. Connect the form to your CRM or email workflow before launch.
