These reports are used for evaluating the effect of the controls at the service organization on the user entities’ financial statements
These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems. These reports can play an important role in:
This report extended beyond the SOC 2 trust service criteria (Security, Confidentiality, Process Integrity, Availability and Privacy) to focus on other respected business related regulatory and compliance frameworks, like HIPPA, NIST or GDPR.
These reports are designed to meet the needs of users who need assurance about the controls at a service organization relevant to security, availability, processing integrity confidentiality, or privacy, but do not have the need for or the knowledge necessary to make effective use of a SOC 2 Report. Because they are general use reports, SOC 3 reports can be freely distributed.
Obtaining a SOC report differentiates the service organization from its peers by demonstrating the establishment of effectively designed internal corporate governance and oversight.
The Accorp Partners Service Organization Control (SOC) compliance service provides a wide range of assurance services in the form of SOC 1 Type I Type II report, SOC 2 Type I & Type II report and SOC 3 reports which broadly cover trust and transparency issues by incorporating risk management. We provide financial and nonfinancial reporting options to service organizations and the organizations can go with any of the SOC attestation and reports as per their organization’s objectives and their user entity’s objective and we also ensure that the organization would implement the right set of business and IT controls and convey correct information to user entity and their stakeholders which enhance the organizations Governance and monitoring standard.
Accorp has a team of professionals who has rich expertise in almost all Business and IT processes and can bring insight to the reporting process. Additionally, a skilled and independent auditor will assist your company in navigating the challenges and complexities of SOC reporting and attestation .
|Domain||Trust Services Principle||Applicability|
|Security||Under this Trust service principle, the SOC scoped IT system and Business services are protected against unauthorized access that addresses physical and logical both ways of access.||
|Availability||This trust service principle ensure that the IT and Business system should be available for operation and provide services as committed or agreed with the client and respected stake holders.||
|Confidentiality||This trust service principle addresses that the Information which are designated as confidential should be protected adequately as committed or agreed by the stakeholders.||
|Processing Integrity||This trust service principle addresses that the System processing is complete, accurate, timely and authorized.||
|Privacy||This trust service principle ensures that the Personal information is adequately collected, stored, used, disclosed and purged in compliance with the commitments as per the user entity’s privacy notice and by setting up a criterion set forth in normally accepted privacy principles in accordance with AICPA.||
|Define audit scope, and overall project time line||Provide overall project plan|
|Identify existing or required controls through discussions with management, and review of available documentation||Complete advance data collection before on-site work to accelerate the audit process|
|Perform readiness review to identify gaps requiring management attention||Conduct on-site meetings, and testing|
|Communicate prioritized recommendations to address any identified gaps||Complete off-site analysis of collected information|
|Hold working sessions to discuss alternatives, and remediation plans||Conduct weekly reporting of project status, and any identified issues|
|Verify that gaps have been closed before beginning the formal audit phase||Provide a draft report for management review, and electronic, and hard copies of the final report|
|Determine the most effective audit, and reporting approach to address the service provider’s external requirements||Provide an internal report for management containing any overall observations, and recommendations for consideration|
A SOC 2 Type I audit is an audit reporting on the policies and procedures a company has established at a particular point in time. It is generally the first step taken and is often referred to as “test of design.” It will answer the question, “are the controls properly in place?” A SOC 2 Type II audit is a “test of effectiveness” over a period of time. The “period of time” is generally no less than 6 months and no more than a year. It will answer, “is your company following its own policies?”
SOC 2 preparation usually happens in a few stages. First, your company should identify all “key systems” and perform a gap analysis against all requirements documented in the Trust Services Principles and Criteria. Next, existing security controls should be identified and policies and procedures should be written to meet all requirements. This can take anywhere from a few weeks to up to 6 months, depending on the size and maturity of your company. At this point you are ready for the SOC 1 Type I audit. A SOC 2 Type II audit is typically performed 6 months later.
|Traditional SAS 70||SOC 1||SOC 2||SOC 3|
|Auditor’s Opinion||Auditor’s Opinion||Auditor’s Opinion||Auditor’s Opinion|
|-||Auditor’s Opinion||Management Assertion||Management Assertion|
|Assertion System Description (including controls)||System Description (including controls)||System Description (including controls)||System Description (including controls)|
|Control objectives||Control objectives||Criteria||Criteria (referenced)|
|Control activities||Control activities||Control activities||-|
|Tests of operating effectiveness||Tests of operating effectiveness||Tests of operating effectiveness||-|
|Results of tests||Results of tests||Results of tests||-|
|Other Information (if applicable)||Other Information (if applicable)||Other Information (if applicable)||-|
Trust and Transparency Solutions Leader, Accorp
Trust and Transparency Solutions Client and Markets Leader, Accorp uss