17.3 Service Organization Controls: SOC 1 & SOC 2 Engagements (AT-C 320)
Key Takeaways
- When an entity outsources core business functions (e.g., payroll, cloud computing, loan servicing), the service organization's controls become part of the user entity's information system and internal control over financial reporting (ICFR).
- SOC 1 reports (governed by AT-C 320 under SSAE) evaluate controls relevant to user entities' internal control over financial reporting (ICFR), whereas SOC 2 reports evaluate controls relevant to the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy).
- A Type 1 report assesses management's description and the suitability of the design of controls as of a specific date (point in time), providing zero evidence of operating effectiveness and precluding the user auditor from reducing assessed control risk below maximum.
- A Type 2 report assesses management's description, the suitability of design, and the operating effectiveness of controls throughout a specified period (commonly at least six months), allowing the user auditor to assess control risk below maximum and reduce substantive testing.
- Complementary User Entity Controls (CUECs) are controls that the service organization assumes user entities will implement; the user auditor must verify that the user entity has designed and implemented these controls for the service organization's controls to be effective.
17.3 Service Organization Controls: SOC 1 & SOC 2 Engagements (AT-C 320)
Core Principle: Modern organizations routinely outsource mission-critical processes—such as payroll processing, healthcare claims management, cloud data storage, software-as-a-service (SaaS) ERP, and 401(k) plan administration—to specialized third-party service organizations. Under AU-C 402 (Audit Considerations Relating to an Entity Using a Service Organization) and AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting), the service organization's controls are treated as part of the user entity's own information system.
1. The Outsourcing Ecosystem: Key Definitions & Participants
Auditing client accounts that rely on outsourced service providers requires understanding the four distinct roles defined in professional standards:
THE SERVICE ORGANIZATION AUDIT ECOSYSTEM
+-----------------------------+ +-----------------------------+
| USER ENTITY | Outsources Core Functions | SERVICE ORGANIZATION |
| (Client being audited; | ----------------------------> | (Third-party vendor; e.g., |
| e.g., Manufacturing Co.) | <---------------------------- | ADP, AWS, Fidelity, SaaS) |
+-----------------------------+ Provides Processed Data +-----------------------------+
| |
| Audits Financial | Examines Internal
| Statements | Controls (AT-C 320)
v v
+-----------------------------+ +-----------------------------+
| USER AUDITOR | Reviews SOC 1 / SOC 2 | SERVICE AUDITOR |
| (Independent CPA firm | <---------------------------- | (Independent CPA firm |
| auditing User Entity FS) | Report for Audit Evidence | auditing Service Org) |
+-----------------------------+ +-----------------------------+
The Four Core Participants
- User Entity: The entity that engages a service organization and whose financial statements are being audited by an independent CPA (e.g., a manufacturing company that outsources payroll to ADP).
- Service Organization: The third-party organization (or segment thereof) that provides services to user entities that affect the user entities' information systems relevant to financial reporting or trust criteria.
- User Auditor: The independent auditor who audits and reports on the financial statements of the user entity.
- Service Auditor: The independent practitioner who examines and reports on the controls of the service organization under the SSAE attestation framework.
2. SOC 1 vs. SOC 2 vs. SOC 3: Comparative Framework
The AICPA established the Service Organization Control (SOC) reporting suite to address different user needs, compliance scopes, and distribution criteria:
+---------------------------------------------------------------------------------------------------------+
| THE SOC REPORTING SUITE COMPARISON MATRIX |
| |
| DIMENSION: SOC 1 (AT-C 320) SOC 2 (AT-C 105/205) SOC 3 |
| --------------------------------------------------------------------------------------------------- |
| Primary Focus Internal Control Over Trust Services Criteria Trust Services |
| FINANCIAL REPORTING (ICFR) (TSC): Security, Privacy, etc Criteria (Summary)|
| |
| Authoritative Standard SSAE: AT-C Section 320 SSAE: AT-C Sections 105/205 SSAE: AT-C 105/205 |
| |
| Report Purpose Evaluate vendor controls Evaluate tech, operational, Public marketing / |
| affecting user entity's FS data security governance general confidence |
| |
| Intended Users User Auditors and User Management, Regulators, General Public |
| Entity Management Business Partners (Unrestricted) |
| |
| Report Distribution RESTRICTED USE RESTRICTED USE GENERAL USE |
| (Users, auditors, vendor) (Specified parties only) (Freely available) |
| |
| Available Formats Type 1 or Type 2 Type 1 or Type 2 General Summary |
| (No test details) |
+---------------------------------------------------------------------------------------------------------+
SOC 1: Internal Control Over Financial Reporting (AT-C 320)
A SOC 1 engagement is specifically designed for service organizations whose services impact their clients' internal control over financial reporting (ICFR).
- Examples: Payroll processing services (ADP, Paychex), third-party loan servicing platforms for financial institutions, medical billing organizations, and trust/custody departments of banks.
- Examination Standard: Conducted under AT-C 320 by the service auditor, expressing an examination opinion on management's description of its system and the suitability of the design (and operating effectiveness in Type 2) of controls.
SOC 2: Trust Services Criteria
A SOC 2 engagement evaluates controls relevant to non-financial operational and technological safeguards based on the AICPA's Trust Services Criteria (TSC):
- Security (Common Criteria): The system is protected against unauthorized access, use, or modification (firewalls, multi-factor authentication, intrusion detection).
- Availability: The system is available for operation and use as committed or agreed (redundancy, disaster recovery, uptime SLAs).
- Processing Integrity: System processing is complete, valid, accurate, timely, and authorized.
- Confidentiality: Information designated as confidential is protected as committed or agreed (encryption of sensitive business data, intellectual property safeguards).
- Privacy: Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and privacy notices (compliance with privacy frameworks regarding personally identifiable information - PII).
SOC 3: General Use Public Summary
A SOC 3 report covers the exact same Trust Services Criteria as a SOC 2 report, but it is written as an executive summary for general use. It omits the detailed descriptions of tests performed by the service auditor and the resulting test results. Companies often display SOC 3 seals on their websites for public marketing.
3. Type 1 vs. Type 2 Reports: The Core Distinction
Both SOC 1 and SOC 2 reports can be issued in either a Type 1 or Type 2 format. Mastering this distinction is one of the most heavily tested areas on the CPA AUD examination.
+---------------------------------------------------------------------------------------------------------+
| TYPE 1 VS. TYPE 2 SOC REPORT COMPARISON |
| |
| FEATURE: TYPE 1 REPORT TYPE 2 REPORT |
| --------------------------------------------------------------------------------------------------- |
| Time Horizon AS OF A SPECIFIED DATE THROUGHOUT A SPECIFIED PERIOD |
| (Single point in time; e.g., (Commonly at least 6 months; |
| as of September 30, 2026) e.g., Jan 1 to Sept 30, 2026) |
| |
| Management's Description Fairly presents the system that Fairly presents the system that |
| Fairness Evaluation was designed and implemented was designed and implemented |
| |
| Suitability of Design Controls suitably designed to Controls suitably designed to |
| achieve control objectives achieve control objectives |
| |
| Operating Effectiveness NO TESTING of operating TESTS OPERATING EFFECTIVENESS; |
| Testing effectiveness performed includes detailed description of tests |
| and results of exceptions noted |
| |
| User Auditor Impact on CANNOT reduce control risk ALLOWS reduction of control risk |
| Assessed Control Risk below maximum (Provides ZERO below maximum (Supports reduced |
| evidence of effectiveness) substantive testing) |
+---------------------------------------------------------------------------------------------------------+
The Type 1 Report (Point-in-Time Design)
A Type 1 report consists of:
- Management's description of the service organization's system as of a specific date.
- The service auditor's opinion on whether management's description fairly presents the system that was designed and implemented as of that date.
- The service auditor's opinion on whether controls were suitably designed to achieve the stated control objectives as of that date.
- Crucial Rule: A Type 1 report provides zero evidence that controls operated effectively over time. It only confirms that controls were placed in operation and properly designed at that single instant.
The Type 2 Report (Period-Spanning Operating Effectiveness)
A Type 2 report includes everything in a Type 1 report, PLUS:
- Covers a specified period (typically a minimum of six consecutive months).
- The service auditor's opinion on whether controls operated with operating effectiveness throughout that period to provide reasonable assurance of achieving the control objectives.
- A detailed section listing the service auditor's tests of controls (nature, timing, extent) and the results of those tests (including any deviations or exceptions found).
4. The User Auditor's Utilization & Control Risk Assessment
When a user auditor audits a client whose financial transactions are processed by an outside service organization, the user auditor must obtain an understanding of the entity and its environment, including internal controls under AU-C 315 and AU-C 402.
USER AUDITOR WORKFLOW FOR SERVICE ORGANIZATIONS
|
+------------------------------+------------------------------+
| |
OBTAINS A TYPE 1 REPORT OBTAINS A TYPE 2 REPORT
| |
- Understands system design and whether - Understands system design and whether
controls were placed in operation. controls were placed in operation.
- CANNOT reduce assessed control risk - Evaluates tests of controls and results.
below maximum! - May REDUCE assessed control risk
- Must perform full substantive testing below maximum (e.g., to low or moderate).
on the related financial statement accounts. - May REDUCE substantive testing on accounts.
Evaluating the Service Auditor's Report
Before relying on a SOC report, the user auditor must:
- Evaluate the professional competence and independence of the service auditor.
- Inquire whether the scope of the SOC report covers the specific transactions, controls, and control objectives relevant to the user entity's financial statements.
- Verify that the period covered by the SOC 2/Type 2 report aligns with the user entity's fiscal year. If there is a timing gap between the end of the SOC report period and the client's year-end (e.g., SOC report covers 9 months ended September 30, and client year-end is December 31), the user auditor must perform roll-forward procedures (inquire of vendor management, obtain an updated bridge letter affirming no material control changes, or test user entity controls over vendor activities).
Subservice Organizations: Carve-Out vs. Inclusive Methods
Service organizations often outsource sub-functions to other entities (a "subservice organization," such as a SaaS provider hosting its platform on AWS):
- Carve-Out Method: The service organization's description excludes the subservice organization's control objectives and related controls. The SOC report identifies the nature of the outsourced services and details the complementary subservice organization controls (CSOCs) required.
- Inclusive Method: The service organization's description includes the subservice organization's control objectives and controls, and the service auditor's tests encompass both entities.
5. Complementary User Entity Controls (CUECs)
One of the most critical elements of a SOC 1 or SOC 2 report is the specification of Complementary User Entity Controls (CUECs).
+---------------------------------------------------------------------------------------------------------+
| COMPLEMENTARY USER ENTITY CONTROLS (CUECs) INTERACTION |
| |
| SERVICE ORGANIZATION CONTROLS COMPLEMENTARY USER ENTITY CONTROLS (CUECs) |
| (Designed & Executed by Vendor) (Designed & Executed by Client / User Entity) |
| - Batch processing algorithms - User reconciles payroll summary to general ledger |
| - Automated tax calculation engine - User reviews and authorizes employee hourly rates |
| - Data center physical security controls - User manages and terminates user ID access promptly |
| |
| \ / |
| +-------------------------- TOTAL SYSTEM OF -------------------------+ |
| INTERNAL CONTROL |
| | |
| v |
| ACHIEVEMENT OF CONTROL OBJECTIVES & ICFR INTEGRITY |
+---------------------------------------------------------------------------------------------------------+
Why CUECs Are Vital
A service organization's internal controls are rarely self-contained. The service organization's control environment is designed under the explicit operating assumption that user entities will implement specific internal controls on their own end.
- Example: A payroll service organization calculates payroll accurately, but assumes the client reviews the monthly payroll register and approves payroll bank debits. If the client fails to review the register, ghost employees or pay rate tampering will go completely undetected!
- User Auditor Mandate: The user auditor cannot simply accept a clean SOC 1 report and conclude that client internal control is effective. The user auditor must inspect the CUECs listed in Section 3 or 4 of the SOC report and specifically test whether the client user entity has designed and implemented those CUECs effectively.
6. Auditor Reporting Conventions: Prohibitions on Referencing the Service Auditor
On the CPA exam, questions frequently test whether the user auditor should refer to the service auditor in their audit report on the user entity's financial statements.
REFERENCING THE SERVICE AUDITOR
|
+--------------------------------+--------------------------------+
| |
UNMODIFIED AUDIT OPINION MODIFIED AUDIT OPINION
(Clean Opinion Issued) (Qualified or Adverse Opinion)
| |
NEVER REFER TO SERVICE AUDITOR! MAY REFER TO SERVICE AUDITOR ONLY IF:
- Implies divided responsibility. Reference is relevant to understanding
- Misleads users into believing the the reason for the modified opinion
service auditor shares liability. (must state reference does not diminish
user auditor's sole responsibility).
Exam Trap: In an unmodified (clean) audit report, the user auditor must NEVER make reference to the service auditor as a basis for the opinion. Making reference implies a division of responsibility (like sharing responsibility with a component auditor under AU-C 600), which is strictly prohibited for service auditors under AU-C 402. The user auditor maintains sole, undivided responsibility for the audit opinion on the user entity's financial statements.
A CPA is auditing the financial statements of a manufacturing company that outsources its complete human resources and payroll processing to an external service organization. The CPA obtains a SOC 1 Type 1 report issued by the service auditor. Which of the following describes the audit evidence provided by this report?
When reviewing a service auditor's SOC 1 Type 2 report, the user auditor notes a section identifying several 'Complementary User Entity Controls' (CUECs). What is the user auditor's professional obligation regarding these controls?
Under what circumstances is an independent user auditor permitted to refer to the service auditor in an unmodified (clean) audit report on a user entity's financial statements?
Which of the following statements correctly differentiates a SOC 1 report from a SOC 2 report under AICPA attestation standards?