8.5 Planning a SOC Engagement: Independence, Materiality, Risk Assessment & Representations

Key Takeaways

  • The service auditor must be independent of the service organization in every SOC engagement, and must also be independent of a subservice organization when the inclusive method is used, but not when the subservice organization is carved out.
  • Materiality in a SOC 1 engagement has meaningful quantitative dimensions but must be considered against the needs of a broad range of user entities because the service auditor does not know any single user entity's threshold, while SOC 2 materiality is predominantly qualitative because the subject matter is not quantifiable.
  • Both parties carry a risk assessment obligation: management must identify and analyze the risks threatening achievement of its control objectives or criteria, and the service auditor must assess the risks that the description is not fairly presented, the controls are not suitably designed, and in a Type 2 that they did not operate effectively.
  • Written representations are required in every SOC engagement, must be dated the same date as the service auditor's report and cover the entire period, and management's refusal to provide them is a pervasive scope limitation requiring a disclaimer or withdrawal.
  • A subsequent event occurs after the period end but before the report date and is handled within the engagement, while a subsequently discovered fact becomes known after the report date and requires the auditor to determine whether the report needs revision and whether anyone is still relying on it.
Last updated: September 2026

Planning a SOC Engagement: Independence, Materiality, Risk Assessment & Representations

Quick Answer: Five Area III planning tasks close here. Summarize the independence considerations among service auditor, service organization and subservice organizations. Explain how materiality is determined and used in a SOC engagement. Identify the risk assessment requirements for both the service organization and the service auditor. Recall the requirements for obtaining management's written representations. And recall the impact of subsequently discovered facts. The section also covers the types of subject matter a practitioner may report on using the Trust Services Criteria.


1. Independence Across the Three Parties

Independence in a SOC engagement is not one relationship but several, and the blueprint asks specifically about the relationships among the service auditor, the service organization and any subservice organizations.

Service Auditor and Service Organization

The service auditor must be independent of the service organization in fact and in appearance, under the independence rules of the AICPA Code of Professional Conduct. Independence is a precondition under AT-C 105; without it, no examination report may be issued. The recurring threats:

  • Self-review threat. The firm designed or implemented the controls, wrote the policies, or drafted the system description, and would now be evaluating its own work. This is the most common impairment in practice, because the same firms that advise on SOC readiness are asked to perform the examination.
  • Management participation threat. The firm made management decisions — selected the trust services categories, decided which controls to implement, or operated a control.
  • Self-interest threat. Direct financial interest in the service organization, or a fee arrangement contingent on the outcome of the opinion.
  • Familiarity and undue influence threats. Long tenure without rotation; a former partner in a key management role at the service organization.

Readiness work is permissible; performing management's responsibilities is not. A firm may explain a criterion, identify gaps and describe options. It may not select the controls, write the description that it will later evaluate, or operate a control during the period.

Service Auditor and Subservice Organizations

This is the distinction the blueprint is testing:

MethodIs the subservice organization part of the subject matter?Independence from the subservice organization required?
Carve-outNo — its controls are excluded from the description and from testingNo. The service auditor performs no procedures there and expresses no opinion on it
InclusiveYes — its description and controls are within the scope of the examination, and its management signs an assertion and provides representationsYes. The subservice organization is a responsible party subject to examination, so the service auditor must be independent of it as well

Service Auditor and User Entities

The service auditor is not auditing user entities and is generally not required to be independent of them. But a practical conflict arises when the same firm is both the service organization's service auditor and a user entity's financial statement auditor: in the financial statement audit, the firm would be relying on its own SOC report. That is a self-review threat in the financial statement audit, evaluated under the Code, and it is typically managed by using a SOC report the firm did not produce or by applying safeguards.


2. Materiality in a SOC Engagement

Materiality applies to all three of the service auditor's conclusions — whether the description is fairly presented, whether the controls were suitably designed, and, in a Type 2, whether they operated effectively — and it has both quantitative and qualitative dimensions. Which dimension dominates depends on the engagement.

SOC 1

The subject matter concerns controls relevant to user entities' internal control over financial reporting, so quantitative factors are meaningful: transaction volumes, dollar values processed, the number of user entities affected, and the size of accounts the processing feeds.

The complication is that the service auditor does not know any individual user entity's materiality threshold, and different user entities have wildly different ones. So the service auditor considers the needs of a broad range of user entities and their auditors rather than calibrating to one customer. Qualitative factors — whether a deviation involves fraud, management override, or a control over authorization — still matter regardless of amount.

SOC 2

The subject matter is generally not quantifiable. There is no dollar amount attached to "the entity implements logical access security software." The AICPA publishes dedicated guidance — Materiality considerations for attestation engagements involving aspects of subject matters that cannot be quantitatively measured — and it is an explicit ISC blueprint reference. Consequently materiality in a SOC 2 is predominantly qualitative, assessed by asking:

  • Does the matter affect whether an applicable trust services criterion was achieved?
  • Would it change the decision of a reasonable report user — a user entity evaluating whether to trust this service?
  • Does it relate to a principal service commitment or system requirement the organization publicly made?
  • Does it involve fraud, intentional circumvention, or management override, any of which is material almost irrespective of size?
  • Is it pervasive across criteria, or isolated to one?

How Materiality Is Used

  1. Planning — scoping which system components, locations and criteria receive attention, and setting sample sizes.
  2. Evaluating identified deviations — individually and in the aggregate. Several individually tolerable deviations across provisioning, access review and termination may collectively establish that the access control criterion was not achieved.
  3. Forming the opinion — a material failure that is not pervasive produces a qualified opinion; a material failure that is pervasive produces an adverse opinion.

Exam trap: materiality is not applied control-by-control in isolation. The question is never "was this control material" but "did the deviations, considered together, prevent achievement of the criterion or control objective in all material respects."


3. Risk Assessment: Two Parties, Two Obligations

The blueprint asks for the risk assessment requirements of both the service organization and the service auditor. They are distinct and both are required.

The Service Organization's Risk Assessment

Management must identify the risks that threaten achievement of its control objectives (SOC 1) or the applicable trust services criteria and its service commitments and system requirements (SOC 2), analyze them, and design and implement controls that address them. In a SOC 2 this obligation is explicit in the CC3 series of the Common Criteria, which requires the entity to specify objectives clearly, identify and analyze risks to achieving them, consider the potential for fraud, and identify and assess changes that could significantly affect the system of internal control.

A service organization that produces a control inventory but no documented risk identification has a risk assessment deficiency, however good its controls happen to be — because nothing demonstrates the controls address the risks the entity actually faces.

The Service Auditor's Risk Assessment

The service auditor must obtain an understanding of the service organization's system and its environment sufficient to identify and assess the risks of material misstatement in the subject matter, and then design procedures responsive to those risks. In a SOC engagement, the risks of material misstatement are the risks that:

  • the description is not fairly presented in accordance with the description criteria;
  • the controls were not suitably designed to achieve the control objectives or criteria; and
  • (Type 2) the controls did not operate effectively throughout the period.

The service auditor also considers fraud risk, including the risk of management override, and evaluates the competence and objectivity of any internal audit function whose work it intends to use. Higher assessed risk drives more persuasive procedures — reperformance rather than inquiry — and larger samples.


4. Management's Written Representations

Written representations are required in every SOC engagement; they are audit evidence, and their absence is a scope limitation.

Form and timing. Written, addressed to the service auditor, signed by management with appropriate responsibility and knowledge, dated the same date as the service auditor's report, and covering the entire period addressed by the report — not just the report date.

Content. Management represents, among other matters, that:

  • It reaffirms the assertion presented in the report.
  • It has provided the service auditor with all relevant information and access, and with all relevant records and documentation.
  • It has disclosed all known instances of noncompliance with laws and regulations, uncorrected misstatements in the description, and known deficiencies in control design or operation.
  • It has disclosed all knowledge of actual, suspected or alleged fraud or intentional circumvention involving management, employees with significant control roles, or others where it could materially affect the subject matter.
  • It has disclosed all subsequent events and all identified system incidents relevant to the report.
  • The criteria used are suitable and available to intended users.

Under the inclusive method, written representations are obtained from the subservice organization's management as well, because that organization is also a responsible party.

If management refuses. Refusal to provide required written representations is a pervasive scope limitation. The service auditor must disclaim an opinion or withdraw from the engagement where withdrawal is possible. The auditor cannot simply note the refusal and proceed, and refusal to represent on a specific matter also raises a question about the reliability of management's other representations.


5. Subsequent Events vs. Subsequently Discovered Facts

These two terms are easy to confuse and the blueprint carries a separate task for each.

Subsequent eventsSubsequently discovered facts
When does it occur?The event occurs after the end of the period (or the as-of date) and before the report dateThe fact becomes known to the auditor after the report date
Was it known at the report date?It arises during the auditor's active engagementNo — had it been known, the auditor may have revised the report
Core obligationInquire of management, and evaluate whether disclosure in the description is needed to prevent the report being misleadingDiscuss with management and determine whether the report needs revision

Handling Subsequently Discovered Facts

  1. Discuss the matter with management and, where appropriate, those charged with governance.
  2. Determine whether the report would have been affected had the fact been known at the report date.
  3. Determine whether anyone is currently using, or is likely to use, the report. If the report has already been superseded by a later period's report and no one relies on it, the obligation may end here.
  4. If revision is necessary and users exist, take action to prevent reliance: management should notify report users. If management refuses, the service auditor takes steps to prevent reliance — which may include notifying user entities and regulators directly — and consults legal counsel before doing so.
  5. Document the matter, the evaluation and the actions taken.

Worked distinction. A forensic report issued in January reveals an intruder had access to the database during the previous November and December, and the SOC report date is February 20. Because the report has not yet been dated, this is a subsequent event that provides evidence about a condition existing during the period — the controls did not operate effectively, so the description and likely the opinion must change. If instead the forensic report surfaces in June, three months after the February report was issued, it is a subsequently discovered fact and the auditor works the five steps above.


6. Subject Matters Reported On Using the Trust Services Criteria

The blueprint asks candidates to "recall the types of subject matters a practitioner may be engaged to report on using the Trust Services Criteria." The criteria are not locked to SOC 2. A practitioner may use them to evaluate controls over:

  1. An entity's entire system used to provide a service to user entities — the classic SOC 2 examination, reported in a restricted-use report with a detailed description and test results, or the SOC 3 general-use summary of the same subject matter.
  2. A particular type of information the system produces, uses or protects — for example, controls over a specific data set rather than over the whole platform.
  3. A specific function, segment or subsidiary rather than the whole entity.
  4. An entity's cybersecurity risk management program, where the Trust Services Criteria serve as the control criteria in a SOC for Cybersecurity examination.

And the engagement itself need not be an examination: the Trust Services Criteria may also be used in a review or an agreed-upon procedures engagement over a suitable subject matter. What may not happen is issuing a SOC 1, SOC 2 or SOC 3 report from anything other than an examination — those reports are examination-only.

Test Your Knowledge

A CPA firm is engaged to perform a SOC 2 examination for a software provider that hosts its platform on a public cloud provider. The software provider uses the carve-out method for the cloud provider. One partner of the CPA firm holds shares in the cloud provider. How does this affect the engagement?

A
B
C
D
Test Your Knowledge

A service auditor performing a SOC 2 examination is determining materiality. Which statement best describes how materiality operates in this engagement?

A
B
C
D
Test Your Knowledge

Three months after issuing an unmodified SOC 1 Type 2 report, a service auditor learns that a significant control failure existed throughout the examination period but had been concealed from the audit team. User entities are actively relying on the report. What is the service auditor's obligation?

A
B
C
D