8.3 SOC 1 Engagements & Financial Statement Reporting (AT-C 320)
Key Takeaways
- AT-C 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting) governs SOC 1 examinations, which exist solely to support user entity financial statement audits.
- Under AU-C 402, a service organization's controls are deemed part of a user entity's information system when they impact the initiation, execution, processing, recording, or reporting of transactions reflected in user financial statements.
- A formal SOC 1 report contains four essential core sections: Section I (Independent Service Auditor's Report), Section II (Management's Assertion), Section III (Management's Description of the System), and Section IV (Control Objectives, Controls, Tests of Operating Effectiveness, and Results).
- Control objectives represent the operational and financial targets established by management to mitigate financial reporting risks, whereas control activities are the specific procedural and technical policies implemented to achieve those objectives.
- SOC 1 Type 1 reports evaluate whether controls are suitably designed as of a specified point in time, while SOC 1 Type 2 reports evaluate both design suitability and operating effectiveness throughout a stated period; AICPA standards set no minimum period, though market practice settles on 6 to 12 months, and only a Type 2 lets a user auditor reduce control risk below maximum.
SOC 1 Engagements & Financial Statement Reporting (AT-C 320)
Quick Summary: Governed by AT-C Section 320, a SOC 1 engagement is an attestation examination specifically engineered to evaluate internal controls at a service organization that impact its clients' Internal Control over Financial Reporting (ICFR). Financial statement auditors evaluate SOC 1 reports under AU-C Section 402 when outsourced services affect transaction initiation, execution, processing, or general ledger posting. A standard SOC 1 report adheres to a rigorous four-part anatomical structure—differentiating management's system description from the independent service auditor's opinion and testing results—while distinguishing point-in-time design reviews (Type 1) from period-spanning operating effectiveness evaluations (Type 2).
1. Regulatory Genesis: AT-C 320 and AU-C 402 Integration
To understand the legal and professional purpose of a SOC 1 engagement, CPA candidates must grasp the interplay between two distinct professional standards issued by the AICPA:
- AT-C Section 320 (Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting): Governs the service auditor—the independent CPA firm hired by the service organization to examine and report on its controls.
- AU-C Section 402 (Audit Considerations Relating to an Entity Using a Service Organization): Governs the user auditor—the independent CPA firm auditing a corporate client's historical financial statements when that client outsources significant business processes.
THE AT-C 320 AND AU-C 402 AUDIT INTERACTION
SERVICE ORGANIZATION USER ENTITY
(e.g., Cloud Payroll Bureau) (e.g., Public Retail Corporation)
┌────────────────────────────┐ ┌────────────────────────────┐
│ Hires Service Auditor │ │ Hires User Auditor │
│ under AT-C 320 │ │ under AU-C 200 / AU-C 402 │
└─────────────┬──────────────┘ └─────────────┬──────────────┘
│ │
▼ ▼
┌────────────────────────────┐ Supplies ┌────────────────────────────┐
│ SERVICE AUDITOR (CPA) │ SOC 1 Type 2 │ USER AUDITOR (CPA) │
│ Issues SOC 1 Report ├───────────────────►│ Evaluates SOC 1 to reduce │
│ under SSAE 18 / AT-C 320 │ Report │ Control Risk for Financial │
└────────────────────────────┘ │ Statement Audit Opinion │
└────────────────────────────┘
When is a Service Organization Part of the User Entity's Information System?
Under AU-C 402.03, a service organization's services are considered an integral extension of the user entity's information system relevant to financial reporting if those services affect any of the following five operational touchpoints:
- The classes of transactions in the user entity's operations that are significant to the user entity's financial statements.
- The procedures (within both automated IT systems and manual workflows) by which the user entity's transactions are initiated, authorized, recorded, processed, corrected as necessary, and transferred to the general ledger.
- The related accounting records, supporting documents, and specific accounts in the user entity's financial statements that are used to initiate, record, process, and report transactions.
- How the user entity's information system captures events and conditions (other than transactions) that are significant to the financial statements.
- The financial reporting process used to prepare the user entity's financial statements, including significant accounting estimates and footnote disclosures.
2. Exemplary Service Organizations Requiring SOC 1 Engagements
Auditors must readily identify service providers whose core functions trigger the requirement for a SOC 1 report versus those that merely warrant operational SOC 2 reviews:
| Industry / Service Type | Specific Operational Functions Impacting User ICFR | Primary Financial Statement Balances Impacted |
|---|---|---|
| Third-Party Payroll Processors (e.g., ADP, Paychex, Workday) | Calculates gross-to-net wages, computes statutory tax withholdings, disburses direct deposits, generates payroll tax returns, exports journal vouchers to general ledger. | Payroll Expense, Accrued Payroll Liabilities, Cash & Cash Equivalents, Payroll Tax Withholdings Payable. |
| 401(k) & Benefit Recordkeepers (e.g., Fidelity, Empower, Vanguard) | Processes employee deferrals, executes trade orders in retirement accounts, maintains participant ledger balances, tracks employer matching accruals. | Employee Benefit Plan Liabilities, Compensation Expense, Retained Earnings, Plan Asset Disclosures. |
| Mortgage & Loan Servicing Bureaus (e.g., Black Knight, Cenlar) | Collects principal and interest payments, recalculates amortization schedules, manages escrow tax/insurance reserves, computes delinquency allowances. | Loans Receivable, Interest Income, Allowance for Credit Losses, Escrow Liabilities. |
| Investment Custodians & Asset Managers (e.g., State Street, BNY Mellon) | Executes securities transactions, holds legal title to financial instruments, calculates net asset values (NAV), records corporate actions and dividend receivables. | Marketable Securities, Investment Income, Unrealized/Realized Gains and Losses, Custodial Cash. |
| Medical Claims Clearinghouses & TPAs (e.g., Optum, Change Healthcare) | Adjudicates healthcare claims, computes deductible/co-pay adjustments, processes provider disbursements, maintains claims payment audit logs. | Healthcare Claims Expense, Accounts Payable, Incurred But Not Reported (IBNR) Actuarial Liabilities. |
| Cloud ERP / Core Ledger Hosting (e.g., NetSuite, SAP S/4HANA Cloud) | Hosts the master general ledger, subledgers (AP/AR), and automated revenue recognition engines, enforcing journal entry validation and posting controls. | All Balance Sheet and Income Statement line items; journal entry posting audit trails. |
3. Anatomical Breakdown of the Four Core Sections of a SOC 1 Report
A SOC 1 report is rigidly standardized into four required sections (with an optional fifth section). Each section has a specific author and distinct legal liability:
ANATOMICAL STRUCTURE OF A SOC 1 REPORT
SECTION I: INDEPENDENT SERVICE AUDITOR'S REPORT
• Prepared and signed by the Independent CPA Firm (Service Auditor)
• Contains the formal audit opinion (Unmodified, Qualified, Adverse, or Disclaimer)
• Includes Scope, Responsibilities, Inherent Limitations, and AU-C 905 Restricted-Use paragraph
─────────────────────────────────────────────────────────────────────────────────────────────
SECTION II: MANAGEMENT'S WRITTEN ASSERTION
• Prepared and signed by Service Organization Management
• Formally asserts that the system description is fair, controls are suitably designed, and
(in Type 2) controls operated effectively throughout the defined period
─────────────────────────────────────────────────────────────────────────────────────────────
SECTION III: MANAGEMENT'S DESCRIPTION OF THE SYSTEM
• Detailed operational narrative authored by Service Organization Management
• Details boundaries, infrastructure, software, people, procedures, data flows, CUECs, and CSOCs
─────────────────────────────────────────────────────────────────────────────────────────────
SECTION IV: SERVICE AUDITOR'S TEST PROCEDURES AND RESULTS
• Authored exclusively by the Independent Service Auditor (Included in Type 2 reports)
• Tabular presentation: Control Objective → Control Activity → Test Procedure → Test Result
─────────────────────────────────────────────────────────────────────────────────────────────
[OPTIONAL] SECTION V: OTHER INFORMATION PROVIDED BY MANAGEMENT (UNAUDITED)
• Business continuity plans, disaster recovery test summaries, management responses to deviations
• Explicitly disclaimed and NOT covered by the Service Auditor's opinion
Deep Dive: Core Sections and Their Operational Meaning
Section I: Independent Service Auditor's Report
The service auditor expresses a formal professional opinion addressing whether:
- Management's description of the system in Section III fairly presents the service organization's system that was designed and implemented throughout the specified period (or as of a point in time in Type 1).
- The controls related to the control objectives stated in the description were suitably designed to provide reasonable assurance that the control objectives would be achieved if controls operated effectively.
- (Type 2 Only) The controls tested operated with operating effectiveness throughout the specified period to provide reasonable assurance that the control objectives were achieved.
Section II: Management's Assertion
A signed legal and professional declaration by executive management of the service organization making explicit representations regarding system description fairness, control design suitability, operational effectiveness across the reporting period, and the suitability of criteria utilized.
Section III: Management's Description of the System
Management details the operational boundaries of the service, including hardware architecture, database engines, operating software, personnel hierarchy, transaction workflows, and data validation routines. Crucially, Section III must define:
- Complementary User Entity Controls (CUECs): Internal controls that service organization management assumes will be implemented by customer organizations (e.g., "User entities must review monthly payroll register summaries against authorized HR changes to ensure disbursement accuracy").
- Subservice Organizations: Disclosure of third-party vendors utilized by the service organization (e.g., using AWS for data center hosting) and whether the carve-out method or inclusive method was used.
Section IV: Information Provided by the Service Auditor (Tests and Results)
Presented in Type 2 reports, Section IV contains the granular tabular record of audit testing. For every control activity, the service auditor details the specific audit testing procedures executed—Inquiry, Observation, Inspection of records, and Reperformance—along with the explicit test results. Any control exception (deviation) identified during testing must be explicitly documented, stating the sample size and the number of exceptions found.
[!IMPORTANT] The Section V Trap: Service organizations frequently append a "Section V" containing management's explanations for exceptions noted in Section IV, or forward-looking plans for infrastructure upgrades. Candidates must remember: Section V is completely unaudited. The service auditor issues an explicit disclaimer stating that no audit procedures were applied to Section V and no opinion is expressed on its contents.
4. Control Objectives vs. Control Activities
A central concept under AT-C 320 is the critical distinction between a Control Objective and a Control Activity:
OBJECTIVES VS. ACTIVITIES ARCHITECTURE
CONTROL OBJECTIVE (The Business & Financial Target)
"Controls provide reasonable assurance that logical access to payroll data files
is restricted strictly to authorized payroll operations personnel."
│
┌────────────────────────┴────────────────────────┐
▼ ▼
CONTROL ACTIVITY A CONTROL ACTIVITY B
(Technical IAM Implementation) (Governance / Review Workflow)
"Dual-authorization is enforced via "Department managers perform quarterly
active directory groups; elevated rights user access recertifications, formally
require ticket sign-off by Controller." revoking stale accounts within 24 hours."
Formulating Objectives and Activities
- Control Objectives: Defined by management (with guidance from user entity requirements and financial audit risks). They represent the overarching control goals necessary to ensure accurate transaction processing and financial data integrity. Control objectives are framed around financial assertions: Completeness, Accuracy, Validity, Cutoff, and Authorization.
- Control Activities: The specific procedural, technical, physical, or supervisory mechanisms implemented by the service organization to achieve the stated control objectives. Control activities include password complexity settings, automated database input masks, segregation of duties matrices, batch reconciliation logs, and supervisor sign-offs.
5. Type 1 vs. Type 2 SOC 1 Reports: Complete Comparative Breakdown
The distinction between Type 1 and Type 2 reports represents one of the most frequently tested concepts on the CPA ISC exam:
| Engagement Feature | SOC 1 Type 1 Report | SOC 1 Type 2 Report |
|---|---|---|
| Time Horizon Tested | Point in Time (e.g., as of June 30, 2026) | Period of Time (typically 6 to 12 months, e.g., January 1 to December 31, 2026) |
| Core Audit Opinions Rendered | 1. Description is fairly presented as of the date.<br>2. Controls are suitably designed as of the date. | 1. Description is fairly presented throughout the period.<br>2. Controls are suitably designed throughout the period.<br>3. Controls operated with operating effectiveness throughout the period. |
| Audit Procedures Applied | Limited to Inquiry, Observation, and Inspection (walkthroughs to confirm control design and implementation). | Comprehensive: Inquiry, Observation, Inspection, and Reperformance across statistical samples throughout the period. |
| Testing of Operating Effectiveness? | NO. Zero testing of operational consistency over time. | YES. Controls are sampled and tested across the entire operational period. |
| Section IV (Test Results) Included? | No. Section IV is omitted (or lists only walkthrough procedures). | Yes. Section IV contains full tabular testing procedures, sample sizes, and detailed deviations. |
| User Auditor Reliance Value (AU-C 402 / SOX 404) | Minimal / Baseline Only. Allows the user auditor to gain an understanding of controls, but CANNOT be used to assess control risk below the maximum. | High. Provides sufficient appropriate audit evidence to reduce control risk below the maximum, supporting reduced substantive testing. |
[!CAUTION] The Control Risk Assessment Trap: A user auditor auditing a public company under SOX Section 404 or a non-public entity under AU-C 330 CANNOT rely on a SOC 1 Type 1 report to reduce control risk. A Type 1 report merely proves that a control was placed in operation on a single calendar day; it provides zero evidence that the control functioned reliably across the financial reporting year. Only a Type 2 report provides operating effectiveness evidence capable of supporting control risk reduction.
6. Practical Audit Scenarios & Core Exam Pitfalls
Practical Scenario 1: Evaluating a Section IV Exception
A user auditor examines a SOC 1 Type 2 report for an outsourced medical billing TPA. In Section IV, under Control Objective 3 ("Controls provide reasonable assurance that provider claims are approved in accordance with fee schedules"), the service auditor notes: "Sample size: 45 claims. Result: 2 deviations noted where claim disbursements exceeding $50,000 were processed with single-manager sign-off rather than mandatory dual-sign-off."
- User Auditor Evaluation: The user auditor cannot automatically conclude that internal controls failed pervasively. The user auditor must: (1) inspect the service auditor's opinion to determine if Section I was qualified; (2) evaluate management's explanation and identify compensating controls (e.g., post-payment monthly variance reconciliations); and (3) determine whether the 2 deviations could have caused a material misstatement on the user entity's financial statements, expanding substantive audit procedures over medical claims expense if necessary.
Summary of Common Exam Traps
| Concept | Correct CPA Understanding | Common Exam Distractor / Trap |
|---|---|---|
| Report Authorship | Section I = Service Auditor; Section II & III = Management; Section IV = Service Auditor; Section V = Management (Unaudited). | Believing the service auditor writes the Section III system description. (Management owns and writes Section III). |
| Type 1 Utility | Type 1 evaluates design at a point in time; it cannot support assessing control risk below maximum. | Claiming that a user auditor can reduce substantive testing based on a clean Type 1 report. |
| Scope Boundaries | SOC 1 evaluates controls impacting user ICFR. Operational IT controls (e.g., encryption) are in-scope only if they safeguard financial data integrity. | Assuming SOC 1 reports evaluate whether the service organization's own financial statements are accurate. (SOC 1 evaluates controls impacting user financial statements!). |
| Section V Assurance | Section V is entirely unaudited supplementary information; the service auditor explicitly disclaims an opinion. | Believing that management responses or disaster recovery plans in Section V carry independent auditor assurance. |
In a SOC 1 Type 2 report, which section contains the detailed tabular listing of control activities, the specific audit procedures executed (such as inspection and reperformance), and the resulting deviations identified?
An independent financial statement auditor is auditing a retail client that outsources all payroll processing to a third-party service bureau. The user entity's payroll expense represents 45% of total operating expenses. The service bureau provides a SOC 1 Type 1 report dated December 31. Can the financial statement auditor rely on this report to assess control risk below the maximum for payroll processing?
Which of the following statements correctly distinguishes a control objective from a control activity in a SOC 1 engagement?