9.2 Type 1 vs. Type 2 Reports & Testing Procedures
Key Takeaways
- A SOC 2 Type 1 report evaluates the fairness of management's description and the suitability of control design as of a specified point in time (a single date), providing zero testing of operating effectiveness.
- A SOC 2 Type 2 report evaluates the fairness of management's description, the suitability of control design, AND the operating effectiveness of controls throughout a specified testing period (typically 6 to 12 months).
- The four primary audit testing procedures—ranked in ascending order of persuasive audit evidence—are Inquiry (weakest), Observation, Inspection of documentation, and Reperformance (strongest).
- User auditors cannot rely on a Type 1 report to assess control risk below the maximum under AU-C 402; only a Type 2 report provides the operating effectiveness evidence necessary to reduce substantive financial statement testing.
- When control deviations are identified, service auditors evaluate whether they represent isolated clerical glitches or systemic control breakdowns, reporting all deviations in Section IV regardless of the final opinion issued.
Type 1 vs. Type 2 Reports & Testing Procedures
Quick Summary: In a SOC 2 examination, the service auditor issues an attestation opinion under AT-C section 205. The engagement can be conducted as either a Type 1 or a Type 2 examination. A Type 1 report assesses whether management's description of its system is fairly presented and whether the controls are suitably designed to achieve the specified Trust Services Criteria as of a specific point in time (a single calendar date). In contrast, a Type 2 report assesses description fairness, design suitability, AND operating effectiveness of controls throughout a specified period (typically 6 to 12 months). Service auditors utilize four primary testing procedures: Inquiry, Observation, Inspection, and Reperformance.
1. Architectural Distinction: Type 1 vs. Type 2 Reports
The distinction between Type 1 and Type 2 reports is one of the most frequently tested concepts on the CPA ISC exam. The report type determines the scope of the auditor's testing, the time horizon of the engagement, and the degree to which user entities and their financial statement auditors can rely on the report.
The Core Structural Dimensions
Every SOC examination addresses three fundamental questions regarding internal controls:
- Fairness of Presentation: Is management's description of the system in Section III presented fairly in accordance with the AICPA Description Criteria (DC section 200)?
- Suitability of Design: Are the controls described suitably designed such that, if operating as intended, they would provide reasonable assurance that the applicable Trust Services Criteria are achieved?
- Operating Effectiveness: Did the controls operate effectively throughout the specified testing period to achieve the criteria?
| Evaluation Element | SOC 2 Type 1 Report | SOC 2 Type 2 Report |
|---|---|---|
| Time Horizon | As of a specified point in time (e.g., "as of December 31, 2025") | Throughout a specified period of time (e.g., "January 1, 2025 to December 31, 2025") |
| Fairness of Description | Yes — Tested as of the specified date | Yes — Tested throughout the specified period |
| Suitability of Design | Yes — Evaluated as of the specified date | Yes — Evaluated throughout the specified period |
| Operating Effectiveness | NO — Operating effectiveness is explicitly not tested | YES — Extensively tested across the entire sample period |
| Typical Period | N/A (single snapshot date) | Commonly 6 to 12 months. AICPA standards prescribe no minimum; the period must simply be long enough to give the auditor sufficient appropriate evidence and long enough to be useful to report users. |
| Section IV Content | Lists controls and auditor's design assessment; no testing results | Detailed matrix: lists controls, auditor's tests of operating effectiveness, and results/deviations |
| User Auditor Reliance | Cannot be used to assess control risk below maximum under AU-C 402 | Can be used to reduce substantive testing if period aligns with audit period |
| Typical Use Case | Newly founded SaaS startups; newly launched platforms; baseline readiness | Mature service organizations; enterprise B2B vendors; annual recurring compliance |
[!IMPORTANT] The User Auditor Reliance Rule (AU-C 402): Under AU-C section 402 (Audit Considerations Relating to an Entity Using a Service Organization), a financial statement user auditor who wants to assess control risk below maximum for an outsourced business process cannot rely on a Type 1 report. Because a Type 1 report provides no evidence that controls operated effectively over time, the user auditor must either obtain a Type 2 report or perform direct tests of controls at the service organization.
2. The Four Audit Testing Procedures
When testing controls in a SOC 2 examination—specifically when evaluating the operating effectiveness of controls in a Type 2 report—the service auditor executes four standardized audit testing procedures. In accordance with professional attestation standards, these procedures provide varying levels of persuasive audit evidence:
1. Inquiry (Weakest)
- Mechanics: Interviewing management, system administrators, security engineers, and operational staff regarding their understanding and execution of control procedures (e.g., asking how emergency firewall changes are authorized).
- Audit Value & Limitation: Inquiry is an indispensable starting point for understanding control workflows, but inquiry alone is never sufficient to support a conclusion regarding the operating effectiveness of any control. Inquiry must always be paired with corroborating physical or documentary evidence.
2. Observation
- Mechanics: Directly watching personnel perform a control activity or witnessing an automated physical mechanism in operation (e.g., observing an employee badge into a corporate server room, or watching a physical security guard log visitor entry).
- Audit Value & Limitation: Provides strong proof that the control was operating at the precise moment the auditor observed it. However, observation is subject to the Hawthorne effect (individuals alter their behavior when they know they are being watched) and provides no evidence that the control operated effectively when the auditor was absent.
3. Inspection of Documentation
- Mechanics: Examining documentary evidence, system-generated audit trails, configuration settings, approval records, access logs, and tickets (e.g., inspecting Jira change tickets to verify manager sign-off, or reviewing system configuration dumps to confirm that password complexity rules are enabled).
- Audit Value: Provides highly reliable, objective historical evidence that controls operated consistently across the entire testing period. Inspection is the workhorse procedure for SOC 2 Type 2 testing.
4. Reperformance (Strongest)
- Mechanics: The auditor independently executes the control procedure that was originally performed by the service organization to verify whether the outcome matches the entity's results (e.g., recalculating a complex billing batch run, or independently executing a script comparing active Active Directory accounts against the HR employee termination roster).
- Audit Value: Provides the highest level of audit assurance because the auditor directly verifies the mechanical accuracy and operational effectiveness of the control without relying on management's representations.
3. Audit Sampling Methodologies for Operating Effectiveness
To evaluate operating effectiveness over a 6- or 12-month testing period, service auditors cannot test every transaction; they utilize audit sampling. In accordance with the AICPA Audit Guide Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, sample sizes are determined based on control frequency, control complexity, and the risk of control failure.
AICPA Sampling Guidelines by Control Frequency
| Control Operating Frequency | Population Size (Annual) | Recommended Minimum Sample Size | Example Control Activity |
|---|---|---|---|
| Annually | 1 instance | 1 instance (100% of population) | Annual disaster recovery simulation test; annual enterprise risk assessment |
| Quarterly | 4 instances | 2 to 4 instances | Quarterly privileged user access recertification; quarterly board review |
| Monthly | 12 instances | 2 to 6 instances | Monthly backup restoration test; monthly financial system reconciliation |
| Weekly | 52 instances | 5 to 15 instances | Weekly vulnerability scans; weekly change advisory board (CAB) meetings |
| Daily | 250 to 365 instances | 25 to 40 instances | Daily backup log reviews; daily firewall anomaly log monitoring |
| Continuous / Automated | Thousands / Ongoing | 1 to 2 instances (if ITGCs pass) | Automated password hashing; automated multi-factor authentication prompt |
[!TIP] The Automated Control Benchmarking Rule: For purely automated application controls (e.g., an automated system rule that prohibits a user from checking out code without automated unit tests passing), the auditor does not need to sample 40 transactions. Under the benchmarking strategy, if the auditor proves that the automated control is functioning correctly on one transaction and proves that Change Management ITGCs (CC8.1) operated effectively throughout the period (guaranteeing the underlying code was never modified without authorization), the auditor can conclude that the automated control operated effectively throughout the entire period.
Information Produced by the Entity (IPE / IUC)
Before selecting a sample, the auditor must test the completeness and accuracy of the population report generated by the system (termed Information Produced by the Entity [IPE] or Information Used by the Auditor [IUC]). For example, if testing employee terminations, the auditor cannot simply accept an Excel spreadsheet from HR; the auditor must independently query the underlying database or inspect report query parameters to confirm no terminated employees were omitted from the population.
4. Evaluating Control Deviations: Isolated Glitch vs. Systemic Breakdown
When testing a sample of items (e.g., 40 daily change tickets), the auditor may identify an instance where the control did not operate as documented—termed a deviation or control exception (e.g., one change was promoted to production without a documented peer review approval).
The Evaluation Framework
When a deviation is identified, the auditor must not automatically issue a qualified opinion; the auditor must perform a rigorous qualitative and quantitative evaluation:
- Determine the Root Cause: Was the deviation an isolated clerical oversight (e.g., a manager approved the change via Slack message but forgot to click the "Approve" button in Jira), or does it represent a deliberate circumvention or management override of internal control?
- Evaluate the Extent and Frequency: Did 1 out of 40 samples fail (a 2.5% error rate), or did 12 out of 40 fail (a 30% error rate indicating systemic non-compliance)?
- Assess Compensating Controls: Are there secondary, redundant controls that mitigated the risk? For example, if a pre-approval ticket was missing, did an automated continuous integrity monitoring tool detect the change and alert security, or did the quarterly access review detect the unauthorized code?
- Evaluate Impact on the Criteria: Did the deviation prevent the service organization from achieving the applicable Trust Services Criterion? If criterion CC8.1 requires authorized changes, and an unauthorized change introduced an undetected security vulnerability, the criterion was not achieved.
Mandatory Reporting in Section IV
Under AICPA attestation standards, all identified deviations must be reported in Section IV of the Type 2 report, regardless of whether the auditor considers them immaterial or issues an unmodified clean opinion. The report must list:
- The control tested
- The audit procedure applied
- The sample size
- The exact number and nature of deviations identified
- Management's response explaining the root cause and remediation (optional for management, but standard practice)
5. Audit Opinions and Reporting Mechanics
The culmination of the SOC 2 examination is the Independent Service Auditor's Report located in Section I. The auditor expresses an opinion on whether management's description is fairly presented, whether controls were suitably designed, and (for Type 2) whether controls operated effectively.
+----------------------------------------------------------------------------------------------------+
| SERVICE AUDITOR OPINION SPECTRUM |
+---------------------+------------------------------------------------------------------------------+
| Opinion Type | Criteria & Operating Effectiveness Status |
+---------------------+------------------------------------------------------------------------------+
| Unmodified (Clean) | Controls suitably designed & operated effectively to achieve criteria. |
| Qualified | Material deficiency or scope limitation affecting specific criteria; |
| ("Except for") | NOT pervasive across the entire system of internal control. |
| Adverse | Material and pervasive failure; system description false or controls fail |
| | systematically across multiple criteria. |
| Disclaimer | Auditor unable to obtain sufficient appropriate evidence due to pervasive |
| | scope limitation (e.g., missing logs, management non-cooperation). |
+---------------------+------------------------------------------------------------------------------+
The Four Opinion Types
- Unmodified Opinion ("Clean"): The auditor concludes that, in all material respects, management's description is fairly presented, controls were suitably designed, and controls operated effectively throughout the period to achieve the applicable Trust Services Criteria.
- Qualified Opinion ("Except for"): Issued when the auditor identifies a material control deficiency or a scope limitation that affects specific criteria, but the impact is not pervasive to the overall system. The opinion includes an explanatory Basis for Qualified Opinion paragraph and states: "In our opinion, except for the matter described in the Basis for Qualified Opinion paragraph, the description is fairly presented... and controls operated effectively in all material respects..."
- Adverse Opinion: Issued when management's description is materially misleading, or when controls were not suitably designed or operating effectively such that the service organization failed to achieve the Trust Services Criteria on a pervasive basis.
- Disclaimer of Opinion: Issued when a severe, pervasive scope limitation prevents the auditor from obtaining sufficient appropriate audit evidence to form an opinion (e.g., if catastrophic system failures destroyed all audit logs for six months, or if management refuses to provide written management representations).
A financial statement auditor is planning the annual audit of an enterprise client that outsources its core payroll processing to a third-party service bureau. To assess control risk below the maximum for the payroll processing cycle, the auditor requests a SOC report from the service bureau. The service bureau provides a SOC 2 Type 1 report dated as of the client's fiscal year-end date. How should the user auditor evaluate this report?
An independent service auditor is testing the operating effectiveness of an automated access revocation control for a SOC 2 Type 2 report. Which audit testing procedure provides the highest level of persuasive audit evidence when verifying that terminated employee accounts were successfully disabled in the production environment?
During a SOC 2 Type 2 examination, the service auditor discovers that the service organization failed to perform formal change authorization and testing for all 18 emergency hotfixes deployed to production during the 12-month period, resulting in a failure to achieve Common Criterion CC8.1. However, all other Common Criteria (CC1–CC7 and CC9) operated effectively without material exception. What form of audit opinion should the service auditor issue?