SOC 1 engagements for organizations whose services impact clients' financial reporting controls.
Service pathway
SOC 1 Type 1 and Type 2 examinations for service organizations whose systems or processes affect a customer's financial reporting controls.
We define the service, systems, processes, control objectives, user-entity responsibilities, stakeholders, and intended report use. The evidence plan assigns owners, clarifies dependencies, and sets a realistic period for operating-effectiveness testing.
A report on controls at a service organization that are relevant to a customer's financial statements. Common examples include payroll processors, fund administrators, and payment gateways.
Tie control objectives to financial reporting → document processes and controls → operate access, change-management, transaction-processing, and related controls → gather evidence over the agreed period → prepare the examination package.
Type 1 evaluates control design at a point in time. Type 2 evaluates design plus operating effectiveness over an observation period, typically three to six months. A licensed CPA firm issues the restricted-use report for customers and their auditors.
A practical next step
Share the standard, scope, and outcome you are working toward.
Start a conversationQuestions to resolve
Service organizations whose systems or processes affect a customer's financial statements—such as payroll processors, fund administrators, and payment gateways—are the usual candidates.
Related routes
Start here
Share the standard, regulation, or customer requirement you are working toward. We will map a proportionate next step.