What SOC 1 is
SOC 1 is a report on controls at a service organization that are relevant to its customers' internal control over financial reporting (ICFR). A licensed CPA firm performs the examination under the AICPA attestation standards, in AT-C section 320.
In SOC 1 terms, your customers are user entities. Their financial statement auditors, called user auditors, use your report to rely on your controls when they audit those customers. Requests usually come from customers whose financial transactions pass through your service, such as payroll, payments, loan servicing, fund administration, billing and claims processing.
Key facts
Control objectives
Management defines control objectives tied to financial reporting risk, such as complete and accurate transaction processing or restricted access to financial data. The examination is built around them.
IT general controls
Most SOC 1 reports include objectives for logical access, change management, computer operations and backups that support the financial processing.
Business process controls
Controls over the input, processing, reconciliation and output of transactions you handle for customers.
Complementary user entity controls
Controls your customers must operate for your control objectives to be achieved. The report lists them so user auditors can check them.
Subservice organizations
Vendors such as cloud or data center providers that support your service. The report presents their controls using either the carve-out method or the inclusive method.
Type 1 and Type 2
A Type 1 report covers the system description and control design as of a date. A Type 2 adds operating effectiveness over a period, which user auditors generally need in order to rely on your controls.
How readiness works with us
We identify the services your customers rely on for financial reporting, the processes and systems that deliver them, and the subservice organizations involved. With your team we draft or refine the control objectives and agree whether to start with a Type 1 or a Type 2.
We map each control objective to the control activities that support it, then check design and evidence. We review access, change records, job monitoring, reconciliations and reports. The result is a gap list ranked by audit impact, with an owner for each item.
We help close the gaps. That can include tightening access to financial systems, formalizing change approval, adding job failure alerts, documenting reconciliations or updating policies. Each control ends up with a named owner, a frequency and an evidence source.
Before fieldwork we test a sample of controls the way an auditor would and help fix what fails. During the examination we help answer requests, pull populations and samples, and explain technical controls. Your management signs the assertion, and the CPA firm issues the report.
What you receive
Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.
Gap assessment
- Services, systems and subservice organizations in scope
- Status of each control against its control objective
- Prioritized remediation plan with owners and target dates
Controls and documentation
- Control matrix mapping controls to control objectives
- Controls implemented or improved in your environment
- Policies and procedures updated where gaps exist
Evidence set
- Evidence organized by control objective for the auditor
- Defined populations, evidence sources and frequencies
- Setup in your compliance platform if you use one
Testing and audit support
- Pre-audit control testing results
- Fixes for exceptions found in testing
- Help with auditor requests during fieldwork
Control areas we commonly implement
Access to financial systems
Role-based access, MFA, privileged access limits, joiner, mover and leaver steps, and periodic access reviews. We can deploy identity with Keycloak.
Change management
Approval and testing before production changes, separation of duties and records that tie each deployment to an approved change.
Computer operations
Monitoring of scheduled jobs and interfaces, alerts on failures and records of how each failure was resolved.
Backups and recovery
Backup schedules for financial data, restore tests and a documented recovery plan.
Logging and monitoring
Logs of access and changes to financial systems, with alerts and a record of review. We deploy open-source monitoring such as Wazuh.
Vendor oversight
An inventory of subservice organizations, review of their SOC reports and tracking of the controls they expect you to operate.
SOC 1 and SOC 2 compared
Some service organizations need both reports. When they do, the two can share scoping work, IT general controls and much of the evidence.
| Topic | SOC 1 | SOC 2 |
|---|---|---|
| Subject | Controls relevant to customers' financial reporting | Controls relevant to security, and optionally availability, processing integrity, confidentiality and privacy |
| Criteria | Control objectives defined by management | AICPA Trust Services Criteria |
| Main readers | Customer management and their financial statement auditors | Customer security, risk and procurement teams |
| Attestation standard | AT-C section 320 | AT-C section 205 |
| Report types | Type 1 and Type 2 | Type 1 and Type 2 |
| Common requesters | Customers of payroll, payments, fund administration and billing services | Customers of SaaS, cloud and data processing services |
Who does what
We prepare your environment and evidence for the examination. We scope, assess, help implement controls, test them and support your team during fieldwork. We do not perform the examination or issue the report.
Your independent CPA firm plans and performs the examination, decides its own procedures, tests your controls and issues the SOC 1 report with its opinion.
Your team owns the service and the controls. Management provides the system description and control objectives and signs the assertion. Control owners run their controls during the period. We can help draft the description and objectives for management to review.
Common questions
How long does readiness take?
It depends on your scope and how mature your controls are today. During scoping we give you a plan with dates for each phase. For a Type 2, also plan for the review period, because the auditor needs evidence that controls operated across it.
Do we need SOC 1 or SOC 2?
It depends on why customers are asking. If their financial statement auditors need to rely on your service, SOC 1 fits. If their security teams are evaluating how you protect data, SOC 2 fits. We review the requests you have received during scoping.
Can you work with our compliance platform?
Yes. If you use Vanta, Drata or a similar platform, we work inside it. We map controls, connect integrations and upload evidence. If you do not use one, we organize evidence in a folder structure your auditor can follow.
Do you perform the SOC 1 audit?
No. A licensed CPA firm performs the examination and issues the report. We prepare your team for it and support you while it runs.
Can you help after the report is issued?
Yes, through a retainer. We can help address exceptions noted in the report, keep evidence on schedule for the next period and prepare for the next examination. If customers ask about the time between your report period and their fiscal year end, your management can issue a bridge letter, and we can help gather the supporting information.
What do we need to prepare?
A named owner on your side, descriptions of the services customers rely on, access to the systems that process financial data, and any existing process documentation, reconciliations and policies. An NDA can be in place before we start.
How to prepare
List the services customers rely on for financial reporting and the customer or auditor requests you have received. Note any deadlines tied to customers' fiscal year ends.
Gather what you already have: process descriptions, reconciliations, reports you send to customers, change and access procedures, and a list of vendors that support the service. Gaps are expected. The gap assessment exists to find them.
Choose an internal owner who knows both the operational process and the supporting systems. If you have already selected a CPA firm, share their contact so we can align on control objectives and timing early.

