Three attestation engagement types
| Type | Assurance | Conclusion wording |
|---|---|---|
| Examination | Reasonable | Opinion — positive assurance |
| Review | Limited | Conclusion — negative assurance |
| Agreed-upon procedures | None | Findings only |
SOC reports at a glance
| Report | Subject | Primary users |
|---|---|---|
| SOC 1 | Controls at a service organization relevant to user entities' internal control over financial reporting (ICFR) | User entities and their auditors |
| SOC 2 | Controls relevant to the Trust Services Criteria: security, availability, processing integrity, confidentiality, privacy | Restricted — management, customers, regulators |
| SOC 3 | Same criteria as SOC 2, summarized | General use — public distribution |
IMPORTANT — Type 1 vs. Type 2: A Type 1 report covers the fairness of the description and the suitability of design of controls at a point in time. A Type 2 report adds operating effectiveness over a period. Only a Type 2 gives the user auditor evidence to rely on the controls for a period.
Security is the only mandatory criterion
In a SOC 2, the security ("common") criteria must always be included; availability, processing integrity, confidentiality, and privacy are included only if relevant to the engagement scope.
Complementary user entity controls
A service organization's description often assumes that user entities implement certain controls of their own (e.g., promptly notifying the service organization of terminated employees). The user auditor must determine whether those complementary controls actually exist at the user entity — otherwise the service organization's controls may not achieve their objectives.
EXAM TIP: The service auditor reports on the service organization. The user auditor audits the user entity and may use a Type 2 SOC 1 report as evidence — and must not reference the service auditor in an unmodified user-entity opinion.