1/31
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Examples of services provided by a service organization
Payroll processing, claims processing, data hosting, cloud computing, data center operations, transaction processing, investment servicing, and IT outsourcing are common services provided by a service organization.
SOC 1 Engagement
An examination engagement that reports on controls at a service organization that are relevant to user entities' internal control over financial reporting (ICFR).
SOC 2 Engagement
An examination engagement that reports on controls at a service organization relevant to one or more Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
SOC 3 Engagement
An examination engagement covering the same subject matter as a SOC 2 report but intended for general public distribution. It provides a short-form report without detailed descriptions of controls or testing.
Type 1 SOC Report
A report that expresses an opinion on the fairness of management's description of the system and the suitability of the design of controls as of a specified date.
Type 2 SOC Report
A report that expresses an opinion on the fairness of management's description of the system, the suitability of the design of controls, and the operating effectiveness of those controls throughout a specified period.
Five Trust Services Categories
Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Five Components of the COSO Framework
Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
Subject Matter of a SOC Engagement
The service auditor forms an opinion on management's assertion regarding the fairness of the system description and the design and, when applicable, the operating effectiveness of controls.
Focus of the Service Auditor's Opinion
The opinion addresses whether management's description of the system is fairly presented, whether controls are suitably designed, and for Type 2 engagements, whether controls operated effectively throughout the examination period.
Types of Service Auditor Opinions in a SOC Engagement
Unmodified opinion, Qualified opinion, Adverse opinion, and Disclaimer of opinion.
Four Key Components of a SOC Report
Management's assertion, the independent service auditor's report, management's system description, and the description of tests of controls and results of testing (Type 2 only).
Management's Responsibility in a SOC 1 Engagement
Management is responsible for preparing the system description, identifying the control objectives, designing and implementing controls, and providing a written assertion regarding the fairness of the description and the suitability of the controls.
Management's Responsibility in a SOC 2 Engagement
Management is responsible for preparing the system description, identifying applicable Trust Services Criteria, designing and implementing controls, and providing a written assertion regarding the fairness of the description and the effectiveness of controls, when applicable.
Elements Included in the Independent Service Auditor's SOC 1 Report
Title, addressee, identification of the system and subject matter, management's responsibilities, service auditor's responsibilities, scope of the engagement, inherent limitations of controls, opinion, signature, city and state of the auditor, and report date.
Elements Included in the Independent Service Auditor's SOC 2 Report
Title, addressee, identification of the system and applicable Trust Services Criteria, management's responsibilities, service auditor's responsibilities, scope of the engagement, inherent limitations of controls, opinion, signature, city and state of the auditor, and report date.