ISc 4

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/31

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:08 PM on 7/20/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

32 Terms

1
New cards

Examples of services provided by a service organization

Payroll processing, claims processing, data hosting, cloud computing, data center operations, transaction processing, investment servicing, and IT outsourcing are common services provided by a service organization.

2
New cards

SOC 1 Engagement

An examination engagement that reports on controls at a service organization that are relevant to user entities' internal control over financial reporting (ICFR).

3
New cards

SOC 2 Engagement

An examination engagement that reports on controls at a service organization relevant to one or more Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

4
New cards

SOC 3 Engagement

An examination engagement covering the same subject matter as a SOC 2 report but intended for general public distribution. It provides a short-form report without detailed descriptions of controls or testing.

5
New cards

Type 1 SOC Report

A report that expresses an opinion on the fairness of management's description of the system and the suitability of the design of controls as of a specified date.

6
New cards

Type 2 SOC Report

A report that expresses an opinion on the fairness of management's description of the system, the suitability of the design of controls, and the operating effectiveness of those controls throughout a specified period.

7
New cards

Five Trust Services Categories

Security, Availability, Processing Integrity, Confidentiality, and Privacy.

8
New cards

Five Components of the COSO Framework

Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.

9
New cards

Subject Matter of a SOC Engagement

The service auditor forms an opinion on management's assertion regarding the fairness of the system description and the design and, when applicable, the operating effectiveness of controls.

10
New cards

Focus of the Service Auditor's Opinion

The opinion addresses whether management's description of the system is fairly presented, whether controls are suitably designed, and for Type 2 engagements, whether controls operated effectively throughout the examination period.

11
New cards

Types of Service Auditor Opinions in a SOC Engagement

Unmodified opinion, Qualified opinion, Adverse opinion, and Disclaimer of opinion.

12
New cards

Four Key Components of a SOC Report

Management's assertion, the independent service auditor's report, management's system description, and the description of tests of controls and results of testing (Type 2 only).

13
New cards

Management's Responsibility in a SOC 1 Engagement

Management is responsible for preparing the system description, identifying the control objectives, designing and implementing controls, and providing a written assertion regarding the fairness of the description and the suitability of the controls.

14
New cards

Management's Responsibility in a SOC 2 Engagement

Management is responsible for preparing the system description, identifying applicable Trust Services Criteria, designing and implementing controls, and providing a written assertion regarding the fairness of the description and the effectiveness of controls, when applicable.

15
New cards

Elements Included in the Independent Service Auditor's SOC 1 Report

Title, addressee, identification of the system and subject matter, management's responsibilities, service auditor's responsibilities, scope of the engagement, inherent limitations of controls, opinion, signature, city and state of the auditor, and report date.

16
New cards

Elements Included in the Independent Service Auditor's SOC 2 Report

Title, addressee, identification of the system and applicable Trust Services Criteria, management's responsibilities, service auditor's responsibilities, scope of the engagement, inherent limitations of controls, opinion, signature, city and state of the auditor, and report date.

17
New cards
Subservice Organization (SOC 1)
A vendor used by a service organization is considered a subservice organization when the services it performs are likely to be relevant to user entities' internal control over financial reporting (ICFR).
18
New cards
Subservice Organization (SOC 2 and SOC 3)
A vendor used by a service organization is considered a subservice organization when the services it performs are likely to be relevant to one or more Trust Services Criteria.
19
New cards
Carve-Out Method
A method of reporting in which the service organization's description excludes the controls at the subservice organization. Management identifies the services provided by the subservice organization, but the service auditor does not express an opinion on the subservice organization's controls.
20
New cards
Inclusive Method
A method of reporting in which the service organization's description includes the services and controls of the subservice organization, and the service auditor's opinion covers both organizations' controls.
21
New cards
Complementary User Entity Controls (CUECs)
Controls that management of the service organization assumes will be implemented by user entities to achieve the stated control objectives or Trust Services Criteria.
22
New cards
Examples of Complementary User Entity Controls (CUECs
Examples include restricting user access, reviewing exception reports, reconciling transactions, approving system changes, maintaining strong passwords, and promptly notifying the service organization of unauthorized activity.
23
New cards
Complementary Subservice Organization Controls (CSOCs) vs. Complementary User Entity Controls (CUECs)
CSOCs are controls expected to be implemented by a subservice organization, while CUECs are controls expected to be implemented by the user entity. Both are necessary for the service organization's controls to achieve the stated objectives or criteria.
24
New cards
Modified Opinion in a SOC Report
If the service auditor issues a qualified or adverse opinion, the report must clearly describe the reasons for the modification and identify the specific subject matter affected.
25
New cards
Acceptance of a SOC Engagement
Before accepting the engagement, the service auditor should determine that management acknowledges and accepts responsibility for the subject matter and that the engagement has a reasonable purpose and suitable criteria.
26
New cards
Management Disclosures in a SOC 1 Engagement
Management must disclose any significant changes to the system during the period, relevant incidents, and any other information necessary for users to understand the system and related controls.
27
New cards
Key Difference in Management Responsibilities (SOC 1 vs. SOC 2)
In a SOC 1 engagement, management identifies control objectives relevant to ICFR. In a SOC 2 engagement, management identifies the applicable Trust Services Criteria and prepares the system description accordingly.
28
New cards
Service Auditor Planning Responsibilities (All SOC Engagements)
The service auditor plans the engagement by obtaining an understanding of the system, assessing risks, determining materiality, identifying controls to be tested, and developing an overall audit strategy.
29
New cards
Additional Planning Responsibilities (SOC 1)
The service auditor considers user entities, complementary user entity controls (CUECs), subservice organizations, control objectives, and whether the carve-out or inclusive method is used.
30
New cards
Additional Planning Responsibilities (SOC 2)
The service auditor considers the applicable Trust Services Criteria, system boundaries, risks affecting those criteria, complementary controls, and the suitability of the criteria used by management.
31
New cards
Misstatement Terminology in SOC Engagements
Misstatements related to the system description are referred to as description misstatements, while deficiencies in controls relate to the design or operating effectiveness of controls.
32
New cards
System (SOC 2 Definition)
A system consists of the infrastructure, software, people, procedures, and data used to provide the services identified in management's system description.