1/43
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Service Organization
Provides the user entity with the benefits of its personnel, expertise, equipment, and technology to operate tasks and functions that the user entity wishes to outsource
Service auditor performs a SOC examination in accordance with attestation standards issued by AICPA
SOC Engagement
Assess the effectiveness of a service organization's controls
Result in the issuance of a SOC report ←- promote reliance by third parties on service organizations
SOC 1 (ICOFR)
An examination to report on a service organization's controls relevant to user entities' internal control over financial reporting
Restricted to management of the service organization, user entities, and the independent auditor of such user entities
Does NOT include potential users
Management Description
Provides sufficient information to allow a user auditor to understand how the service organization's processing affects the user entity's financial statements and to assess the risk of material misstatement of the user entity's financial statements
Management Assertion
Service Auditor’s Report
Test of Controls & Results (Type 2)
Controls that were tested
Items tested represent all, or a selection of, the items in the population.
The nature of the tests performed
Deviations identified…
The number of items tested
The number and nature of deviations
Causative factors (optional)
SOC 2 (Trust Services Criteria)
An examination of a service organization's description of its system, the suitability of the design of controls, and the operating effectiveness of controls relevant to security, availability, processing integrity, confidentiality, and privacy
Intended for use by those who have sufficient knowledge and understanding of the service organization, the services provided, and the system used to provide such services
Management and the service auditor agree on the intended users of the report (specified parties)
Provide assurance to stakeholders about the organization's ability to protect data and ensure reliable system operations
Management Description
Enables users to understand the system and the processing and flow of data throughout and from the system; must be prepared in accordance with specific criteria and describes the procedures and controls in place to manage risk
Management Assertion
Service Auditor’s Report
Test of Controls & Results (Type 2)
Controls that were tested
Items tested represent all, or a selection of, the items in the population.
The nature of the tests performed
Deviations identified…
The number of items tested
The number and nature of deviations
Causative factors (optional)
SOC 3 (Trust Service Criteria for General Use)
Report on whether controls within the system were effective to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria
Intended for general use by those who lack an understanding of the service organization, their services, or their system
Does not include a description of the system, a description of the service auditor's tests of controls, or the results
Issued as a Type 2 report for general users who need assurance about the controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy, but lack the knowledge and understanding
SOC for Cybersecurity Engagement
SOC engagement where the service auditor is engaged to report on the subject matter of the suitability of the controls within an entity's cybersecurity risk management program using the trust services criteria relevant to security, availability, and confidentiality as control criteria
Examine and report on a description of the entity's cybersecurity risk management program and the effectiveness of controls with that program
SOC for Supply Chain Engagement
SOC engagement used to examine and report on an entity's controls over security, availability, processing integrity, confidentiality, or privacy of a system used to produce, manufacture, or distribute products
Type 1
A report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date
Comprised of…
Management's description of the service organization's system
Written assertion by management of the service organization about…
Management's description of the system fairly presents the service organization's system that was designed and implemented
Controls related to the control objectives stated in management's description of the system were suitably designed to achieve those control objectives
Report that expresses an opinion
Type 2
A report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period
Comprised of…
Management's description of the service organization's system
A written assertion by management of the service organization about…
Management's description of the system fairly presents the service organization's system that was designed and implemented
Controls related to the control objectives stated in management's description of the system were suitably designed and operated effectively to achieve control objectives
Report that expresses an opinion and includes a description of the tests of controls and results
Trust Service Criteria
Set forth the outcomes that an entity's controls should meet to achieve the entity's objectives created by the AICPA; enables practitioners to evaluate and report on controls over the security, availability, processing integrity, confidentiality, or privacy of information and systems
“CAPPS”
Confidentiality
Availability
Processing Integrity
Privacy
Security
Subject Matters:
SOC for cybersecurity engagement
SOC 2 engagement
SOC 3 engagement
Consist of:
Common criteria to all 5 TSC
Additional specific criteria for availability, processing integrity, confidentiality, and privacy
Confidentiality
Information designated as confidential is protected to meet the entity's objectives; relates to various types of sensitive information such as trade secrets and intellectual property
Availability
Information and systems being available for operation and use to meet the entity's objectives
Processing Integrity
Ensures system processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives
Security
Ensuring that information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems that could compromise the availability, integrity, confidentiality, and privacy of information or systems and affect the entity's ability to meet its objective
Required to be in SOC 2 Report; primary area of focus for system users because organizations have increased dependence on technology and concerns about
cybersecurity risks and their impact on operational processes
No additional specific criteria
Privacy
Ensures that personal information is collected, used, retained, disclosed, and disposed of to meet the entity's objectives
Relates only to personal information
Trust Services Supplemental Criteria
Trust Service Criteria expand by adding 4 criteria related to control activities deployed by the entity through policies that establish what is expected and procedures that put policies into action (COSO principle 12)
Logical and Physical Access Controls: How an entity restricts, provides, and removes access and prevents unauthorized access
System Operations: How an entity detects and mitigates processing deviations, including logical and physical security deviations
Change Management: How an entity manages changes and prevents unauthorized changes from being made
Risk Mitigation: Relates to how an entity manages risk mitigation activities arising from potential business disruptions and the use of vendors and business partners
A Series
Additional criteria for Availability that addresses entity's ability to ensure all systems are continuously available as needed by maintaining and monitoring processing capacity, identifying and responding to threats, and ensuring a recovery plan is in place and tested
A1.1: Maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to meet entity objectives.
2. A1.2: Ensures systems are available by identifying environmental threats, designing detection measures, implementing protection mechanisms and alerts, responding
to environmental threats, communicating threat events, performing data backup, ensuring there is offsite storage, implementing an alternate infrastructure, and considering data recoverability to meet entity objectives
3. A1.3: The entity tests its recovery plan procedures to ensure system recovery meets entity objectives
PI Series
Additional criteria for Processing Integrity that focuses creating, using, and communicating quality information so that objectives will be met regarding product/service specifications, controls for completeness and accuracy, productivity, and system specifications
PI1.1: Obtains, generates, uses, and communicates relevant, quality information regarding processing objectives to support the use of products and services
2. PI1.2: Implements policies and procedures over system inputs to result in products, services, and reporting that meet entity objectives
3. PI1.3: The entity implements policies and procedures over system processing to result in products, services, and reporting that meet entity objectives.
4. PI1.4: The entity implements policies and procedures to make available or deliver output completely, accurately, and timely that meet entity objectives.
5. PI1.5: The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives
C Series
Additional criteria for Confidentiality that focuses on confidential information is handled appropriately
C1.1: Identifies and maintains confidential information to meet the entity's confidentiality objectives
2. C1.2: Disposes of confidential information to meet the entity's confidentiality objectives
P Series
Additional criteria for Privacy that focuses on privacy-related matters relating to collecting personal data, obtaining consent when collecting and using that data, using data for specific purposes only, managing access to individuals' data responsibly, disclosing policies to third parties and individuals properly, maintaining complete and accurate records, and monitoring and enforcing practices in place
P1.0: Notice and Communication of Objectives Related to Privacy
2. P2.0: Choice and Consent
3. P3.0: Collection
4. P4.0: Use, Retention, and Disposal
5. P5.0: Access
6. P6.0: Disclosure and Notification
7. P7.0: Quality
8. P8.0: Monitoring and Enforcement
Unmodified (Unqualified) Opinion
Service auditor’s opinion…
Management’s description of the system fairly presents the system that was designed and implemented
SOC 1: Management’s description of the system fairly presents service organization’s system that was designed and implemented
SOC 2: Management's description of the service organization's system presents the service organization's system that was designed and implemented in accordance with the description criteria
Controls stated in management's description of the system were suitably designed
SOC 1: Controls related to the control objectives were suitably designed to achieve the control objectives
SOC 2: Controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the trust services criteria
Controls stated in management's description of the system operated effectively
SOC 1: Controls related to the control objectives operated effectively throughout the specified period to achieve the control objectives
SOC 2: The controls operated effectively throughout the specified period to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the trust services criteria
Qualified Opinion
Opinion that states that except for the effects of the matter(s) giving rise to the modification, the description is presented in accordance with the description criteria and the controls were suitably designed and operating effectively
Material, NOT pervasive
Report:
SOC 1 = Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (except for the matter referred to)
SOC 2 = Service Auditor’s Responsibilities: Amend to state service auditor believes evidence obtained is sufficient and appropriate to provide a basis for qualified opinion
Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (except for the effects of matters giving rise to the modification)
Adverse Opinion
Opinion that states that the description misstatements, either individually or in the aggregate, are material and pervasive, or deficiencies in the design or operation of controls are material and pervasive
Report
SOC 1 = Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (because of the matter referred to in the preceding paragraph)
SOC 2 = Service Auditor’s Responsibilities: Amend to state service auditor believes evidence obtained is sufficient and appropriate to provide a basis for adverse opinion
Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (because of the significance of the matter(s) referred to in the preceding paragraph)
Disclaimer of Opinion
Opinion issued when sufficient and appropriate evidence cannot be obtained on which to base the opinion, and the service auditor concludes that the possible effects on the subject matters of undetected misstatements, if any, could be both material and pervasive
In a separate paragraph, add clear description of the matters that give rise to the modification, describing items in question in which the examination did not comply with the attestation standards
States that auditor does not express an opinion
“We were engaged to examine”
Omits:
What the standards require of the practitioner
Practitioner believes the evidence obtained is sufficient and appropriate to provide a reasonable basis for the service auditor's opinion
Describing the nature of an examination engagement
Complementary User Entity Controls (CUECs)
Controls implemented by the user entity of a service organization, which are necessary, in combination with the service organization's controls, to provide reasonable assurance that the service commitments and system requirements/ objectives stated in management’s description are achieved
Scope and opinion section
Must include statement that user entities are responsible for implementing controls
For SOC 1 ←- Relevant CUECs are described in system description and state service organization's controls can only be achieved if CUECs are designed and operating effectively
For SOC 2 ←- Service organization's system descriptions includes relevant CUECs and a statement that user entities are responsible for those controls; also state that engagement does not include evaluation of whether the CUECs were evaluated for design suitability or operating effectiveness
Service Commitments
Declarations made by service organization management to user entities and others about the system used to provide the service in a SOC 2 engagement
System Requirements
Specifications for how a system should function to meet service commitments and other obligations, such as meeting commitments to vendors and business partners in a SOC 2 engagement
Inclusive Method
Method of addressing the services provided by a subservice organization in which the description of the service organization's system includes a description of:
The nature of the services provided
The components of the subservice organization's system used to provide services to the service organization, including the subservice organization's controls that are necessary, in combination with controls at the service organization, to provide reasonable assurance that the control objectives stated in management's description of the service organization's system (SOC 1®) or the service organization's service commitments and system requirements (SOC 2®) were achieved
Most useful when the services provided by the subservice organization are extensive
Service auditor must be independent from service org
Carve-Out Method
Method of addressing the services provided by a subservice organization in which the CSOCs of the subservice organization are excluded from the description of the service organization's system and from the scope of the engagement
Management still identifies:
Nature of services performed
Types of controls expected to be performed at the subservice organization that are necessary, in combination with controls at the service organization, to provide reasonable assurance that the control objectives stated in management's description of the service organization's system (SOC 1®) or the service organization's service commitments and system requirements (SOC 2®) were achieved
Controls at the service organization used to monitor the effectiveness of the subservice organization's controls.
Cannot be used if subservice services and controls have pervasive effect on service organization
Audit Report for SOC Engagement
Title ←- “Independent”
Addressee
Scope ←- Description of subject matter
Service Organization’s Responsibilities
Service Auditor’s Responsibilities
Inherent Limitations
Description of TOCs (Type 2)
Other Matter (Type 1)
Opinion
Restricted Use
Subservice Organization
An entity used by the service organization to provide services to user entities to provide reasonable assurance that the service commitments and system requirements would be achieved
Vendor is considered:
Services are relevant to report users’ understanding of the service organization's system related to the applicable trust services criteria/ ICOFR and if controls at the subservice organization are necessary, in combination with the service organization’s controls, to provide reasonable assurance that the service commitments and system requirements are achieved (CSOCS)
Complementary Subservice Organization Controls (CSOC)
those controls that are necessary, in combination with the service organization controls, to provide reasonable assurance that service commitments and system requirements are achieved. A vendor used by a service organization is considered a subservice organization only if the services provided by the vendor are relevant to the users' understanding of the service organization's system, and the controls are necessary, in combination with the controls of the service organization, to provide reasonable assurance that the service commitments and system requirements are achieved
Scope and opinion section
Materiality
Service auditor must assess during risk assessment and determine the nature, extent, and timing of procedures necessary to obtain sufficient appropriate evidence to support an opinion in the SOC engagement
Vary between SOC 1 and SOC 2, but service auditor is required to reassess materiality if the auditor obtains new information that would have caused the auditor to assess the initial materiality differently
SOC 1 Engagement ←- Consider fair presentation of the information being reported on in management’s description; qualitative factors (significant aspects of the process have been included/ omitted/ distorted
SOC 2 Engagement ←- Based on the likelihood and magnitude of risks threatening achievement of service commitments and system requirements, and whether the controls the service organization has designed, implemented, and operated were effective in mitigating those risks to an acceptable level based on the TSC
Determined by the common information needs of a broad range of report users as a group.
Description Mistatement
A misstatement that describes errors or omissions in the description of the service organization's system.
Deviation (Exception)
A miststameent that results from failure of a control to operate in a specific instance; A deviation could result in a deficiency
Deficnicny in Design
When a control necessary to meet control objectives is missing or improperly designed so that even if it operates as designed, control objectives would not be achieved
Deficinicy in Operating Effectiveness
When a properly designed control fails to operate as designed or when the person performing the control does not possess the competency necessary to perform the control effectively.
System Boundaries
Specific aspects of a service organization's infrastructure, software, people, procedures, and data necessary to provide its services
When systems for multiple services share aspects, infrastructure, software, people, procedures, and data, the systems will overlap, but the boundaries of each system will differ
Financial reporting system is bounded by the components of the system related to financial transaction initiation, authorization, recording, processing, and reporting
System related to processing integrity may extend to other operations such as risk management, internal audit, information technology, or call center processes
In a SOC 2 engagement addressing confidentiality and privacy criteria, the system boundaries cover all the system components as they relate to the life cycle of the confidential and personal information within well-defined processes
System
The infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve one or more of the organization's specific business objectives in accordance with management-specified requirements
Comprised of:
Infrastructure: Individual physical or virtual resources, or a collection of resources, that support a service organization's environment
Software: Applications and programs that support the operations of an IT system
People: Employees, contractors, subcontractors, and managers who govern, manage, operate, secure, and use the system
Data: Type of information used by personnel and systems, information describing that data such as data dictionaries, and information mapping the flow of data and where it is stored
Procedures: Automated or manual business procedures that are related to services and products offered, including the activities that initiate, authorize, perform, deliver, and report on those procedures
Risk Assessment Procedures
As part of the risk assessment, the service auditor obtains an understanding of the service organization's system/ controls
Includes processes and procedures used to:
Prepare the description of the system; control objectives
Identify the controls designed to achieve control objectives;
Assess suitability of the design of the controls;
Assess the operating effectiveness of controls
Risk Assessment Procedures: PERFORM A WALKTHROUGH
Inquiring of service organization management, those charged with governance who have relevant information
Observing operations and inspecting documents, reports, and printed and electronic records of transaction processing
Inspecting a selection of agreements between the service organization and its user entities
Reperforming the application of a control
Reading relevant reports received from regulators, internal auditors, or other specialists