M1 & M2 S4 ISC CPA

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/43

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:14 AM on 9/15/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

44 Terms

1
New cards

Service Organization

Provides the user entity with the benefits of its personnel, expertise, equipment, and technology to operate tasks and functions that the user entity wishes to outsource

  • Service auditor performs a SOC examination in accordance with attestation standards issued by AICPA


2
New cards

SOC Engagement

Assess the effectiveness of a service organization's controls

  • Result in the issuance of a SOC report ←- promote reliance by third parties on service organizations


3
New cards

SOC 1 (ICOFR)

An examination to report on a service organization's controls relevant to user entities' internal control over financial reporting

  • Restricted to management of the service organization, user entities, and the independent auditor of such user entities

  • Does NOT include potential users


  1. Management Description

    • Provides sufficient information to allow a user auditor to understand how the service organization's processing affects the user entity's financial statements and to assess the risk of material misstatement of the user entity's financial statements

  2. Management Assertion

  3. Service Auditor’s Report

  4. Test of Controls & Results (Type 2)

    1. Controls that were tested

    2. Items tested represent all, or a selection of, the items in the population.

    3. The nature of the tests performed

    4. Deviations identified…

      1. The number of items tested

      2. The number and nature of deviations

      3. Causative factors (optional)


4
New cards

SOC 2 (Trust Services Criteria)

An examination of a service organization's description of its system, the suitability of the design of controls, and the operating effectiveness of controls relevant to security, availability, processing integrity, confidentiality, and privacy

  • Intended for use by those who have sufficient knowledge and understanding of the service organization, the services provided, and the system used to provide such services

  • Management and the service auditor agree on the intended users of the report (specified parties)

  • Provide assurance to stakeholders about the organization's ability to protect data and ensure reliable system operations


  1. Management Description

    • Enables users to understand the system and the processing and flow of data throughout and from the system; must be prepared in accordance with specific criteria and describes the procedures and controls in place to manage risk

  2. Management Assertion

  3. Service Auditor’s Report

  4. Test of Controls & Results (Type 2)

    1. Controls that were tested

    2. Items tested represent all, or a selection of, the items in the population.

    3. The nature of the tests performed

    4. Deviations identified…

      1. The number of items tested

      2. The number and nature of deviations

      3. Causative factors (optional)


5
New cards

SOC 3 (Trust Service Criteria for General Use)

Report on whether controls within the system were effective to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the applicable trust services criteria

  • Intended for general use by those who lack an understanding of the service organization, their services, or their system

  • Does not include a description of the system, a description of the service auditor's tests of controls, or the results

  • Issued as a Type 2 report for general users who need assurance about the controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy, but lack the knowledge and understanding


6
New cards

SOC for Cybersecurity Engagement

SOC engagement where the service auditor is engaged to report on the subject matter of the suitability of the controls within an entity's cybersecurity risk management program using the trust services criteria relevant to security, availability, and confidentiality as control criteria

  • Examine and report on a description of the entity's cybersecurity risk management program and the effectiveness of controls with that program


7
New cards

SOC for Supply Chain Engagement

SOC engagement used to examine and report on an entity's controls over security, availability, processing integrity, confidentiality, or privacy of a system used to produce, manufacture, or distribute products

8
New cards

Type 1

A report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design of the controls to achieve the related control objectives included in the description as of a specified date

  • Comprised of…

    1. Management's description of the service organization's system

      • Written assertion by management of the service organization about…

        • Management's description of the system fairly presents the service organization's system that was designed and implemented

        • Controls related to the control objectives stated in management's description of the system were suitably designed to achieve those control objectives

  1. Report that expresses an opinion


9
New cards

Type 2

A report on the fairness of the presentation of management's description of the service organization's system and the suitability of the design and operating effectiveness of the controls to achieve the related control objectives included in the description throughout a specified period

  • Comprised of…

    1. Management's description of the service organization's system

      • A written assertion by management of the service organization about…

        • Management's description of the system fairly presents the service organization's system that was designed and implemented

        • Controls related to the control objectives stated in management's description of the system were suitably designed and operated effectively to achieve control objectives

  1. Report that expresses an opinion and includes a description of the tests of controls and results


10
New cards

Trust Service Criteria

Set forth the outcomes that an entity's controls should meet to achieve the entity's objectives created by the AICPA; enables practitioners to evaluate and report on controls over the security, availability, processing integrity, confidentiality, or privacy of information and systems

  • CAPPS

  1. Confidentiality

  2. Availability

  3. Processing Integrity

  4. Privacy

  5. Security


Subject Matters:

  1. SOC for cybersecurity engagement

  2. SOC 2 engagement

  3. SOC 3 engagement


Consist of:

  1. Common criteria to all 5 TSC

  2. Additional specific criteria for availability, processing integrity, confidentiality, and privacy


11
New cards

Confidentiality

Information designated as confidential is protected to meet the entity's objectives; relates to various types of sensitive information such as trade secrets and intellectual property

12
New cards

Availability

Information and systems being available for operation and use to meet the entity's objectives

13
New cards

Processing Integrity

Ensures system processing is complete, valid, accurate, timely, and authorized to meet the entity's objectives

14
New cards

Security

Ensuring that information and systems are protected against unauthorized access, unauthorized disclosure of information, and damage to systems that could compromise the availability, integrity, confidentiality, and privacy of information or systems and affect the entity's ability to meet its objective

  • Required to be in SOC 2 Report; primary area of focus for system users because organizations have increased dependence on technology and concerns about

cybersecurity risks and their impact on operational processes

  • No additional specific criteria


15
New cards

Privacy

Ensures that personal information is collected, used, retained, disclosed, and disposed of to meet the entity's objectives

  • Relates only to personal information


16
New cards

Trust Services Supplemental Criteria

Trust Service Criteria expand by adding 4 criteria related to control activities deployed by the entity through policies that establish what is expected and procedures that put policies into action (COSO principle 12)

  1. Logical and Physical Access Controls: How an entity restricts, provides, and removes access and prevents unauthorized access

  2. System Operations: How an entity detects and mitigates processing deviations, including logical and physical security deviations

  3. Change Management: How an entity manages changes and prevents unauthorized changes from being made

  4. Risk Mitigation: Relates to how an entity manages risk mitigation activities arising from potential business disruptions and the use of vendors and business partners


17
New cards

A Series

Additional criteria for Availability that addresses entity's ability to ensure all systems are continuously available as needed by maintaining and monitoring processing capacity, identifying and responding to threats, and ensuring a recovery plan is in place and tested

  1. A1.1: Maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and to enable the implementation of additional capacity to meet entity objectives.

2. A1.2: Ensures systems are available by identifying environmental threats, designing detection measures, implementing protection mechanisms and alerts, responding

to environmental threats, communicating threat events, performing data backup, ensuring there is offsite storage, implementing an alternate infrastructure, and considering data recoverability to meet entity objectives

3. A1.3: The entity tests its recovery plan procedures to ensure system recovery meets entity objectives

18
New cards

PI Series

Additional criteria for Processing Integrity that focuses creating, using, and communicating quality information so that objectives will be met regarding product/service specifications, controls for completeness and accuracy, productivity, and system specifications

  1. PI1.1: Obtains, generates, uses, and communicates relevant, quality information regarding processing objectives to support the use of products and services

2. PI1.2: Implements policies and procedures over system inputs to result in products, services, and reporting that meet entity objectives

3. PI1.3: The entity implements policies and procedures over system processing to result in products, services, and reporting that meet entity objectives.

4. PI1.4: The entity implements policies and procedures to make available or deliver output completely, accurately, and timely that meet entity objectives.

5. PI1.5: The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives

19
New cards

C Series

Additional criteria for Confidentiality that focuses on confidential information is handled appropriately

  1. C1.1: Identifies and maintains confidential information to meet the entity's confidentiality objectives

2. C1.2: Disposes of confidential information to meet the entity's confidentiality objectives

20
New cards

P Series

Additional criteria for Privacy that focuses on privacy-related matters relating to collecting personal data, obtaining consent when collecting and using that data, using data for specific purposes only, managing access to individuals' data responsibly, disclosing policies to third parties and individuals properly, maintaining complete and accurate records, and monitoring and enforcing practices in place

  1. P1.0: Notice and Communication of Objectives Related to Privacy

2. P2.0: Choice and Consent

3. P3.0: Collection

4. P4.0: Use, Retention, and Disposal

5. P5.0: Access

6. P6.0: Disclosure and Notification

7. P7.0: Quality

8. P8.0: Monitoring and Enforcement


21
New cards

Unmodified (Unqualified) Opinion

Service auditor’s opinion…

  1. Management’s description of the system fairly presents the system that was designed and implemented

    • SOC 1: Management’s description of the system fairly presents service organization’s system that was designed and implemented

    • SOC 2: Management's description of the service organization's system presents the service organization's system that was designed and implemented in accordance with the description criteria

  2. Controls stated in management's description of the system were suitably designed

    • SOC 1: Controls related to the control objectives were suitably designed to achieve the control objectives

    • SOC 2: Controls were suitably designed to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the trust services criteria

  3. Controls stated in management's description of the system operated effectively

    • SOC 1: Controls related to the control objectives operated effectively throughout the specified period to achieve the control objectives

    • SOC 2: The controls operated effectively throughout the specified period to provide reasonable assurance that the service organization's service commitments and system requirements were achieved based on the trust services criteria


22
New cards

Qualified Opinion

Opinion that states that except for the effects of the matter(s) giving rise to the modification, the description is presented in accordance with the description criteria and the controls were suitably designed and operating effectively

  • Material, NOT pervasive

  • Report:

    • SOC 1 = Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (except for the matter referred to)

    • SOC 2 = Service Auditor’s Responsibilities: Amend to state service auditor believes evidence obtained is sufficient and appropriate to provide a basis for qualified opinion

      • Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (except for the effects of matters giving rise to the modification)


23
New cards

Adverse Opinion

Opinion that states that the description misstatements, either individually or in the aggregate, are material and pervasive, or deficiencies in the design or operation of controls are material and pervasive

  • Report

    1. SOC 1 = Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (because of the matter referred to in the preceding paragraph)

    2. SOC 2 = Service Auditor’s Responsibilities: Amend to state service auditor believes evidence obtained is sufficient and appropriate to provide a basis for adverse opinion

      • Opinion: Add separate paragraph, before the opinion paragraph describing the matters that gave rise to the modification (because of the significance of the matter(s) referred to in the preceding paragraph)


24
New cards

Disclaimer of Opinion

Opinion issued when sufficient and appropriate evidence cannot be obtained on which to base the opinion, and the service auditor concludes that the possible effects on the subject matters of undetected misstatements, if any, could be both material and pervasive

  • In a separate paragraph, add clear description of the matters that give rise to the modification, describing items in question in which the examination did not comply with the attestation standards

  • States that auditor does not express an opinion

  • “We were engaged to examine”



Omits:

  1. What the standards require of the practitioner

  2. Practitioner believes the evidence obtained is sufficient and appropriate to provide a reasonable basis for the service auditor's opinion

  3. Describing the nature of an examination engagement


25
New cards

Complementary User Entity Controls (CUECs)

Controls implemented by the user entity of a service organization, which are necessary, in combination with the service organization's controls, to provide reasonable assurance that the service commitments and system requirements/ objectives stated in management’s description are achieved

  • Scope and opinion section

  • Must include statement that user entities are responsible for implementing controls

For SOC 1 ←- Relevant CUECs are described in system description and state service organization's controls can only be achieved if CUECs are designed and operating effectively

For SOC 2 ←- Service organization's system descriptions includes relevant CUECs and a statement that user entities are responsible for those controls; also state that engagement does not include evaluation of whether the CUECs were evaluated for design suitability or operating effectiveness


26
New cards

Service Commitments

Declarations made by service organization management to user entities and others about the system used to provide the service in a SOC 2 engagement

27
New cards

System Requirements

Specifications for how a system should function to meet service commitments and other obligations, such as meeting commitments to vendors and business partners in a SOC 2 engagement


28
New cards

Inclusive Method

Method of addressing the services provided by a subservice organization in which the description of the service organization's system includes a description of:

  1. The nature of the services provided

  2. The components of the subservice organization's system used to provide services to the service organization, including the subservice organization's controls that are necessary, in combination with controls at the service organization, to provide reasonable assurance that the control objectives stated in management's description of the service organization's system (SOC 1®) or the service organization's service commitments and system requirements (SOC 2®) were achieved

    • Most useful when the services provided by the subservice organization are extensive

    • Service auditor must be independent from service org


29
New cards

Carve-Out Method

Method of addressing the services provided by a subservice organization in which the CSOCs of the subservice organization are excluded from the description of the service organization's system and from the scope of the engagement

  • Management still identifies:

    1. Nature of services performed

    2. Types of controls expected to be performed at the subservice organization that are necessary, in combination with controls at the service organization, to provide reasonable assurance that the control objectives stated in management's description of the service organization's system (SOC 1®) or the service organization's service commitments and system requirements (SOC 2®) were achieved

    3. Controls at the service organization used to monitor the effectiveness of the subservice organization's controls.

  • Cannot be used if subservice services and controls have pervasive effect on service organization


30
New cards

Audit Report for SOC Engagement

  1. Title ←- “Independent”

  2. Addressee

  3. Scope ←- Description of subject matter

  4. Service Organization’s Responsibilities

  5. Service Auditor’s Responsibilities

  6. Inherent Limitations

  7. Description of TOCs (Type 2)

  8. Other Matter (Type 1)

  9. Opinion

  10. Restricted Use


31
New cards

Subservice Organization

An entity used by the service organization to provide services to user entities to provide reasonable assurance that the service commitments and system requirements would be achieved

  • Vendor is considered:

    • Services are relevant to report users’ understanding of the service organization's system related to the applicable trust services criteria/ ICOFR and if controls at the subservice organization are necessary, in combination with the service organization’s controls, to provide reasonable assurance that the service commitments and system requirements are achieved (CSOCS)


32
New cards

Complementary Subservice Organization Controls (CSOC)

those controls that are necessary, in combination with the service organization controls, to provide reasonable assurance that service commitments and system requirements are achieved. A vendor used by a service organization is considered a subservice organization only if the services provided by the vendor are relevant to the users' understanding of the service organization's system, and the controls are necessary, in combination with the controls of the service organization, to provide reasonable assurance that the service commitments and system requirements are achieved

  • Scope and opinion section


33
New cards

Materiality

Service auditor must assess during risk assessment and determine the nature, extent, and timing of procedures necessary to obtain sufficient appropriate evidence to support an opinion in the SOC engagement

  • Vary between SOC 1 and SOC 2, but service auditor is required to reassess materiality if the auditor obtains new information that would have caused the auditor to assess the initial materiality differently


SOC 1 Engagement ←- Consider fair presentation of the information being reported on in management’s description; qualitative factors (significant aspects of the process have been included/ omitted/ distorted

SOC 2 Engagement ←- Based on the likelihood and magnitude of risks threatening achievement of service commitments and system requirements, and whether the controls the service organization has designed, implemented, and operated were effective in mitigating those risks to an acceptable level based on the TSC

  • Determined by the common information needs of a broad range of report users as a group.


34
New cards

Description Mistatement

A misstatement that describes errors or omissions in the description of the service organization's system.

35
New cards

Deviation (Exception)

A miststameent that results from failure of a control to operate in a specific instance; A deviation could result in a deficiency

36
New cards

Deficnicny in Design

When a control necessary to meet control objectives is missing or improperly designed so that even if it operates as designed, control objectives would not be achieved

37
New cards

Deficinicy in Operating Effectiveness

When a properly designed control fails to operate as designed or when the person performing the control does not possess the competency necessary to perform the control effectively.

38
New cards

System Boundaries

Specific aspects of a service organization's infrastructure, software, people, procedures, and data necessary to provide its services

  • When systems for multiple services share aspects, infrastructure, software, people, procedures, and data, the systems will overlap, but the boundaries of each system will differ

    • Financial reporting system is bounded by the components of the system related to financial transaction initiation, authorization, recording, processing, and reporting

    • System related to processing integrity may extend to other operations such as risk management, internal audit, information technology, or call center processes

    • In a SOC 2 engagement addressing confidentiality and privacy criteria, the system boundaries cover all the system components as they relate to the life cycle of the confidential and personal information within well-defined processes


39
New cards

System

The infrastructure, software, procedures, and data that are designed, implemented, and operated by people to achieve one or more of the organization's specific business objectives in accordance with management-specified requirements

  • Comprised of:

    • Infrastructure: Individual physical or virtual resources, or a collection of resources, that support a service organization's environment

    • Software: Applications and programs that support the operations of an IT system

    • People: Employees, contractors, subcontractors, and managers who govern, manage, operate, secure, and use the system

    • Data: Type of information used by personnel and systems, information describing that data such as data dictionaries, and information mapping the flow of data and where it is stored

    • Procedures: Automated or manual business procedures that are related to services and products offered, including the activities that initiate, authorize, perform, deliver, and report on those procedures


40
New cards

Risk Assessment Procedures

As part of the risk assessment, the service auditor obtains an understanding of the service organization's system/ controls

  • Includes processes and procedures used to:

    • Prepare the description of the system; control objectives

    • Identify the controls designed to achieve control objectives;

    • Assess suitability of the design of the controls;

    • Assess the operating effectiveness of controls


Risk Assessment Procedures: PERFORM A WALKTHROUGH

  1. Inquiring of service organization management, those charged with governance who have relevant information

  2. Observing operations and inspecting documents, reports, and printed and electronic records of transaction processing

  3. Inspecting a selection of agreements between the service organization and its user entities

  4. Reperforming the application of a control

  5. Reading relevant reports received from regulators, internal auditors, or other specialists


41
New cards
42
New cards
43
New cards
44
New cards