Transcription of Service Organization Control (SOC) Reports
1 Service Organization Control (SOC) Reports : What they are and what to do with them OCTOBER 28, 2016 Presenter Colin Wallace, CPA/CFF, CFE, CIA, CISA Partner Colin has provided management consulting and internal audit services to public, private, government, and not-for-profit organizations since 2002. He has organized and performed financial, operational, and compliance audits throughout the United States and abroad, and has worked on all aspects of the internal audit process including planning, analysis, reporting, and project management. Colin has led numerous fraud investigations involving misappropriation and misuse of company assets, the Foreign Corrupt Practices Act, and management override of internal controls.
2 In addition, he has managed significant SOC examination and SOX 404 assessment projects from initial implementation to final reporting. Colin is an active member of the firm s Technology, Communications and Media Group and is a leader of the firm s forensic and investigative services team. He currently serves as the quality Control practice leader for the Business Risk Group. OBJECTIVES Understand the differences between SOC 1, 2, and 3 Reports List items that are and aren t covered in SOC Reports Analyze the scope of your provider s report Assess the impact of complementary user entity controls and internal Control exceptions Work with an auditor or management to evaluate and complement their Service providers controls | 3 OVERVIEW Historical with SAS 70 SAS 70 Reporting New with SSAE 16 SOC 1 Internal Controls Over Financial Reporting New with AT101 SOC 2 Trust services Principles (Detailed Reporting) SOC 3 Trust services Principles (Summary Reporting)
3 | 4 DEFINITIONS SOC 1 report oA report on Controls at a Service Organization which are relevant to the user entities internal Control over financial reporting. SOC 2 report oReport on Controls at a Service Organization related to compliance or operations and based on Trust services Principles and Criteria. Principles covered include Security, Availability, Processing Integrity, Confidentiality and/or Privacy. SOC 3 report oA SOC 3 report is a general-use report that provides only the auditor s report on whether the system achieved the Trust services Criteria without including a description of tests and results or opinion on the description of the system.
4 | 5 SOC comparison : REPORTING OPTIONS soc 1 soc 2 SOC 3 Summary Detailed Reports for users and auditors Detailed report for users, auditors and specified parties Summary report that can be more generally distributed Applicability Focused on financial reporting risks and controls specified by the Service provider Most applicable when the Service provider performs financial transactions processing or supports transaction processing systems Focused on the Trust services Principles: oSecurity oAvailability oConfidentiality oProcessing Integrity oPrivacy Applicable to a broad variety of systems | 6 SOC comparison : SCOPE soc 1 soc 2 / SOC 3 Required focus Internal Control over financial reporting Compliance or operational controls Define scope and systems Classes of transactions Procedures for processing and reporting transactions Accounting records of the systems Handling of significant events and conditions other than transactions report preparation for users Other aspects relevant to processing and reporting user transactions Infrastructure Software Procedures People Data Control domains covered Transaction processing controls Supporting information technology general controls Security Availability Confidentiality Processing Integrity
5 Privacy Level of standardization Control objectives are defined by the Service provider and may vary depending on the type of Service provided. Principles are selected by the Service provider Specific predefined criteria are used rather than Control objectives | 7 SOC comparison : report STRUCTURE soc 1 soc 2 SOC 3 Auditor s Opinion Auditor s Opinion Auditor s Opinion Management Assertion Management Assertion Management Assertion Assertion System Description (including controls) Assertion System Description (including controls) Assertion System Description (including controls) Control Objectives Criteria Criteria (referenced) Control Activities Control Activities Test of Operating Effectiveness* Test of Operating Effectiveness* Results of Tests* Results of Tests* Other Information (if applicable) Other Information (if applicable) *Note: Only applicable for Type II Reports .
6 | 8 SOC comparison : report TYPES Type I Type II SOC Reports soc 1 soc 2 soc 1 soc 2 Coverage Point in time Period of time Assessment Design Design Operating Effectiveness Results of Tests | 9 INTERNATIONAL REPORTING ISAE 3402 SSAE 16 (SOC 1) United States CICA 5970 Canada HKCPA HK/China AUS 810 Australia AAF 01/06 United Kingdom Others | 10 WHY ARE SOC Reports IMPORTANT? services outsourced to Service organizations are relevant to the audit when these services and related controls are part of the entity s information system which is relevant to financial reporting. When reliance is placed on controls at Service organizations and their sub- Service providers, it is important to obtain and review SOC Reports covering a sufficient portion of the audit period.
7 | 11 WHY DO WE REVIEW SOC Reports ? New Hire InformationEmployee TerminationOther Employee Masterfile ChangesPayroll RegisterPayroll Journal EntriesFinancial Statements | 12 PCAOB OBSERVATIONS Reliance on Service organizations was not identified or not properly documented. Sub- Service organizations that were scoped out of the report were not addressed. Complementary-entity user controls were not sufficiently tested or not properly linked to the test of controls. Update procedures were not properly performed or documented when the auditor s report did not sufficiently cover the entire audit period. Control exceptions identified by the Service provider were not evaluated to determine the sufficiency of audit procedures.
8 | 13 HOW ARE SOC Reports EVALUATED? Description Inventory Inventory existing outsourced vendor relationships to determine whether third-party assurance may be required Assess Assess the key financial reporting risks associated with significant outsourced vendors Identify in-scope Service organizations Identify Identify relevant Reports that have been obtained and determine appropriateness Identify any additional Reports or documents needed to complete the assessment ( , bridge letter, Management s discussion with the Service provider, etc.) Test and Conclude Assess the adequacy of the SOC report scope Perform review procedures to evaluate the operational effectiveness of controls relied upon at the Service Organization | 14 STRUCTURE AND CONTENTS OF SOC 1/SOC 2 Reports The structure and contents of SOC 1 and SOC 2 Reports generally follows the below list.
9 OIndependent Service auditor s report (opinion) oManagement s written assertion oService Organization s description of the system oComplementary user entity controls oControl objectives (SOC 1)/Criteria (SOC 2), Control activities and Control tests performed (Type II Reports ) oSupplemental information from the Service Organization When performing an evaluation of an SOC report , management should identify and evaluate each section of the report | 15 INDEPENDENT Service AUDITOR S report This section describes the scope of the examination and provides the Service auditor s opinion on: oManagement s presentation of its system of internal Control . oThe suitability of the design of the system.
10 OOpinion on the operating effectiveness of the controls (Type II Reports only). It generally includes the following sections: oScope oService Organization s Responsibilities oService Auditor s Responsibilities oInherent Limitations oOpinion oDescription of Test of Controls oRestricted Use | 16 REVIEWING INDEPENDENT Service AUDITOR S report Verify that the report coverage is adequate. If the coverage is insufficient and/or the report date does not coincide with the client s year-end, verify how Management was able to gain acceptance of the coverage exceptions. Verify the type of report issued and determine whether it is appropriate for use ( , SOC 1 vs.)