Example: marketing

SOC 1 reporting services - EY - United States

SOC 1 reporting servicesValue to clients We know your people,environment, processes,and technology. We have an establishedand tested set ofprocesses and protocolsfor working with you oninternal controls overfinancial reporting . Through SOC 1 testing,we continue to identifyefficiencies throughmulti-purpose risk andcontrols evaluations. We utilize experiencedprofessional in ourFinancial ServicesOrganization along withsubject matterresources withexperience providingattestation reports fororganizations likely tobe relevant to an auditof a user s entityfinancial statements. We advise you on how toleverage the SOC 1report to enhance yourcustomer sunderstanding of theservice organization sprocesses. Thisperspective is a majorpart of the EYdifference. We update you onimpending changes onSOC 1 reporting andwork with you to planfor efficient an external service provider, you have designed your processes to meet yourcustomers operational and processing needs, but are you addressing their auditand compliance needs?

SOC 1 reporting services Value to clientsThe SOC 1 report • We know your people, environment, processes, and technology. • We have an established and tested set of

Tags:

  Services, Reporting, Soc 1 reporting services

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of SOC 1 reporting services - EY - United States

1 SOC 1 reporting servicesValue to clients We know your people,environment, processes,and technology. We have an establishedand tested set ofprocesses and protocolsfor working with you oninternal controls overfinancial reporting . Through SOC 1 testing,we continue to identifyefficiencies throughmulti-purpose risk andcontrols evaluations. We utilize experiencedprofessional in ourFinancial ServicesOrganization along withsubject matterresources withexperience providingattestation reports fororganizations likely tobe relevant to an auditof a user s entityfinancial statements. We advise you on how toleverage the SOC 1report to enhance yourcustomer sunderstanding of theservice organization sprocesses. Thisperspective is a majorpart of the EYdifference. We update you onimpending changes onSOC 1 reporting andwork with you to planfor efficient an external service provider, you have designed your processes to meet yourcustomers operational and processing needs, but are you addressing their auditand compliance needs?

2 If not, you may be missing a critical focus on providing your customers services in an efficient and effectivemanner, but this may not be enough. Your customers also need to: Understand controls over the processes they have outsourced and their effecton their internal controls Evaluate the design of those controls Have confidence that the controls are functioning as intendedService Organization Controls (SOC) reports are prepared in accordance with theAmerican Institute of Certified Public Accountant s (AICPA) Attestation Standards,and may also include an expression of opinion in accordance with the InternationalAuditing and Assurance Standards Board s (IAASB) International Standard onAssurance Engagements (ISAE) 3402. These standards allow independent auditorsto issue reports that help meet the compliance and audit needs of your your customers compliance and audit needs Improved Risk Management Experienced independent audit teams evaluatesyour existing processes and controls over financial reporting to identifyopportunities for improvement.

3 Independent review of control environment Through compliance withregulatory guidance and leading industry best practices, SOC 1 report willsupport a service organization s ability to address a financial statement auditwith greater confidence. Decreased costs Service organizations without a SOC 1 report may be subjectto testing by a customer s internal and external auditors. This disruptsoperations and requires the redeployment of scarce resources to assist theauditors. Enhanced communications A well described system in a SOC 1 report canincrease transparency to a customer and improve its understanding of internalcontrols over financial 1 reporting benefitsA SOC 1 report is an examination (similar to an audit) of a description produced by youof the system(s) you operate on behalf of your customers that are relevant to theirinternal control processes related to financial reporting .

4 There are two types ofreports: type 1 and type 2. Type 1 reports provide: A description of your controls supported by a management assertion and an auditor sopinion on the fairness of that description, and whether the controls had been placedinto operation A management assertion and an auditor s opinion on whether the controls aresuitably designed to meet the control objectivesA type 2 report adds a management assertion and an auditor s opinion on theoperating effectiveness of your controls in addition to the opinions provided in a type SOC 1 impacts your entire organizationConsider theseSOC1 reportingbenefits1. Improved riskmanagement2. Independentreview of controlenvironment3. Transparencyand ownershipof controls4. Baseline todrive controlmaturityGovernanceControlsUsage of ReportCommunicationsChangeReadinessMonit oring &Enforcement Mission.

5 Visionand values Tone at thetop Greatertransparencyof the issues Who reviews &assures quality Who isaccountable tocontroleffectiveness Clarity inroles/responsibilitiesfor reducing/limiting gaps Access controldeficiencies Identifyineffective orpoorlydesignedcontrols Identifycontrolmitigationstrategies Identifyfinancial risks Understandcontrols impact to userentityfinancialreporting Followthorough withcorrectiveactionplanning Stakeholdercommunicationplan ManagerToolkits Establishstakeholderworkingcouncils Recurring gapanalysis Assessment ofcontrols Performancemanagementmetrics Drive controlmaturitythroughcontinuousimprovem ent Technologychange Processchange Resourceinfusion Changeleadershipalignment Changecapability Changenetworksestablished Employeefeedbackloopestablished StakeholderreadinessassessmentThe SOC 1 reportOur approach is focused on helping you meet your customer s audit andcompliance requirements.

6 It includes the following: Working with you to understand your customers regulatory and complianceneeds in order to develop a strategy for meeting those needs Assisting you in developing the control objectives for your processes Assisting you in planning an appropriate approach to the risk assessment andidentifying the basis for your assertion Helping your personnel identify the controls you have implemented to addressthe control objectives Testing the operational effectiveness of your controls Assisting you in describing your controls in the SOC 1 report reporting on the results of our testingSOC 1 Report Practical ApproachHow the process works Perspective your SOC 1 report is not just a tool for meeting clients requirements; it is usually the single best description of your processes andprocedures that you can provide your clients.

7 We advise you on how to leveragethis communication to enhance your clients understanding of your perspective is a major part of the EY difference. Experienced professionals our service delivery teams includes dedicatedprofessionals with significant experience performing SOC 1 engagements. Thismeans you will be teaming with people who understand the issues that canarise, and how critical your programs and projects are to your organization ssuccess. Knowledge our skilled professionals experience and knowledge from workingwith multiple clients is leveraged to benefit your organization teams of professionals is focused on providing the right services at the righttime to leading organizations in both the public and private sector. EY can helporganizations achieve their business objectives by providing a wide range ofadvisory services that are designed to help enhance risk management activitiesand improve business processes.

8 From our network of member firms around theworld, EY s professionals provide services that help clients assess, improve andmonitor their business EY differenceDevelop proposalsPlan the SOC 1 PerformexaminationReport the resultsUser organization: Regulatory AuditrequirementsUnderstand thekey businessprocesses anduser organizationneeds orproposalsEvaluate systemdesign andperform tests ofoperatingeffectivenessExternalcommunic ationSOC 1 report for aspecified periodEY | Assurance | Tax | Transactions | AdvisoryAbout EYEY is a global leader in assurance, tax, transaction and advisory services . The insights and quality services wedeliver help build trust and confidence in the capital markets and in economies the world over. We developoutstanding leaders who team to deliver on our promises to all of our stakeholders.

9 In so doing, we play a criticalrole in building a better working world for our people, for our clients and for our refers to the global organization, and may refer to one or more, of the member firms of Ernst & YoungGlobal Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited byguarantee, does not provide services to clients. For more information about our organization, please 2016 Ernst & Young LLPAll Rights no. 00000196 Ernst & Young LLP (UEN T08LL0859H) is a limited liability partnership registered in Singapore under theLimited Liability Partnerships Act (Chapter 163A).This material has been prepared for general informational purposes only and is not intended to be reliedupon as accounting, tax or other professional advice.

10 Please refer to your advisors for specific : Regulatory AuditrequirementsPlan and scopethe engagementReview resultswith managementServiceexpectations andrelationshipprotocolsDevelop detailedtesting approachand work programServiceorganization: Regulatory AuditrequirementsSummarizeexecutivemanag ement andaudit committeecommunicationsInternalcommunica tionManagementLetterRepeat in subsequent periods using lessons learnedOur organization plays an important role internationally in the SOC reportinglandscape. We have representatives in working groups defining the professionalstandards that are used for SOC reporting . We have over 1150 professionals worldwidewhose daily work is delivering SOC reports to our clients. All this leads to a substantialamount of thought leadership on SOC reporting within our organization.


Related search queries