SOC 1 Attestation
SOC 1 reports on the controls a service organisation operates that affect its clients' internal control over financial reporting.
- Standard
- SOC 1 Type II
- Indicative timeline
- 12-20 weeks to readiness, plus a 6-12 month observation period
- Discipline
- Compliance & Security
- Assessment type
- Independent third-party assessment
The standard
Overview
SOC 1 is an attestation engagement, not a certification. It reports on the controls a service organisation operates that are relevant to its clients' internal control over financial reporting. Examinations follow the AICPA attestation standards, principally AT-C section 320; ISAE 3402 is the international equivalent. Management defines the control objectives, and the examination tests the controls supporting them. A Type II report covers design and operating effectiveness over a stated period.
The report is written for your clients and their external auditors. Where a service you run affects their financial statements, such as payroll, payments, claims handling or fund administration, their auditors need assurance over your controls. A current Type II report answers that once, in a form auditors accept.
UKCert prepares organisations for the examination: transaction flows in scope, control objectives, control descriptions, advance testing and the evidence set the service auditor will request. The opinion itself is issued by an independent, licensed CPA firm.
Who this is for
- Payroll and payment processing providers
- Fund administrators, custodians and transfer agents
- Claims handlers and insurance administrators
- Hosting providers running clients' finance systems
- Suppliers whose clients' auditors request control assurance
What it gives you
Why organisations certify
What a certified SOC 1 Type II assessment gives you once the certificate is issued.
Answers Client Auditors
External auditors receive a report prepared to a standard they recognise, which removes the need to negotiate bespoke assurance with each client every year.
Fewer Client Audits
One examination replaces repeated site visits and control questionnaires from individual clients, reducing the demand placed on your finance and operations teams.
Contract Requirement Met
Financial services and outsourcing contracts often oblige the supplier to provide a SOC 1 or ISAE 3402 report. Holding one keeps renewals and new bids on track.
Documented Control Set
Control objectives and the controls supporting them are written down and owned, so responsibility for each check is clear rather than assumed.
Evidence of Operation
A Type II report covers a period, not a date. It shows the controls ran throughout, which is what client auditors rely on when planning their own work.
Errors Found Earlier
Testing controls across a full period surfaces exceptions, weak segregation of duties and missing approvals while there is still time to correct them.
Scope
What the assessment covers
The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.
- Management-defined control objectives
- System description prepared by management
- Transaction processing and data flow scoping
- Complementary user entity controls
- Subservice organisation carve-out or inclusive method
- Tests of control design and operating effectiveness
- Management's written assertion
- Bridge letter covering the period after the report
How it runs
The assessment, stage by stage
From first enquiry to certificate. Each stage is agreed with you before it starts.
-
Scoping and Readiness
We identify the services and transaction flows that touch client financial reporting, agree the system boundary, and decide whether subservice organisations are carved out or included.
-
Control Objectives
Control objectives and the controls that meet them are drafted with your process owners, alongside the complementary user entity controls your clients will be expected to operate.
-
Gap Remediation
We test the controls as they stand, record where design or evidence is missing, and work through remediation before the observation period opens rather than during it.
-
System Description
Management prepares the description of the system and the written assertion. We review both for completeness against the controls in scope and the way the service actually runs.
-
Observation Period
The service auditor tests controls across the agreed period, commonly six or twelve months. We coordinate evidence collection and sampling so requests do not stall your teams.
-
Report and Renewal
The independent CPA firm issues the report with its opinion. Bridge letters cover the gap to client year ends, and the examination repeats annually to keep coverage continuous.
Questions
SOC 1 Type II — frequently asked
Anything here that does not cover your situation, put it to an assessor rather than guessing at it.
Same discipline
Other schemes in Compliance & Security
Certifying against more than one standard?
Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what SOC 1 Type II should sit alongside.