20 certification schemes

SOC 1 Type II

SOC 1 Attestation

SOC 1 reports on the controls a service organisation operates that affect its clients' internal control over financial reporting.

Standard
SOC 1 Type II
Indicative timeline
12-20 weeks to readiness, plus a 6-12 month observation period
Discipline
Compliance & Security
Assessment type
Independent third-party assessment

The standard

Overview

SOC 1 is an attestation engagement, not a certification. It reports on the controls a service organisation operates that are relevant to its clients' internal control over financial reporting. Examinations follow the AICPA attestation standards, principally AT-C section 320; ISAE 3402 is the international equivalent. Management defines the control objectives, and the examination tests the controls supporting them. A Type II report covers design and operating effectiveness over a stated period.

The report is written for your clients and their external auditors. Where a service you run affects their financial statements, such as payroll, payments, claims handling or fund administration, their auditors need assurance over your controls. A current Type II report answers that once, in a form auditors accept.

UKCert prepares organisations for the examination: transaction flows in scope, control objectives, control descriptions, advance testing and the evidence set the service auditor will request. The opinion itself is issued by an independent, licensed CPA firm.

Who this is for

  • Payroll and payment processing providers
  • Fund administrators, custodians and transfer agents
  • Claims handlers and insurance administrators
  • Hosting providers running clients' finance systems
  • Suppliers whose clients' auditors request control assurance

What it gives you

Why organisations certify

What a certified SOC 1 Type II assessment gives you once the certificate is issued.

Answers Client Auditors

External auditors receive a report prepared to a standard they recognise, which removes the need to negotiate bespoke assurance with each client every year.

Fewer Client Audits

One examination replaces repeated site visits and control questionnaires from individual clients, reducing the demand placed on your finance and operations teams.

Contract Requirement Met

Financial services and outsourcing contracts often oblige the supplier to provide a SOC 1 or ISAE 3402 report. Holding one keeps renewals and new bids on track.

Documented Control Set

Control objectives and the controls supporting them are written down and owned, so responsibility for each check is clear rather than assumed.

Evidence of Operation

A Type II report covers a period, not a date. It shows the controls ran throughout, which is what client auditors rely on when planning their own work.

Errors Found Earlier

Testing controls across a full period surfaces exceptions, weak segregation of duties and missing approvals while there is still time to correct them.

Scope

What the assessment covers

The areas an assessor works through. Your final scope is confirmed in writing before any audit is booked.

  • Management-defined control objectives
  • System description prepared by management
  • Transaction processing and data flow scoping
  • Complementary user entity controls
  • Subservice organisation carve-out or inclusive method
  • Tests of control design and operating effectiveness
  • Management's written assertion
  • Bridge letter covering the period after the report

How it runs

The assessment, stage by stage

From first enquiry to certificate. Each stage is agreed with you before it starts.

  1. Scoping and Readiness

    We identify the services and transaction flows that touch client financial reporting, agree the system boundary, and decide whether subservice organisations are carved out or included.

  2. Control Objectives

    Control objectives and the controls that meet them are drafted with your process owners, alongside the complementary user entity controls your clients will be expected to operate.

  3. Gap Remediation

    We test the controls as they stand, record where design or evidence is missing, and work through remediation before the observation period opens rather than during it.

  4. System Description

    Management prepares the description of the system and the written assertion. We review both for completeness against the controls in scope and the way the service actually runs.

  5. Observation Period

    The service auditor tests controls across the agreed period, commonly six or twelve months. We coordinate evidence collection and sampling so requests do not stall your teams.

  6. Report and Renewal

    The independent CPA firm issues the report with its opinion. Bridge letters cover the gap to client year ends, and the examination repeats annually to keep coverage continuous.

Questions

SOC 1 Type II — frequently asked

Anything here that does not cover your situation, put it to an assessor rather than guessing at it.

Ask a question

Readiness work commonly runs twelve to twenty weeks, depending on how many transaction flows are in scope and how well the controls are already documented. The observation period follows, usually six or twelve months for a Type II, and the service auditor issues the report several weeks after that period closes. First reports sometimes use a shorter initial period.

A SOC 1 report has no expiry date. It covers a stated period, and its usefulness depends on how recent that period is. Client auditors normally expect a report covering a period ending within the last twelve months, which is why reports are produced annually. A bridge letter from management covers the interval to the client's year end.

No. No law requires a SOC 1 report. The pressure is contractual and audit-driven. When your service affects a client's financial statements, that client's auditors must obtain assurance over your controls under their own auditing standards. Providing one report is usually simpler for both sides than accommodating separate audits from every client.

The examination repeats over the next period. Scoping is revisited to reflect new services, systems or subservice organisations, control descriptions are updated, and the service auditor tests again. Where the previous report contained exceptions, remediation is checked. Successive reports should leave no uncovered gaps in the timeline, which is what client auditors look for.

SOC 1 covers controls relevant to clients' financial reporting, and management defines the control objectives. SOC 2 covers the AICPA Trust Services Criteria, which are fixed: security, availability, processing integrity, confidentiality and privacy. Organisations whose service affects both financial statements and customer data security sometimes need both reports. Assessment work is quoted on the scope involved.

Certifying against more than one standard?

Where you hold several standards, shared clauses are assessed once in a combined visit rather than as separate audits. Talk it through with an assessor before you decide what SOC 1 Type II should sit alongside.