TL;DR
A Service Organization Control (SOC) 1 report is a formal audit document that verifies a service organization's internal controls over client financial data. Issued in two types — Type 1 (design of controls) and Type 2 (operating effectiveness) — these reports are often required in medical, financial, and data-handling industries. Conducted by a specialized Certified Public Accountant (CPA) firm, a SOC 1 audit typically takes weeks to months and remains valid for up to 12 months. Organizations that can modify client financial data are generally classified as SOC 1 service organizations and may be required to produce a report before winning new business.
What is a SOC 1 report?
A SOC 1 report details how your organization protects client financial data. You'll use reports like this to validate your commitment to your current and potential customers.
SOC reports were designed, in part, by the AICPA. The organization says two types of SOC 1 reports exist (Type 1 and Type 2). Both require an organization to detail how they secure client data. Only Type 2 SOC 1 reports look over the operating effectiveness of those plans.
| Report Type | What It Covers |
|---|---|
| Type 1 | Details how the organization secures client data (design of controls) |
| Type 2 | Details how the organization secures client data AND evaluates the operating effectiveness of those plans |
What is SOC 1 used for?
Every day, you and your staff follow protocols regarding client data. You do all you can to ensure you don't change or otherwise invalidate that information. SOC 1 reports help you audit those plans and prove you're doing what you say you will do.
SOC 1 audits look over so-called "controls." These may apply to:
- Programs. Do the tools you use protect information?
- Data. Do your workflows allow changing of critical information?
- Resources. Do the computers, servers, and other pieces of equipment you use protect data?
An auditor may look over the physical pieces of your organization. The auditor may also look over the processes, permissions, and passwords that protect information. The auditor doesn't have to prove that everything is watertight. Instead, they will simply try to prove or disprove that you're keeping the promises made in your report.
Are SOC 1 reports mandatory?
Some industries are under regulatory or legal pressure to create SOC reports, including:
- Medical: Does your company process medical claims for customers?
- Financial: Do you service loans for your customers? Do you process payroll? Any financial data could be subject to a SOC 1 report.
- Data: Do you store information for customers? Do you offer software that could alter financial information?
The ability to "write" information is important here. If you can only see information but never change it, you may not need a SOC 1 report. But if you have the ability and authority to make a mistake when you alter data, a report could be critical. If you can change data, your company is technically a "SOC 1 service organization," and potential customers may demand to see a report before doing business with you.
How does a SOC 1 audit work?
As part of the process, you'll create attestation reports that detail everything you do to protect client data. You'll also give access to both your facility and your staff. Your firm will take the work from there. Expect the process to take weeks, if not months.
How do you hire the right CPA firm for a SOC 1 audit?
Hire a CPA firm that specializes in IT audits to handle your SOC 1 audit. It's not advised to complete the hard work yourself. You'll need an expert to walk through the process with you.
How long does a SOC 1 report remain valid?
The final report is typically good for a full 12 months, but some last for longer or shorter time periods. Ask your CPA firm how long yours will last before you get started.
As part of your audit, you may learn that poor authentication puts client data at risk. Find out about five identity attacks that exploit broken authentication on our blog.
Frequently asked questions
What is the difference between a Service Organization Control (SOC) 1 Type 1 and Type 2 report?
Both report types require an organization to document how it secures client financial data. The key distinction is scope: a Type 1 report evaluates whether the right controls are in place at a specific point in time, while a Type 2 report goes further by assessing whether those controls are actually operating effectively over a defined period.
Does my company need a Service Organization Control (SOC) 1 report?
If your organization has the ability to modify client financial data — such as processing payroll, servicing loans, or storing data that affects financial reporting — you are likely classified as a SOC 1 service organization. In that case, customers or regulators may require you to produce a SOC 1 report before entering into a business relationship.
Who is qualified to conduct a Service Organization Control (SOC) 1 audit?
SOC 1 audits must be performed by a CPA firm that specializes in IT audits. It is not advisable to attempt the audit internally. The firm will review your attestation reports, your physical facilities, and your staff's processes, permissions, and access controls.
How long does a Service Organization Control (SOC) 1 audit take, and how long is the report valid?
The audit process can take weeks or even months to complete. Once finalized, the resulting report is typically valid for 12 months, though the exact duration can vary. It is recommended to confirm the validity period with your CPA firm before beginning the process.
What specific controls does a Service Organization Control (SOC) 1 audit examine?
A SOC 1 audit examines whether the tools, workflows, and physical or technical resources your organization relies on are adequately protecting client data — for instance, whether software programs guard information, whether data workflows prevent unauthorized changes, and whether equipment such as servers is properly secured.
What is an attestation report, and why does it matter in a Service Organization Control (SOC) 1 audit?
As part of the SOC 1 audit process, your organization prepares attestation reports that detail everything you do to protect client data. The CPA firm then uses those reports — alongside access to your facility and staff — to prove or disprove that you are keeping the promises documented in your report. This is the core mechanism by which the auditor validates your controls.
References
SOC for Service Organizations: Information for Service Organizations. AICPA.