The first batch of posts here have been from the perspective of the audit firm performing System and Organization Controls (SOC) examinations. It’s worth taking a step back and looking at things from the perspective of the company receiving an SOC report as part of their third-party risk management (TPRM) process.
An important aspect of Governance, Risk, and Compliance (GRC) is ensuring third-party service providers maintain appropriate internal controls. This has become even more relevant as companies outsource services so they can focus on their core competencies. For example, using the example company in prior posts, Trikomo Payroll would focus on payroll processing and outsource data center facilities and network operations for their systems to a third-party managed services provider. Sticking with creating company names using references to Greece, let’s name this data center managed service provider Acropolis Web Services (AWS). Is that acronym too on the nose?
Trikomo Payroll would need to consider and assess risks related to outsourcing to AWS. From that perspective, Trikomo Payroll would implement a periodic (annual) control to review AWS internal controls. This can be in the form of an Internal Controls Questionnaire (ICQ). Typically, however, AWS will respond by providing their SOC 1 and/or 2 report, which they had completed by an independent audit firm as a proactive measure to limit the time and resources required to complete individual ICQs for each of their clients.
At this point, legal, security, and/or compliance personnel will need to know what to look for when reviewing the AWS SOC report(s). Included below is a list of items they’ll want to look for:
General / Opinion
- Is the audit firm that performed the SOC examination reputable?
- Are services used by Trikomo Payroll covered by the report?
- Is the period covered by the report appropriate?
- Was there a “clean” opinion or was it qualified?
The AICPA has an online tool that can be used to search for the firm to ensure they’ve completed a peer review, which is an assessment of the audit firms system of quality control. The tool can be found here –> AICPA Peer Review Program.
Complementary User Entity Controls (CUEC)
- Reconcile (or map) the CUECs included in the AWS SOC report to internal controls implemented by Trikomo Payroll.
- Assess the risk for any CUEC’s that Trikomo Payroll do not have complementary controls to mitigate.
AWS would have completed an SOC examination to assess internal control requirements for the vast majority of their clients. As such, the scope of the report, and subsequently one or more of the CUECs, might include services not used by Trikomo Payroll.

Complementary Subservice Organization Controls (CSOC)
- Determine if AWS used any subservice organizations to provide services relevant to Trikomo Payroll.
Depending on the nature and extent of services outsourced, there might be a need to request the SOC report from the subservice organizations if it’s determined their services are relevant to Trikomo Payroll. However, due to restrictions on report disseminated, it might be difficult to obtain the subservice organization report.
Controls & Test Results
- Are controls relevant to Trikomo Payroll included in the report?
- Are there any exceptions noted as a result of testing those controls?
- Does Trikomo Payroll have internal controls in place to mitigate the risk for any test exceptions noted.
Typically, if exceptions noted in the report didn’t rise to the level of qualifying the control objective (and subsequently the report opinion), the risk to Trikomo Payroll would be limited. However, it’s important to track these exceptions from year-to-year to determine if it’s a recurring issue with the service provider.
The staff performing the assessment will want to document the date the assessment was completed and who completed the assessment as evidence for their auditors. I’ve found the best method for documenting the evidence is to use an internal ticketing system as it creates an electronic record of the assessment having occurred, the evidence (e.g., SOC report, CUEC mapping, etc.) can be attached, the date it was completed, and it doesn’t get lost if there’s personnel turnover.