SOC Planning – Controls Risk Assessment

There are various planning steps that occur at the onset of a System and Organization Controls (SOC) 1 and/or 2 engagement, most of them the client isn’t aware is happening in the background. These steps are generally included in the audit program with templates available to complete some of the steps.

The controls risk assessment is a planning step that can begin once the control matrices are received from the client. This is when the fun begins. The SOC controls risk assessment is different from what would normally be included in a NIST-based risk assessment, which looks at risks from a confidentiality, integrity, and availability perspective, and assesses those risks based on impact and likelihood.

The SOC control risk assessment analyzes the design of controls to ensure they adequately meet the control objective or trust service criteria (TSC), the significance of the controls as they related to the objective/criteria, and the risk of non-compliance for each control.

Example SOC 1 control matrices for an access control objective. This is not a fully fleshed out objective and is just being used for illustrative purposes.

Control Design

The primary goal when reviewing the controls is to determine whether the sum of the controls adequately support the control objective or TSC.

This is a wholesale review of the controls to ensure they meet the minimum requirements of the control objective. Although not ideal, there are situations in which a single control is enough to meet the controls objective. It’s also possible for there to be 10+ controls and still miss a key aspect of the control objective.

Using the example control matrices above, if this were a very large organization, I’d inquire about controls to update access for employees that transfer from one business unit (BU) or department to another BU or department. This is a potential area for there to be a design deficiency.

There’s a lot of grey area in this review that requires professional judgement that comes from working with clients both big and small, more and less complex. The audit firm should be cautious about starting the engagement before clearing up any potential design deficiencies.


Control Significance

The control significance assessment determines the significance of the control as it relates to the control objective. Each control is assessed a rating of high, moderate, or low based on its significance. A high control significance would indicate the control has a direct correlation to the control objective. A moderate control significance would indicate a supporting control. A low control significance would indicate limited or no correlation to the control.

At a minimum, there needs to be at least 1 control with high control significance per objective/criteria. Otherwise, there would be a design deficiency.

In my experience, policies and procedures would be assessed as low control significance, assuming the control objective doesn’t directly call out for policies and procedures. This isn’t to say policies and procedures aren’t an important aspect of the overall control environment, just that they’re not directly related to meeting the objective/criteria as stated. Monitoring controls (e.g. periodic review) would be assessed as moderate control significance. These controls are detective controls rather than preventive controls.


Risk of Non-Compliance

Each control is then assessed a rating of high or low based on the risk that testing would result in an exception or finding. This assessment is pretty straightforward. Controls are typically assessed as low risk of non-compliance unless one of the following criteria are met:

  • First Year Engagement: All controls are assessed a high risk of non-compliance.
  • Subsequent Year Engagement: Control assessed a high risk of non-compliance if exceptions or findings were noted in the prior year.
  • Other: Although less frequent, if exceptions were noted during other internal control assessments, the control could also be assessed as a high risk of non-compliance. These might be found on a corrective action plan (CAP) reports provided during planning.

Example completed risk assessment using the access control matrices in the image above.

Why

Now, you might ask, what’s the purpose of going through this process? There are 2 primary reasons:

  1. Completeness: Ensure the controls are complete and there are no design deficiencies that would result a qualified opinion.
  2. Sampling: Control significance and risk of non-compliance are used as a basis for determining testing sample sizes.

The completed risk assessment is documented in the audit workpapers and isn’t usually provided to the client. However, in some situations, the client might request the results of the risk assessment in what would be referred to as a test plan. The test plan would include the risk assessment along with a tentative plan for how each control will be tested. This request is more common with government clients.


Not all firms use the same audit methodology as noted above. However, it’s important for service organizations to understand what goes into each of the steps of an engagement prior to contracting with a service auditor. The best time to do this is during the request for services and proposal process, at which point the service auditor should provide a general audit methodology used to complete the engagement.

SOC Examination Lifecycle & What to Expect

There are 3 distinct phases during the SOC 1 and SOC 2 examination lifecycle; planning, fieldwork, and reporting. There are a lot of steps that happen behind the scenes within each of these phases, but for purposes of this post we’re mostly going to focus on steps that are more visible to the service organization.

We’re going to use a hypothetical 12-month examination period from October 1, 2024 through September 30, 2025 for this SOC examination lifecycle.

WordPress AI generated step-by-step flowchart of the SOC examination phases. I attempted to tweak it a little using the WordPress AI tool, but it consistently made it worse, so I then used ChatGPT to align it better with the information included in the post. Not exact, but gives a decent overview.

Planning:

The planning phase should start at least 3 months before the end of the examination period, depending on if the project plan includes a single or split fieldwork phase, which we’ll get into in the next section. However, if I had my way, planning would ideally start around 6-9 months before the end of the period.

Using the 12-month examination period example, this would have the planning phase starting in the January to March range. Either way, it’s best to get started as early as possible to allow the service auditor and service organization to properly plan (e.g., assign staff) the project timeline. Included below are various tasks that occur during the planning phase.

Contract / Engagement Letter: The service auditor typically won’t complete any work on the examination until the contract and/or engagement letter is signed by the service organization.

Kick-off Meeting / Entrance Conference: This might be a single meeting or separate meetings depending on the client. Government clients like having a smaller kick-off meeting with project management personnel to set the stage and then follow-up with a more formal entrance conference to include process/control owners. The control matrices (SOC 1 control objectives/controls or SOC 2 criteria/controls) should be provided shortly after the kick-off meeting.

Controls Risk Assessment: The service auditor assesses the controls for design completeness, control significance, and non-compliance risk. This process directly feeds into the document request list (DRL). However, more importantly, this allows the service auditor to determine if there are any major design gaps in the controls that need to be remediated before fieldwork can begin. I’ll get into more detail regarding the risk assessment process in a separate post.

Document Request List: The initial DRL is typically more high level in a first year examination as the service auditor doesn’t have a detailed understanding of the controls yet. During subsequent year examinations, the prior year request list can be used as a baseline for a more thorough initial DRL. The DRL should be provided at least 2 weeks prior to fieldwork and is a living document throughout the examination.


Fieldwork

The fieldwork phase is when the meat of the examination occurs, including interviews, inspections, observations, walkthroughs, and detail tests of controls. Depending on the client and size of the project, this phase can be completed during a single combined fieldwork period or separately as interim and final/year-end fieldwork.

Single Fieldwork: A single fieldwork phase would typically start about 1-2 weeks before the end of the examination period. This would have fieldwork starting during the 2ⁿᵈ half of September using the 12-month example. A single fieldwork phase is common for smaller examinations. However, it’s also not totally uncommon for larger examinations to get a late start and go through a single fieldwork phase.

Split Fieldwork: A split interim and final fieldwork phase is typical for larger examinations. In a split fieldwork scenario, at a minimum, the service auditor will complete interviews with process/control owners to gain an understanding of the control environment and validate the design and accuracy of the controls. If any gaps are identified, the service auditor will work with the service organization to document additional and/or compensating controls.

Using the 12-month examination period example, interim fieldwork would occur sometime between April and July, allowing the service auditor to complete initial testing for 6-9 months worth of transactions. Year-end fieldwork would start the week after the examination period ends, which would be the 1ˢᵗ week of October in the example.


Reporting

The reporting phase will begin approximately 2-4 weeks after the end of the examination period, after all testing is completed. This is highly dependent on how responsive the service organization is in responding to document requests and how quickly the service auditor is able to inspect the documentation. This also assumes no exceptions / finding are noted during testing.

Draft Report: Testing workpapers go through multiple levels of review by the service auditor leading up to issuing the draft report. I’ve had clients request the initial draft report within 15 days after the end of the examination period (e.g., October 15ᵗʰ). However, this puts undue strain on both the service organization and service auditor. Ideally, issuance of the draft report would occur around 4 weeks after the end of the examination period.

Exit Conference: An exit conference is scheduled between the service auditor, project management team, and process/controls owners to discuss the draft report and provide timeframes for any management responses if any findings are identified. The meeting can occur anywhere between 1-2 (or more) weeks after issuing the draft report.

Final Report: The service auditor will request the service organization review and sign various documents prior to issuing the final report, including a management assertion letter and management representation letter. Ideally, the final report is issued approximately 6-8 weeks after the examination period ends. As someone that’s performed examinations with a period ending September 30ᵗʰ quite often, my goal is to have the report finalized before the week of Thanksgiving.


The timing for planning and fieldwork is more condensed for a 9-month examination period (e.g., January 1ˢᵗ – September 30ᵗʰ). However, the reporting phase tends to be about the same.

And Now For Something Completely Different

Last month I asked some friends to come up with a title for the monthly post of topics outside the normal focus of the blog. One of them gave me the idea of naming it “And Now For Something Completely Different”, which is taken from Monty Python’s Flying Circus, or so I’m told. I liked the idea, but should also note I didn’t know where the phrase came from and never actually watched the show outside of a few skits on YouTube. Feel free to use that against me. 😀


WordPress

Let’s start things off with a topic related to this blog and millions of sites on the interweb. A WordPress vulnerability was found in the wild affecting versions 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. The vulnerabilities affect self-hosed WordPress.org sites, not sites hosted by WordPress.com.

I self-hosted my personal blog for a while, leasing server space with GoDaddy, but then transferred it to WordPress.com in 2012. Self-hosting was fun for a while as it allowed me to make unlimited changes to the look and feel of the site, without restrictions. It also put me in a position to learn a little more about how things work on the backend, but as life got busy it just turned into more of a hassle. It was worth moving to a hosted site with WordPress.com for its ease of use.

With that said, if you’re using a self-hosted .org site and don’t have it set to automatically update, you should do that now.

https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk


Click to Pray

Bob the Hacker posted another doozy this month related to the Click to Pray app. Click to Pray is the Pope’s official prayer app launched in 2018 that does the things you would think it would do. However, Bob found a vulnerability that made Personally Identifiable Information (PII) available to anyone. He notified various powers that be about the vulnerability during January 2026, but never received a response and it didn’t get fixed. That is, it wasn’t fixed until he posted about it earlier this month. Again, he received no response about the fix, only finding out it was fixed after reading about it online.

https://bobdahacker.com/blog/click-to-pray


META

The more Meta pushes to expand their use of AI, and that doesn’t even include their “glasses”, the more I want to delete all my Meta accounts. As I noted last month, I still have a Facebook account to keep up with things going on in my community / neighborhood and also still have a IG account. The IG account is set to private, limiting it to only friends / contacts I’ve approved, which is a pretty small group. The last picture I posted there was in 2022. There’s still a high probability I’ll delete both FB and IG accounts at some point.

Meta announced they were going to start using pictures from public IG accounts as a basis for other users to create alternate pictures with it’s AI image generator and it was going to be automatically turned on for all public accounts, requiring the user to turn it off. In essence, if you weren’t paying attention to the news, you wouldn’t even know it was happening. The public wasn’t having it and they eventually decided to back off their plan.

https://www.androidcentral.com/apps-software/meta/meta-removes-muse-image-ai-from-instagram-after-users-voiced-major-concerns


That’s it for this month.