Internal Assessment of Third-Party SOC Reports

The first batch of posts here have been from the perspective of the audit firm performing System and Organization Controls (SOC) examinations. It’s worth taking a step back and looking at things from the perspective of the company receiving an SOC report as part of their third-party risk management (TPRM) process.

An important aspect of Governance, Risk, and Compliance (GRC) is ensuring third-party service providers maintain appropriate internal controls. This has become even more relevant as companies outsource services so they can focus on their core competencies. For example, using the example company in prior posts, Trikomo Payroll would focus on payroll processing and outsource data center facilities and network operations for their systems to a third-party managed services provider. Sticking with creating company names using references to Greece, let’s name this data center managed service provider Acropolis Web Services (AWS). Is that acronym too on the nose?

Trikomo Payroll would need to consider and assess risks related to outsourcing to AWS. From that perspective, Trikomo Payroll would implement a periodic (annual) control to review AWS internal controls. This can be in the form of an Internal Controls Questionnaire (ICQ). Typically, however, AWS will respond by providing their SOC 1 and/or 2 report, which they had completed by an independent audit firm as a proactive measure to limit the time and resources required to complete individual ICQs for each of their clients.

At this point, legal, security, and/or compliance personnel will need to know what to look for when reviewing the AWS SOC report(s). Included below is a list of items they’ll want to look for:


General / Opinion

  • Is the audit firm that performed the SOC examination reputable?
  • Are services used by Trikomo Payroll covered by the report?
  • Is the period covered by the report appropriate?
  • Was there a “clean” opinion or was it qualified?

The AICPA has an online tool that can be used to search for the firm to ensure they’ve completed a peer review, which is an assessment of the audit firms system of quality control. The tool can be found here –> AICPA Peer Review Program.


Complementary User Entity Controls (CUEC)

  • Reconcile (or map) the CUECs included in the AWS SOC report to internal controls implemented by Trikomo Payroll.
  • Assess the risk for any CUEC’s that Trikomo Payroll do not have complementary controls to mitigate.

AWS would have completed an SOC examination to assess internal control requirements for the vast majority of their clients. As such, the scope of the report, and subsequently one or more of the CUECs, might include services not used by Trikomo Payroll.

Example template for mapping SOC CUECs to internal controls.

Complementary Subservice Organization Controls (CSOC)

  • Determine if AWS used any subservice organizations to provide services relevant to Trikomo Payroll.

Depending on the nature and extent of services outsourced, there might be a need to request the SOC report from the subservice organizations if it’s determined their services are relevant to Trikomo Payroll. However, due to restrictions on report disseminated, it might be difficult to obtain the subservice organization report.


Controls & Test Results

  • Are controls relevant to Trikomo Payroll included in the report?
  • Are there any exceptions noted as a result of testing those controls?
  • Does Trikomo Payroll have internal controls in place to mitigate the risk for any test exceptions noted.

Typically, if exceptions noted in the report didn’t rise to the level of qualifying the control objective (and subsequently the report opinion), the risk to Trikomo Payroll would be limited. However, it’s important to track these exceptions from year-to-year to determine if it’s a recurring issue with the service provider.


The staff performing the assessment will want to document the date the assessment was completed and who completed the assessment as evidence for their auditors. I’ve found the best method for documenting the evidence is to use an internal ticketing system as it creates an electronic record of the assessment having occurred, the evidence (e.g., SOC report, CUEC mapping, etc.) can be attached, the date it was completed, and it doesn’t get lost if there’s personnel turnover.

SOC 2 and the Trust Services Principles/Criteria

In my first post, way back on June 1ˢᵗ, I provided a brief overview of the System and Organization Controls (SOC) 1, 2, and 3 reports. Since then the posts have mostly been from the SOC 1 perspective, although the concepts still mostly apply to SOC 2 reports. Either way, I figured it would be beneficial to go into a little more detail about SOC 2 reports.

Example cover page for an SOC 2 Type 2 report.

Trust Services Principles/Criteria:

SOC 2 examinations were born out of the Trust Services Principles (TSP) and were later renamed as Trust Services Criteria (TSC). There are 5 TSCs that can be included in an SOC 2 report. Service organizations have the option to include 1 or more of these in their report depending on the needs of their clients.

Security / Common Criteria: The Security criteria ensures systems and information are protected against unauthorized access and disclosure. Initially, there were some security criteria that spanned all 5 TSCs. As a result, those criteria were consolidated into what is now known as the Common Criteria (CC), which also include aspects of the organizations overall control environment, risk assessment processes, and monitoring activities. There are 9 overall Common Criteria (CC1 – CC9).

The Security / Common Criteria is the baseline for inclusion in all SOC 2 reports. In other words, a service organization can choose to include just the Security / Common Criteria in their examination / report or include 1 or more of the remaining TSCs at their discretion.

Availability: The Availability criteria ensures systems are accessible and operational based on internal and/or contractual requirements. The criteria in this principle include performance monitoring, data backup, and testing of disaster recovery plans. There is 1 overall Availability criteria (A1).

Example availability criteria (A1) as noted in the TSC.

Included in the image above are the A1: Additional Availability criteria. The service organization would document 1 or more of their controls for each of the 3 sub-criteria noted. Those controls are what the service auditor would assess.

Processing Integrity: The Processing Integrity criteria ensures system processing is complete, valid, accurate, timely, and authorized. In essence, the controls supporting this criteria ensure the systems do what they were intended to do, without errors. There is 1 overall Processing Integrity criteria (PI1).

Confidentiality: The Confidentiality criteria ensures the organization is able to identify, maintain, and protect sensitive data thought the use of encryption, access controls, and data disposal procedures. There is 1 overall Confidential criteria (C1).

Privacy: The Privacy criteria ensures Personal Identifiable Information (PII) is collected, used, retained, and disclosed in accordance with the organizations own privacy policy and generally accepted privacy principles.

The Privacy criteria is expansive and requires a lot of time to assess. As a result, including the Privacy criteria in an SOC 2 examination / report substantially increases the overall cost to complete the engagement, compared to just including the 1ˢᵗ 4 TSCs, making it the least likely to be included in an SOC 2 examination / report. There are 8 overall Privacy criteria (P1 – P8).

SOC2+:

Service organizations also have the option to complete an SOC 2+ examination / report. This report would include an assessment of 1 or more TSCs along with other criteria specified by the service organization. The other criteria can be objectives typically included in an SOC 1 report for clients that are also interested in the financial statement impact of the services provided by the service organization. Or, for example, the service organization could include requirements under the Health Insurance Portability and Accountability Act Security Rule (e.g., HIPAA) in the SOC 2+ report. I haven’t seen organizations used this option often, rather deciding to have separate SOC 1 and SOC 2 examinations completed, with either/both provided to clients based on their specific needs.

SOC Report Structure / Overview

System and Organization Controls (SOC) reports are pretty easy to read once you get a handle of how they’re structured. The reports are typically made up of 4 or 5 sections, not including the cover page and table of contents.

The section details below are provided to give a general idea of what’s included in each section. However, they’re not all inclusive. I’ll go into more detail regarding some of the sections in later posts.

Section I: Independent Service Auditor’s Report

The Independent Service Auditor’s Report includes the scope of the engagement, service organization and service auditor responsibilities, and most important of all, the auditor’s opinion. The opinion will include 2 or 3 statements depending on if it’s a Type 1 or Type 2 report.

A Type 1 report will indicate the description is fairly presented and the controls related to the control objectives were suitably designed as of a specific date (e.g., September 30, 2025).

A Type 2 report will indicate the description is fairly presented, controls related to the control objectives were suitably designed throughout the period (e.g., October 1, 2024 – September 30, 2025), and controls operated effectively to provide reasonable assurance the control objectives were achieved throughout the period (e.g., October 1, 2024 – September 30, 2025).

Example SOC 1 Type 2 Opinion

Section II: Management Assertion

The Management Assertion documents, from the management of the service organization perspective, the services included in the scope of the report, any services completed by subservice organizations (if applicable), acknowledges the service organizations responsibilities in fairly presenting system, and that the controls were suitably designed.

The service auditor will typically provide a Management Assertion template to the service organization for review and completion. The service organization has a choice to sign or leave it unsigned in the final report.

Section III: Description of the System

The Description of the System provides an overview of the service organization operations and controls in narrative form. There are certain aspects that are required to be included, while others can be limited by just referencing the control objectives and controls documented in Section IV. I’ve found the best system description includes more detail than just the control objectives / controls and provides a cross reference of controls between both sections.

This section also includes complementary controls for both users (service organization clients) and subservience organizations.

Section IV: Tests of Controls and Results

Control objectives, controls supporting each control objective, tests completed by the service auditor, and test results are noted in this section, typically in table format. The test results would note if any exceptions were noted during testing, even if the report has a “clean opinion.” The best case scenario for the service organization is for the test results to note something in line with “No exceptions noted.” for each control.

Example control, test of operating effectiveness, and test results.

Section V: Other Information Provided by the Service Organization (Optional)

The Other Information section is optional at the discretion of the service organization. Some companies will use this section to provide additional information about their organization that was not included in the description of the system. This can include other services provided by the organization or future plans for the organization.

Also, in the event there were exceptions / issues noted during testing that were reported in Section IV of the report, some organizations will include additional background regarding the exception(s), action plans to remediate the control weaknesses, and if the action plans were already implemented.

The service auditor will review this section for adequacy, but it’s not subjected to the same procedures applied in forming an opinion. In other words, this section is not tested by the service auditor.

The Manager Assertion, Description of the System, Control Objective and Controls included in the Section IV, and Other Information sections are all provided by the service organization. The only sections / parts noted above that are technically completed by the service auditor are Section I and the tests of operating effectiveness and test results columns included in Section IV.