SOC 1 readiness

We help service organizations prepare the controls that affect customers' financial reporting, with evidence organized for the CPA firm's SOC 1 examination.

On this page

What SOC 1 is

SOC 1 is a report on controls at a service organization that are relevant to its customers' internal control over financial reporting (ICFR). A licensed CPA firm performs the examination under the AICPA attestation standards, in AT-C section 320.

In SOC 1 terms, your customers are user entities. Their financial statement auditors, called user auditors, use your report to rely on your controls when they audit those customers. Requests usually come from customers whose financial transactions pass through your service, such as payroll, payments, loan servicing, fund administration, billing and claims processing.

Key facts

Control objectives

Management defines control objectives tied to financial reporting risk, such as complete and accurate transaction processing or restricted access to financial data. The examination is built around them.

IT general controls

Most SOC 1 reports include objectives for logical access, change management, computer operations and backups that support the financial processing.

Business process controls

Controls over the input, processing, reconciliation and output of transactions you handle for customers.

Complementary user entity controls

Controls your customers must operate for your control objectives to be achieved. The report lists them so user auditors can check them.

Subservice organizations

Vendors such as cloud or data center providers that support your service. The report presents their controls using either the carve-out method or the inclusive method.

Type 1 and Type 2

A Type 1 report covers the system description and control design as of a date. A Type 2 adds operating effectiveness over a period, which user auditors generally need in order to rely on your controls.

How readiness works with us

We identify the services your customers rely on for financial reporting, the processes and systems that deliver them, and the subservice organizations involved. With your team we draft or refine the control objectives and agree whether to start with a Type 1 or a Type 2.

What you receive

Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.

Gap assessment

  • Services, systems and subservice organizations in scope
  • Status of each control against its control objective
  • Prioritized remediation plan with owners and target dates

Controls and documentation

  • Control matrix mapping controls to control objectives
  • Controls implemented or improved in your environment
  • Policies and procedures updated where gaps exist

Evidence set

  • Evidence organized by control objective for the auditor
  • Defined populations, evidence sources and frequencies
  • Setup in your compliance platform if you use one

Testing and audit support

  • Pre-audit control testing results
  • Fixes for exceptions found in testing
  • Help with auditor requests during fieldwork

Control areas we commonly implement

Access to financial systems

Role-based access, MFA, privileged access limits, joiner, mover and leaver steps, and periodic access reviews. We can deploy identity with Keycloak.

Change management

Approval and testing before production changes, separation of duties and records that tie each deployment to an approved change.

Computer operations

Monitoring of scheduled jobs and interfaces, alerts on failures and records of how each failure was resolved.

Backups and recovery

Backup schedules for financial data, restore tests and a documented recovery plan.

Logging and monitoring

Logs of access and changes to financial systems, with alerts and a record of review. We deploy open-source monitoring such as Wazuh.

Vendor oversight

An inventory of subservice organizations, review of their SOC reports and tracking of the controls they expect you to operate.

SOC 1 and SOC 2 compared

Some service organizations need both reports. When they do, the two can share scoping work, IT general controls and much of the evidence.

TopicSOC 1SOC 2
SubjectControls relevant to customers' financial reportingControls relevant to security, and optionally availability, processing integrity, confidentiality and privacy
CriteriaControl objectives defined by managementAICPA Trust Services Criteria
Main readersCustomer management and their financial statement auditorsCustomer security, risk and procurement teams
Attestation standardAT-C section 320AT-C section 205
Report typesType 1 and Type 2Type 1 and Type 2
Common requestersCustomers of payroll, payments, fund administration and billing servicesCustomers of SaaS, cloud and data processing services

Who does what

We prepare your environment and evidence for the examination. We scope, assess, help implement controls, test them and support your team during fieldwork. We do not perform the examination or issue the report.

Your independent CPA firm plans and performs the examination, decides its own procedures, tests your controls and issues the SOC 1 report with its opinion.

Your team owns the service and the controls. Management provides the system description and control objectives and signs the assertion. Control owners run their controls during the period. We can help draft the description and objectives for management to review.

Common questions

How long does readiness take?

It depends on your scope and how mature your controls are today. During scoping we give you a plan with dates for each phase. For a Type 2, also plan for the review period, because the auditor needs evidence that controls operated across it.

Do we need SOC 1 or SOC 2?

It depends on why customers are asking. If their financial statement auditors need to rely on your service, SOC 1 fits. If their security teams are evaluating how you protect data, SOC 2 fits. We review the requests you have received during scoping.

Can you work with our compliance platform?

Yes. If you use Vanta, Drata or a similar platform, we work inside it. We map controls, connect integrations and upload evidence. If you do not use one, we organize evidence in a folder structure your auditor can follow.

Do you perform the SOC 1 audit?

No. A licensed CPA firm performs the examination and issues the report. We prepare your team for it and support you while it runs.

Can you help after the report is issued?

Yes, through a retainer. We can help address exceptions noted in the report, keep evidence on schedule for the next period and prepare for the next examination. If customers ask about the time between your report period and their fiscal year end, your management can issue a bridge letter, and we can help gather the supporting information.

What do we need to prepare?

A named owner on your side, descriptions of the services customers rely on, access to the systems that process financial data, and any existing process documentation, reconciliations and policies. An NDA can be in place before we start.

How to prepare

List the services customers rely on for financial reporting and the customer or auditor requests you have received. Note any deadlines tied to customers' fiscal year ends.

Gather what you already have: process descriptions, reconciliations, reports you send to customers, change and access procedures, and a list of vendors that support the service. Gaps are expected. The gap assessment exists to find them.

Choose an internal owner who knows both the operational process and the supporting systems. If you have already selected a CPA firm, share their contact so we can align on control objectives and timing early.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.