SOC 1 – Financial reporting-related controls under ISAE 3402

Overview 

A SOC 1 report addresses controls at a service organisation that are relevant to its clients’ internal control over financial reporting. It is requested in particular by internationally active or US-oriented clients and their auditors. SOC 1 and ISAE 3402 pursue a comparable purpose, but are based on different professional frameworks. The required framework or report format primarily depends on the requirements of the intended report users. 

To whom is the standard relevant? 

  • Globally active service providers with a focus on the US
  • Companies with financial reporting-related processes
    Typical examples include:
    • Payroll service providers
    • Shared service centres
    • Financial service providers
    • Business process outsourcing
    • IT application service providers
  • Outsourcing partners with international clients, particularly with a US focus

Scope of services 

  • Audit of the internal control system (ICS)
  • Type 1: design assessment
  • Type 2: effectiveness assessment over a period of time
  • Readiness assessment

Benefits 

  • Recognised evidence for auditors, particularly with a US focus
  • Reduction of financial statement-related requests and customer audits
  • International acceptance, particularly with a US focus

FAQ