SOC 1

Give your clients assurance over
financial reporting controls

A SOC 1 report is an examination of controls at a service organization that are likely to be relevant to your clients' internal controls over financial reporting, and/or financial systems. ControlCase works on SOC 1 attestations in combination with our network of CPA partners. Examinations are performed by both ControlCase IT and Cybersecurity experts and CPA accounting experts, and the report is signed off by registered CPAs, in good standing with State Board of Accountancy and that are registered for and participate in the AICPA Peer Review Program, while the wider ControlCase team brings the assessment experience built across PCI DSS, ISO 27001, and HITRUST.

Assess Once, Comply to Many

Meet Your Clients' Audit Needs

SOC 1 reports are specifically intended to meet the needs of entities that use service organizations (user entities) and the CPAs who audit those user entities' financial statements (user auditors).

Support User Auditors

The report helps user auditors evaluate the effect of controls at your organization on your clients' financial statements, reducing friction during their audit cycles.

Demonstrate Control Effectiveness

A Type 2 report covers both the suitability of design and the operating effectiveness of controls over a defined period.

Answer the Right Request

If your services may impact the control environment of one or more of your clients' financial reporting activities, SOC 1 is the correct report, not SOC 2.

What is a SOC 1 Report?

What is a SOC 1 Report?

SOC 1 is an examination of controls at a service organization that are likely to be relevant to user entities' internal control over financial reporting. SOC 1 reports are specifically intended to meet the needs of entities that use service organizations (user entities) and the CPAs that audit the user entities' financial statements (user auditors) in evaluating the effect of the service organization's controls on the user entities' financial statements.

The AICPA created two SOC reporting options so service organizations can obtain the right third-party assurance report. SOC 1 addresses internal control over financial reporting. SOC 2 evaluates information systems relevant to security, availability, processing integrity, confidentiality, and/or privacy. Service organizations that do not affect their clients' financial reporting should select SOC 2 instead.

Why Choose ControlCase for SOC 1?

A CPA Association Built for Attestation Work
SOC 1 reports must be issued by licensed CPAs. ControlCase works hand-in-hand with our CPA partners to handle the attestation portion of SOC engagements by leveraging the Information Technology experts within ControlCase with the Accounting and Assurance experts who are CPAs, and the report comes from practitioners who are qualified to sign it.
One Audit Across Your Framework Set
Most organizations that need a SOC 1 also carry SOC 2, ISO 27001, or PCI-DSS obligations. ControlCase's technology offering, Compliance Hub, provides control mapping for other standards and regulations out of the box, so evidence gathered once supports multiple reports through the “One Audit” approach instead of running each engagement in isolation. Compliance Hub is part of the service offering at no additional cost.
A Dedicated Point of Contact
ControlCase assigns a named point of contact to each engagement who provides the support and coordination needed from kickoff through report issuance, so you are not chasing status across teams.

Which SOC 1 Report Do You Need?

Path 1

SOC 1 Type 1

Reports on management's description of the service organization's system and the suitability of the design of controls at a point in time.

Path 2

SOC 1 Type 2

Reports on management's description of the system, the suitability of the design, and the operating effectiveness of controls over a period of time retrospectively, normally 12 months.

ControlCase SOC 1 Process

STEP 01
Scoping and Engagement Setup
Confirm that SOC 1 is the right report rather than SOC 2. Agree on Type 1 or Type 2, define the system and confirm the control objectives in scope, and assign your point of contact.
STEP 02
System Description Support
A SOC 1 engagement rests on management's description of the system. ControlCase advises on structure and ultimate completeness, while the description is written by and remains management's own.
STEP 03
Examination Fieldwork
The CPA conducts the examination alongside your ControlCase assessor. For a Type 1 this tests the suitability of design as of the stated date. For a Type 2 it also tests operating effectiveness across the agreed review period.
STEP 04
Report Issuance
ControlCase issues via the CPA partner, the SOC 1 report with the practitioner's opinion, ready to share with your clients and their auditors, and agrees on the timing of your next annual cycle.
STEP 01
Scoping and Engagement Setup
Confirm that SOC 1 is the right report rather than SOC 2. Agree on Type 1 or Type 2, define the system and confirm the control objectives in scope, and assign your point of contact.
STEP 02
System Description Support
A SOC 1 engagement rests on management's description of the system. ControlCase advises on structure and ultimate completeness, while the description is written by and remains management's own.
STEP 03
Examination Fieldwork
The CPA conducts the examination alongside your ControlCase assessor. For a Type 1 this tests the suitability of design as of the stated date. For a Type 2 it also tests operating effectiveness across the agreed review period.
STEP 04
Report Issuance
ControlCase issues via the CPA partner, the SOC 1 report with the practitioner's opinion, ready to share with your clients and their auditors, and agrees on the timing of your next annual cycle.

Ready to Start Your SOC 1 Report?

Book Expert Time
Chat with an Advisor Available now
Chat with our representative
Compliance Advisor
Compliance Advisor HUMAN · LIVE
Online now · Replies within 2 minutes