SOC 1 (SSAE 18)
Definition
A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for Attestation Engagements No. 18. Used primarily by financial statement auditors to assess how a vendor's controls affect the user entity's audit.
- Full form
- Service Organization Control 1
- Governing standard
- SSAE No. 18
- Focus
- Controls over financial reporting
- Primary audience
- Financial statement auditors
Common questions
Who typically requests a SOC 1 report from a vendor?+
A user entity's external financial auditor requests it, because they need to understand how a service organisation's controls, such as a payroll processor's, affect the accuracy of the user entity's own financial statements during the audit.
How does SOC 1 differ from SOC 2 in what it covers?+
SOC 1 is scoped narrowly to controls relevant to financial reporting. SOC 2 has a broader scope built around the AICPA Trust Service Criteria, covering security and, where selected, availability, confidentiality, processing integrity, and privacy, none of which SOC 1 is designed to assess.
Is a SOC 1 report useful for evaluating a vendor's cybersecurity posture?+
Generally no. Its control objectives are defined around financial-statement-relevant processes, so it can be silent on broader security controls such as access management or incident response that a SOC 2 report is specifically built to address.
Related terms
- Complementary User Entity Controls (CUECs)
- Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user...
- SOC 2
- A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus...
- Trust Service Criteria (TSC)
- The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are...
- Type I Report
- An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...
- Type II Report
- An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a...