Skip to content

SOC 1 (SSAE 18)

Definition

A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for Attestation Engagements No. 18. Used primarily by financial statement auditors to assess how a vendor's controls affect the user entity's audit.

Full form
Service Organization Control 1
Governing standard
SSAE No. 18
Focus
Controls over financial reporting
Primary audience
Financial statement auditors

Common questions

Who typically requests a SOC 1 report from a vendor?+

A user entity's external financial auditor requests it, because they need to understand how a service organisation's controls, such as a payroll processor's, affect the accuracy of the user entity's own financial statements during the audit.

How does SOC 1 differ from SOC 2 in what it covers?+

SOC 1 is scoped narrowly to controls relevant to financial reporting. SOC 2 has a broader scope built around the AICPA Trust Service Criteria, covering security and, where selected, availability, confidentiality, processing integrity, and privacy, none of which SOC 1 is designed to assess.

Is a SOC 1 report useful for evaluating a vendor's cybersecurity posture?+

Generally no. Its control objectives are defined around financial-statement-relevant processes, so it can be silent on broader security controls such as access management or incident response that a SOC 2 report is specifically built to address.

Related terms

Complementary User Entity Controls (CUECs)
Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user...
SOC 2
A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus...
Trust Service Criteria (TSC)
The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are...
Type I Report
An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...
Type II Report
An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.