Type II Report
Definition
An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a specified period, typically six to twelve months. The auditor performs testing throughout the period.
- Framework
- SOC attestation reporting
- Scope
- Design suitability and operating effectiveness
- Typical period
- Six to twelve months
- Method
- Auditor testing throughout the period
Common questions
Why do investigators and auditors treat a Type II report as stronger evidence in a control failure or breach investigation?+
Because the auditor actually tested whether controls operated as designed across a sustained period rather than confirming design on paper alone, a Type II opinion speaks directly to whether a control was functioning during the period an incident occurred.
What can a Type II report not tell an investigator?+
It covers only the specific period and control objectives tested, so a control failure just outside the review window, or a control objective not included in scope, falls outside what the report can attest to.
Related terms
- Complementary User Entity Controls (CUECs)
- Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user...
- SOC 1 (SSAE 18)
- A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for...
- SOC 2
- A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus...
- Trust Service Criteria (TSC)
- The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are...
- Type I Report
- An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...