What does SOC 1 Type 1 report mean on the CPA exam?
SOC 1 Type 1 report. A report on the fairness of the description and the suitability of the design of controls, at a point in time. It does not test whether the controls actually ran.
Defined against AT-C 320.08.
Which CPA exam sections use SOC 1 Type 1 report?
SOC 1 Type 1 report appears in the AUD section of the CPA exam.
What is the difference between SOC 1 Type 1 report and SOC 1 Type 2 report?
A Type 1 report covers the fairness of the description and the SUITABILITY OF THE DESIGN of controls at a point in time. A Type 2 report covers those plus the OPERATING EFFECTIVENESS of the controls over a period. Only a Type 2 supports reducing substantive testing, because only a Type 2 tests whether the controls actually ran. (AT-C 320)
Other terms defined against AT-C 320
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.
- inclusive method: Brings a subservice organization's controls inside the description and the scope of the service auditor's report, so one report covers both organizations.
- SOC 1 Type 2 report: A report covering the description, the suitability of design, and the operating effectiveness of controls over a period.
- suitably designed: The controls, if they operated as described, would achieve the stated objective.
Related terms
- SOC 3 report: A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- auditor's report: The document carrying the opinion, with its sections in a fixed order.
- technological feasibility: The point at which software to be sold, leased, or otherwise marketed reaches a completed detail program design or, absent one, a working model.
- Type 1 subsequent event: A recognized subsequent event: it gives evidence about a condition that already existed at the balance sheet date, so the statements are adjusted.
- referential integrity: The database rule that a foreign key must point at a row that actually exists.