What does SOC 1 Type 2 report mean on the CPA exam?
SOC 1 Type 2 report. A report covering the description, the suitability of design, and the operating effectiveness of controls over a period. Only a Type 2 supports reducing substantive testing.
Defined against AT-C 320.08.
Which CPA exam sections use SOC 1 Type 2 report?
SOC 1 Type 2 report appears in the AUD section of the CPA exam.
What is the difference between SOC 1 Type 2 report and SOC 1 Type 1 report?
A Type 1 report covers the fairness of the description and the SUITABILITY OF THE DESIGN of controls at a point in time. A Type 2 report covers those plus the OPERATING EFFECTIVENESS of the controls over a period. Only a Type 2 supports reducing substantive testing, because only a Type 2 tests whether the controls actually ran. (AT-C 320)
Other terms defined against AT-C 320
- carve-out method: Excludes a subservice organization's control objectives and controls from both the description and the scope of the service auditor's report.
- inclusive method: Brings a subservice organization's controls inside the description and the scope of the service auditor's report, so one report covers both organizations.
- SOC 1 Type 1 report: A report on the fairness of the description and the suitability of the design of controls, at a point in time.
- suitably designed: The controls, if they operated as described, would achieve the stated objective.
Related terms
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.
- SOC 3 report: A general use report on the same trust services criteria as a SOC 2, without the system description or the tests and results.
- operating effectiveness: Whether a control actually worked across the period, as opposed to whether it was well designed.
- auditor's report: The document carrying the opinion, with its sections in a fixed order.
- further audit procedures: The work done in response to assessed risk: tests of controls and substantive procedures.
- general IT control: A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information.