SOC stands for System and Organization Controls and represents a group of compliance standards developed by the American Institute of CPAs (AICPA) – a network of professionals across the globe. SOC Audits aim to examine all the policies, procedures, and internal controls of an organization. SOC reports are designed to help organizations, that deal with information systems and share their information with other organizations.
| SOC 1 (Financial Controls) | SOC 2 (IT Controls) | SOC 3 (Publicly Shareable) | |
|---|---|---|---|
| ABOUT | A SOC 1 may be a report on Controls at a Service Organization which are relevant to user entities control over financial reporting. | A SOC 2 report is predicated on the prevailing SysTrust and WebTrust principles. The aim of the SOC 2 report is to gauge an organization’s information systems relevant to security, availability, processing integrity, confidentiality, or privacy. | SOC 3 is analogous to SOC 2 is predicated on the prevailing Systrust and WebTrust principles. The difference being, the report doesn’t detail the testing performed and is supposed to be used as marketing material |
| PURPOSE | Audits of financial Statements | GRC Programs, Oversight, Due Diligence | Marketing or General Purpose |
| INTENDED USERS | Financial Statement Auditors, Customers, Related third parties | Management, Regulators, Related third parties | Anyone with a need for confidence in service organization’s controls |
| FOCUS ON | Internal controls relevant to Financial Reporting | Operational controls regarding security, availability, processing integrity, confidentiality or privacy | Easy to read report on Controls |
| REPORT TYPE | Type I Type II | Type I Type II | General |
| EVALUATES | Design of Internal Control Operation Effectiveness of Internal Control during review period | Design of Internal Control Operation Effectiveness of Internal Control during review period | Design of Controls related to SOC2 objectives |
| Report Types | SOC 1 | SOC 2 |
|---|---|---|
| TYPE 1 |
|
|
| TYPE 2 |
|
|
Visit following sections for more information’s on next step for getting certified from Cetonix
Talk to our team about accredited certification, GRC compliance or auditor training tailored to your organisation.