Nearly every type of business relies on external service providers to help keep operations running smoothly and to provide customers, clients, or patients with high-quality service and care. Whether it’s a cloud-based accounting or HR system, an outsourced medical billing provider, a financial services core system, or an investment management application, service providers can make your job easier and more efficient. But remember: You can outsource operational functions, but you cannot outsource responsibility.
Effective oversight of service provider vendors is essential for managing risk and potential adverse impacts to your reputation. For instance, patients don’t care that it was a third-party who didn’t patch a server that gave hackers access to their personal data; they care their data was exposed and they hold you, as the service provider, responsible for lack of oversight of your contracted third party (sub-service organization). Unlike functions that are performed in-house, when services are outsourced, you may have limited information on hand and less control over the process. A System and Organizational Controls (SOC) report can be an invaluable tool in helping you gain confidence about the controls at your service providers.
What is a SOC report?
A SOC report is a way to verify that an organization has designed sufficient controls and that those controls are in place and operating effectively. These controls are typically related to organization and management, operations, logical security, networking, access, application processing, privacy, and availability. These controls are tested for operating effectiveness by independent third-party auditors. Any exceptions are identified in the SOC report and may vary by severity from a report qualification to a minor issue. Based on the type of SOC report (explained below), it is up to you as a service organization to determine the impact on your business and customers of any noted exceptions and to act accordingly.
Which SOC report should you request?
There are primarily two different types of SOC reports. It is important to understand these types so that your organization can obtain the most relevant report to address your reporting and vendor due diligence needs. You may also have a need to require both reports from a service provider, which is very common.
- SOC 1: Reports on controls at a service organization that may be relevant to user entities’ internal control over financial reporting. These would be ideal for organizations whose service organization provides a service that would impact financial reporting (ask yourself: Is the service provided impactful to your financial statements?)
- Type 1: A design of controls report. This option evaluates and reports on the design of controls put into operation at a point in time. You can think of this as a “kicking the tires” report.
- Type 2: Includes the design and testing of controls to report on the operational effectiveness of controls over a period of time. This is more of a “deep dive” report.
- SOC 2: The purpose is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, or privacy. The SOC 2 has predefined criteria in which the service organization identifies internal controls they need to address the criteria. A SOC 2 audit is more prescriptive than a SOC 1.
It is not uncommon for service organizations, especially larger ones, to have many SOC reports covering many specific functions and systems. They may also have a SOC 1 and SOC 2 report for the same function or system. A SOC 1, Type 2 report is more valuable than a SOC 1, Type 1 report since it tests the operational effectiveness of controls over a period of time. A financial statement auditor will likely want to see a SOC 1, Type 2 report. Type 1 reports are typically done the first time a service organization undergoes a SOC exam, with the expectation that in subsequent years, a Type 2 report will be issued.
When should you request a SOC report?
Not all service providers need to be treated equally from a monitoring perspective. Perform a periodic risk assessment to determine how risky a service provider is to your organization. This risk assessment should consider items such as:
- What functions are they providing to your organization?
- Is the service organization’s service material to your financial statements?
- Does the service organization have access to your systems and data?
- Does the service organization have access to, process, manage, and maintain customer personally identifiable information (PII) or credit card information?
- Have there been issues with this vendor in the past, including through review of their SOC report?
This risk assessment will drive the level of monitoring needed on an ongoing basis, including if review of a SOC report is necessary, and the frequency of this review.
How to conduct and document a SOC report review
For those service providers in which SOC reports will be reviewed, make sure you have a consistent review process that is followed each time. BerryDunn has a review checklist available on our website to ensure your review is consistent and captures the salient items.
When you receive a SOC report, it should be thoroughly reviewed and documented, including the date of the review and who performed it. More so than reviewing the SOC report, you must also review user control considerations (UCCs). UCCs are controls that the service organization had included in the report as critical to the internal control cycle and are the responsibility of you, as their customer. The UCCs should be reviewed and determined if they are applicable to the services you receive from the service organization, and if they are, you should determine that controls are in place and should be tested internally for operating effectiveness.
There are certain items within a SOC report we recommend that you review and document:
- System or function covered: Make sure the SOC report covers the function or system pertinent to your organization.
- Type of report: Is it a SOC 1 or SOC 2? If a SOC 1, is it a Type 1 or Type 2?
- Period covered in the report: What period does the report cover? If being used for a financial statement audit, is a bridge letter needed?
- Service auditor: Who is the service auditor? Are they reputable, qualified, and independent from the service provider?
- Opinion: Review the service auditor’s report. What opinion was provided? Were there any opinion exceptions?
- Subservice organizations: Does the service provider rely on any third-party service providers?
- Control objectives: Review the controls pertinent to your organization. Were there any testing exceptions identified?
The use of service providers, for most organizations, is unavoidable. It is important to have a thorough process to monitor these service providers to help ensure they don’t adversely impact your organization’s operations. Requesting and reviewing SOC reports from your service providers is one effective due diligence mechanism. We hope you will find our SOC review checklist helpful and, to learn more, please watch our video on how to effectively use this checklist.