On this page
A SOC 1 auditor is the CPA firm, called the service auditor, that examines a service organization’s controls relevant to its customers’ internal control over financial reporting (ICFR) and issues the SOC 1 report. The AICPA attestation standard for the work is AT-C section 320. Management states the control objectives and describes the system, then signs a written assertion about the description and the controls. The auditor tests that assertion and gives an opinion.
Four checks decide the choice: the firm is a licensed CPA firm, it is independent of you, it has issued SOC 1 reports for services like yours, and its proposal covers the same scope as every other proposal you collect. Whether your service needs SOC 1 or SOC 2 is a separate decision, answered in SOC 1 vs SOC 2.
What does a SOC 1 auditor do?
The service auditor examines management’s description of the system, management’s assertion, the control objectives, and the controls behind them. The AICPA defines SOC 1 as an examination of controls at a service organization that are likely to be relevant to user entities’ ICFR. The report is written for those user entities and for the CPAs who audit their financial statements (user auditors).
Role: Describes the system, states the control objectives, asserts that the controls meet them, and operates the controls.
Depends on: The service auditor's opinion to satisfy customers and their auditors.
Role: Examines the description, assertion, and controls, tests them, and issues the opinion in the report.
Depends on: Management's description and evidence, and independence from the service organization.
Role: Receives the report, runs the customer-side controls the report lists, and stays responsible for its own financial statements.
Depends on: The report for coverage of the service it uses, and its own controls for everything else.
Role: Decides how far the customer's audit can rely on your controls.
Depends on: The report's scope, period, opinion, and exceptions, and its own assessment of the service auditor's competence and independence under AU-C section 402.
SOC 2 tests against the published Trust Services Criteria. A SOC 1 has no fixed criteria list: the control objectives are written for the service. Linford & Company, a CPA firm, describes the work as covering IT general controls (access, change management, computer operations) plus business-process controls such as transaction authorization and reconciliations.
Scope follows the service, not the company. A payroll provider’s scope might cover the applications and procedures that receive pay data, calculate payroll, approve changes, and produce output, along with access to those systems. The auditor does not examine every other activity the company performs.
Who can issue a SOC 1 report?
In the US, a CPA firm. This page describes US practice. The AICPA describes SOC as a suite of service offerings CPAs may provide and says it refers unlicensed firms and practitioners to state boards of accountancy. A software platform, or a readiness consultant that is not a CPA firm, cannot sign the opinion. A SOC 1 is an attestation report, not a certification, and no body certifies a company as “SOC 1.”
Verify five things before you request a proposal:
- License. Confirm that the CPA who will sign holds an active license, and that the firm may issue attest reports in the relevant state. Our CPA licensing guide covers the individual and firm layers.
- Peer review. Ask whether the firm is enrolled in AICPA peer review and what its latest result was. The peer review guide explains how to read it.
- Independence. The service auditor must be independent of you. If the firm or a related company also sells you readiness work, software, or consulting, ask how it evaluates the threats to independence. The AICPA Code of Professional Conduct has specific rules for nonattest services provided to an attest client.
- SOC 1 experience. Ask how many SOC 1 reports the engagement partner has signed and for which kinds of service. A firm that mostly issues SOC 2 reports may still be the right choice, but transaction-processing and reconciliation objectives are different work from security criteria.
- Named team. Ask who will sign the report and who will lead fieldwork.
The same checks apply to a SOC 2 auditor, and how to choose a SOC 2 auditor covers the RFP mechanics. Our auditor directory is a place to start a list, but confirm that each firm issues SOC 1 reports before you ask it for a proposal.
Should you get a Type 1 or a Type 2 SOC 1 report?
Choose the type your customer’s auditor will accept, and set the period to match the customer’s audit calendar. A Type 1 report gives the auditor’s opinion on the description and on whether the controls are suitably designed as of one date. A Type 2 report adds tests of whether the controls operated effectively throughout a stated period. Customers’ auditors usually want Type 2: MGO, a CPA firm, says Type 2 reports generally provide stronger audit evidence and are preferred for financial statement audits.
No universal period applies. Linford describes twelve months as typical, with Type 2 periods ranging from six to eighteen months. What matters is whether the dates cover the customer’s own audit period.
In the chart’s example, the customer’s fiscal year runs twelve months and your Type 2 period covers the first nine. Months nine to twelve have no opinion behind them. A bridge letter can describe that stretch, but Linford notes that it is not a substitute for a report and carries no auditor opinion. MGO tells customers to check that the coverage period aligns with their fiscal year or audit period. Set your period end from your customers’ audit calendars, not the other way around. Our SOC 2 bridge letter guide explains how these letters work, and the idea carries over.
For a first report, a Type 1 is sometimes the right start. Linford says it fixes which controls will be tested later, and that a Type 2 exposes any control that was not run and documented across the whole period. Ask the customer’s auditor whether a Type 1 followed by a Type 2 satisfies them before you commit.
What should the scope brief say?
Write one brief and send it to every firm, so the proposals price the same examination. Start by asking the customer which process uses your output, what error or unauthorized change could reach its financial statements, and whether its auditor expects a SOC 1 report. That answer gives a better scope than an industry checklist.
| Brief item | Question to answer | Why it matters |
|---|---|---|
| Service boundary | Which legal entity, service, application, location, and period are in scope? | A narrower boundary gives a cheaper but different report. |
| Customer process | Which customer financial-reporting process does the service feed? | The process decides which control objectives the report needs. |
| Control objectives | Which objectives address that process, and who drafts the first version? | There is no fixed list, and management owns the description. |
| Customer-run controls | Which controls must customers operate for yours to work (complementary user entity controls, or CUECs)? | Readers need to know what they still have to do. |
| Subservice organizations | Which vendors perform relevant activities, and does the report include or carve out their controls? | A carved-out vendor’s controls are not tested in your report, so customers may need that vendor’s own evidence. |
| Report type and period | Type 1 or Type 2, which dates, and how do they fit customer audit calendars? | A period that ends early leaves a coverage gap. |
How do you compare SOC 1 proposals?
A narrower boundary or an omitted subservice organization is not an equivalent report, even when the service names look the same. Compare the written answers on scope before you compare price.
| What to compare | A comparable proposal states | Ask again if |
|---|---|---|
| Scope | The service, entities, locations, and subservice organizations, and whether each is included or carved out | It says only “SOC 1 examination” |
| Control objectives | Who drafts them and how they tie to the customer process that prompted the request | The same objectives would fit any client |
| Report type and period | The type, the start and end dates, and how they meet customer audit calendars | Dates are left “to be agreed” |
| People | The CPA who signs, who leads fieldwork, and their SOC 1 history | Only the firm’s name appears |
| Independence | Other services the firm or its affiliates provide to you, and how it handles the threats | Readiness, software, or advisory work is bundled without explanation |
| Evidence | Populations, samples, walkthroughs, exception follow-up, and what you must retain from day one | Testing is described only as “standard” |
| Timeline | Dates for fieldwork, the draft, and the final report | The only claim is speed |
| Fee | Separate prices for Type 1 and Type 2, and what triggers a scope change | The price covers a different boundary from the others |
What does a SOC 1 audit cost, and how long does it take?
We have no observed SOC 1 fee data, so we do not quote a range. Linford lists what firms weigh: company size and the number of people with in-scope access, IT and business-process complexity, use of cloud infrastructure, the number of business-process control objectives, offices and data centers in scope, and Type 1 or Type 2. It calls the number of business-process objectives the factor people underestimate, and says trimming two unneeded process areas in scoping does more for a fee than negotiating.
Timing differs by firm. Linford reports that Type 2 fieldwork commonly takes four to eight weeks, separate from the period under examination. I.S. Partners says a Type 2 report takes about eight to twelve weeks to complete, and longer the first time. Both are firm statements, not benchmarks, so ask each proposal for dates.
How should a customer read a SOC 1 report?
Confirm first that the report covers the service and period you rely on. Linford says SOC 1 reports are restricted-use documents shared under a nondisclosure agreement, so ask your account contact. A vendor that cannot produce one, when its service touches your financial reporting, is giving you a useful signal. MGO lists eight areas to review, which the table folds into the report’s sections.
| Where to look | What to check |
|---|---|
| Service auditor’s report | Whether the opinion is unqualified, qualified, adverse, or disclaimed, and which control objectives any qualification names |
| System description | Whether the described service, systems, and data flow match what you buy, and which subservice organizations are carved out |
| Control objectives and tests | Whether the objectives cover the financial process you rely on, and the nature, timing, and severity of any exceptions |
| Customer-run controls (CUECs) | What you must operate on your side, and whether those controls exist and work |
| Report type and period | Type 1 or Type 2, and whether the dates cover your fiscal year or audit period |
| Information produced by the entity | How the auditor evaluated the completeness and accuracy of the reports the controls depend on |
The report is evidence, not a replacement for your own controls. MGO adds that management must review, evaluate, and document how the report supports its ICFR conclusions. If a customer-run control says you approve transactions or manage access on your side, you still have to do it. If a relevant provider is carved out, you may need separate evidence about that provider.
Does your service need a SOC 1 report at all?
Probably, if your service creates, calculates, or posts transactions, holds or moves customer funds, or produces records customers use to prepare their financial statements, and a customer’s auditor has asked for one. Linford names payroll processors, medical claims processors, loan servicing companies, trust and custody providers, and benefits administrators as common examples. It places software companies on that list only when the platform calculates, records, or moves amounts that land in customers’ financial statements, and says a service that only gives customers read access to data they own probably calls for SOC 2 instead.
The choice between the two reports, and the cases that need both, is covered in SOC 1 vs SOC 2.
More in Auditor Selection