It helps customer management and financial-statement auditors understand how outsourced processing may affect financial reporting controls; it is not a general cybersecurity assessment.
Management describes the service and asserts that the description and controls meet the applicable criteria. An independent licensed CPA firm examines that assertion under applicable professional attestation standards. A Type 1 report addresses control design at a specified date; a Type 2 report also addresses operating effectiveness over a specified period.
Key points
Read the scopeIdentify the service, locations, systems, control objectives, reporting period or date, subservice organizations, and method used to include or carve them out.
Use the opinionReview the auditor’s opinion, tests and results for a Type 2 report, exceptions, management responses, and whether the evidence matches the customer’s financial-reporting risks.
Complete the control chainImplement complementary user-entity controls and evaluate subservice dependencies; the service organization cannot operate controls assigned to its customers.
Important limitationA clean SOC 1 opinion is not a security certification and does not cover every system, threat, or customer responsibility. It provides assurance only for the described scope, criteria, date or period, and controls relevant to financial reporting.