# What is a SOC 1 Report?

> A System and Organization Controls 1 (SOC 1) report is an independent service-auditor report on controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting.

- Canonical URL: https://yellowcube.eu/glossary/soc-1-report/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It helps customer management and financial-statement auditors understand how outsourced processing may affect financial reporting controls; it is not a general cybersecurity assessment.

Management describes the service and asserts that the description and controls meet the applicable criteria. An independent licensed CPA firm examines that assertion under applicable professional attestation standards. A Type 1 report addresses control design at a specified date; a Type 2 report also addresses operating effectiveness over a specified period.

### Key points

- **Read the scope:** Identify the service, locations, systems, control objectives, reporting period or date, subservice organizations, and method used to include or carve them out.
- **Use the opinion:** Review the auditor’s opinion, tests and results for a Type 2 report, exceptions, management responses, and whether the evidence matches the customer’s financial-reporting risks.
- **Complete the control chain:** Implement complementary user-entity controls and evaluate subservice dependencies; the service organization cannot operate controls assigned to its customers.
- **Important limitation:** A clean SOC 1 opinion is not a security certification and does not cover every system, threat, or customer responsibility. It provides assurance only for the described scope, criteria, date or period, and controls relevant to financial reporting.

### Related terms

[SOC 2 report](<https://yellowcube.eu/glossary/soc-2-report/>) · [Security audit](<https://yellowcube.eu/glossary/security-audit/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Compensating control](<https://yellowcube.eu/glossary/compensating-control/>) · [Sarbanes–Oxley Act (SOX) cybersecurity](<https://yellowcube.eu/glossary/sarbanes-oxley-act-cybersecurity/>) · [SOC 3 report](<https://yellowcube.eu/glossary/soc-3-report/>)

### Sources

[AICPA & CIMA, SOC 1—SOC for Service Organizations: ICFR](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-1) · [AICPA & CIMA, System and Organization Controls: SOC Suite of Services](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

