CPA AUDITING & ATTESTATION (AUD) • ASSESSING RISK AND DEVELOPING A PLANNED RESPONSE

Service Organizations — Use SOC 1 Reports In Audit Planning

Understanding how auditors leverage SOC 1 reports to assess risks at outsourced service providers during financial statement audits.

Historical Context & Motivation

As businesses increasingly outsource critical functions such as payroll processing, investment custody, and claims administration, auditors face a fundamental challenge: how do you assess internal controls over financial reporting when those controls reside outside your client's organization? This question has driven the evolution of professional standards governing service organization reporting for decades. Before formalized reporting frameworks existed, user auditors—those auditing the entity that outsources—had limited options for obtaining evidence about the controls maintained by a service organization. They could attempt to visit the service organization directly, rely on vague management representations, or simply accept the gap in audit coverage, none of which constituted sufficient appropriate audit evidence under professional standards.

The American Institute of Certified Public Accountants (AICPA) recognized this gap early on and issued guidance—first through SAS No. 70 (Statement on Auditing Standards No. 70) in 1992—that created a structured framework for reporting on controls at service organizations. Over time, this guidance matured into the current SOC (System and Organization Controls) reporting suite, with SOC 1 reports specifically addressing controls relevant to user entities' financial reporting. The development of these standards paralleled the explosive growth of outsourcing in financial services, healthcare, technology, and virtually every other industry.

1992
SAS No. 70 Issued
The AICPA published SAS No. 70, establishing the first authoritative framework for service auditor reports. This standard introduced the concept of Type I (design of controls at a point in time) and Type II (design and operating effectiveness over a period) reports.
2006
AU Section 324 Update
The AICPA revised guidance to provide clearer direction on how user auditors should evaluate and use SAS 70 reports in their audit planning, refining responsibilities between user entities, service organizations, and their respective auditors.
2011
SOC Framework Replaces SAS 70
The AICPA replaced SAS No. 70 with SSAE 16 (Statement on Standards for Attestation Engagements No. 16) and introduced three SOC report types: SOC 1 for financial reporting controls, SOC 2 for trust service criteria, and SOC 3 for general-use trust service reports.
2017
SSAE 18 Takes Effect
SSAE 18 (now codified in AT-C Section 320) superseded SSAE 16, strengthening requirements around complementary user entity controls (CUECs) and subservice organizations, bringing service organization reporting closer to modern risk assessment frameworks.
2022+
Cloud & Fintech Expansion
With the explosive growth of cloud computing, fintech platforms, and software-as-a-service (SaaS) providers, SOC 1 reports have become indispensable to virtually every financial statement audit where significant transaction processing is outsourced.

The central question this lesson addresses is: once a user auditor identifies that a client relies on a service organization for processes affecting financial statements, how should the auditor obtain and use a SOC 1 report to plan and execute audit procedures that provide sufficient appropriate evidence about the client's internal controls and the related financial statement assertions?

Core Principles & Definitions

To effectively use SOC 1 reports in audit planning, it is essential to understand several foundational concepts. A service organization is any entity—or segment of an entity—that provides services to a user entity in a manner that is likely relevant to the user entity's internal control over financial reporting (ICFR). The user entity is the audit client that has engaged the service organization, and the user auditor is the auditor of the user entity's financial statements. The service auditor is the independent CPA engaged by the service organization to examine and report on its controls. Understanding how these parties interact is fundamental to grasping the flow of assurance in a SOC 1 engagement.

1

SOC 1 Type I Report

Reports on the description and design of controls at a service organization as of a specific date. It confirms that controls are suitably designed but does NOT test whether they operated effectively over time.
2

SOC 1 Type II Report

Reports on the description and design of controls AND tests operating effectiveness over a specified period (typically six to twelve months). This report is far more useful for user auditors conducting financial statement audits.
3

Complementary User Entity Controls (CUECs)

Controls that the service organization's system design assumes the user entity will implement. For example, the service org processes payroll, but expects the user entity to authorize pay rates. The user auditor must verify these are in place.
4

Subservice Organizations

Service organizations may themselves outsource functions to a subservice organization. SOC 1 reports use either the inclusive method (includes subservice controls) or the carve-out method (excludes them, requiring separate consideration).
5

Control Objectives

The SOC 1 report describes control objectives that link to the service organization's processes. These objectives (e.g., 'transactions are authorized and recorded accurately') relate directly to financial statement assertions such as completeness, accuracy, and valuation.
KEY TAKEAWAY
Think of a SOC 1 report as an independent home inspection report when you are buying a property managed by a third party. You (the user auditor) cannot live in the house 24/7 to verify the foundation, plumbing, and wiring (the service organization's controls). Instead, a qualified inspector (the service auditor) examines the property and delivers a detailed report. A Type I report tells you the house appears well-built on the day of inspection; a Type II report tells you the systems functioned properly over the past year. You still need to verify that you've been maintaining the thermostat and changing the filters (CUECs), because the inspector's report assumed you would.

Visual Explanation — The SOC 1 Assurance Flow

The following diagram illustrates the flow of assurance from the service organization's controls through the SOC 1 report to the user auditor's risk assessment. Understanding this chain of evidence is critical because the user auditor does not directly test the service organization's controls; instead, the auditor relies on the service auditor's work, supplemented by an evaluation of complementary user entity controls and any additional procedures deemed necessary.

The diagram traces the assurance chain from the service organization (which maintains controls) through the service auditor (who issues the SOC 1 report) to the user auditor, who performs four sequential evaluation steps: evaluate the report, map controls to assertions, assess gaps, and plan the audit response.

Several features of this diagram warrant close attention. First, notice that the user auditor does not directly audit the service organization's controls. The assurance flows indirectly through the service auditor's report—a form of audit evidence obtained from a third party. Second, the dashed line from the SOC 1 report to the user auditor emphasizes that the report is used as part of the user auditor's overall risk assessment, not as a substitute for the auditor's own professional judgment. Third, the four bottom-row boxes show that reading the SOC 1 report is only the beginning; the user auditor must actively evaluate, map, identify gaps, and design responsive audit procedures.

How the User Auditor Evaluates a SOC 1 Report

When the user auditor obtains a SOC 1 report, the evaluation process is governed by AU-C Section 402 (Audit Considerations Relating to an Entity Using a Service Organization). Although this is not a mathematical framework in the traditional sense, there is a structured decision process that mirrors a risk model. The user auditor essentially walks through a series of evaluations to determine how much reliance can be placed on the SOC 1 report and what residual risk remains that requires additional procedures.

Step A — Assess the Service Auditor's Competence and Independence

The user auditor must evaluate whether the service auditor possesses adequate professional competence and independence. While the user auditor does not re-perform the service auditor's work, they should consider whether the service auditor is a CPA subject to the same professional standards, whether the report follows the appropriate SSAE (now AT-C Section 320), and whether the opinion is unqualified or modified. A qualified or adverse service auditor's opinion is a significant red flag that may require the user auditor to perform alternative procedures.

Step B — Evaluate Report Period Coverage

A critical consideration is whether the period covered by the SOC 1 Type II report aligns with the user entity's fiscal year. For instance, if the client's fiscal year ends December 31 but the SOC 1 report covers only January 1 through September 30, a three-month gap period exists. The user auditor must decide what additional procedures—sometimes called bridge procedures—are necessary to cover this gap. Bridge procedures may include inquiries of management, monitoring activities performed by the user entity, or obtaining a bridge letter from the service organization.

Step C — Identify and Test CUECs

Every SOC 1 report lists complementary user entity controls (CUECs) that the service organization assumes the user entity has in place. For example, a payroll service provider may assume the user entity independently verifies employee headcount before authorizing payroll runs. If the user entity has not implemented these controls, the control environment is incomplete, and the auditor cannot rely on the SOC 1 report for the relevant control objectives. The user auditor must test the design and operating effectiveness of each identified CUEC.

Step D — Address Exceptions and Modifications

A Type II report includes the service auditor's description of tests performed and the results of those tests. The user auditor must carefully review any exceptions or deviations noted by the service auditor. An exception does not automatically preclude reliance on the control; the user auditor must assess the nature, severity, and frequency of exceptions to determine their impact on the assessed risk of material misstatement. Where exceptions are significant, the user auditor designs additional substantive procedures to address the residual risk.

⚠️ Important Distinction
The user auditor should not reference the SOC 1 report or the service auditor in their own audit report. Doing so would constitute an inappropriate division of responsibility. The user auditor bears full responsibility for the audit opinion, even when relying on the service auditor's work as evidence.

Detailed Breakdown — SOC 1 vs. SOC 2 vs. SOC 3 & Report Components

While this lesson focuses on SOC 1 reports, it is valuable to understand how SOC 1 fits within the broader SOC reporting framework so that auditors select the correct report for their needs. The distinguishing factor is the subject matter of the examination and the intended audience. SOC 1 reports are specifically designed for controls relevant to user entities' financial reporting—making them the primary tool for CPA auditors conducting financial statement audits.

Comparison of SOC Report Types
AttributeSOC 1SOC 2SOC 3
StandardsAT-C §320 (SSAE 18)AT-C §205 / TSP §100AT-C §205 / TSP §100
FocusControls relevant to user entities' ICFRTrust service criteria (security, availability, processing integrity, confidentiality, privacy)Same as SOC 2 but summarized
Report TypesType I and Type IIType I and Type IIGeneral-use only (no Type I/II)
Intended UsersUser entities' management and their auditors (restricted use)Specified parties (restricted use)General public (unrestricted)
Used by User Auditor for F/S Audit?Yes — primary toolGenerally no — addresses IT controls beyond ICFRNo — insufficient detail
The five sections of a SOC 1 Type II report are shown in sequence. For the user auditor, Section I (the opinion) and Section IV (tests and results) are the most critical components. Section III (system description) is essential for understanding what is and is not within the scope of the report.

The user auditor should pay particular attention to how the service organization handles subservice organizations. Under the inclusive method, the subservice organization's controls are included within the SOC 1 report's scope, and the service auditor tests them. Under the carve-out method, the subservice organization is explicitly excluded from the scope. When the carve-out method is used, the user auditor must determine whether controls at the carved-out subservice organization are relevant to the audit and, if so, obtain a separate SOC 1 report or perform alternative procedures to obtain evidence about those controls.

Worked Example — Using a SOC 1 Report in an Audit Engagement

Consider the following scenario: You are the user auditor for Greenfield Manufacturing, Inc., a mid-sized company with a December 31 fiscal year-end. Greenfield outsources all payroll processing to PayMax Services. PayMax provides a SOC 1 Type II report covering the period January 1 through October 31. The report was issued by a reputable CPA firm and contains an unqualified opinion. However, Section IV notes two exceptions: (1) one instance where payroll files were processed without supervisory approval, and (2) three instances where access-rights reviews were not completed on schedule. The report identifies three CUECs: (a) user entity authorizes all pay-rate changes before submission, (b) user entity reconciles payroll register to its general ledger monthly, and (c) user entity restricts access to the payroll submission portal to authorized personnel. PayMax uses a carved-out data hosting subservice organization, CloudVault Inc.

Evaluating the PayMax SOC 1 Type II Report
1
Step 1 — Assess the Service AuditorConfirm that the service auditor is a licensed CPA firm subject to peer review and professional standards (AT-C §320). In this case, the firm is reputable and the report follows SSAE 18 standards. The opinion is unqualified, indicating the service auditor concluded that PayMax's description is fairly presented, controls are suitably designed, and they operated effectively over the specified period.
Service auditor deemed competent and independent; unqualified opinion.
2
Step 2 — Evaluate Period Coverage and Identify GapGreenfield's fiscal year ends December 31, but the SOC 1 report covers only through October 31. This creates a two-month gap period (November 1 – December 31). To address this gap, the user auditor should consider: (1) inquiring of Greenfield management about any changes in PayMax's controls during November–December, (2) requesting a bridge letter from PayMax confirming no significant changes to controls, (3) reviewing any monitoring activities Greenfield performs over PayMax during the gap period, and (4) performing additional substantive tests of payroll transactions processed during November and December.
Two-month gap identified; bridge procedures planned for November–December.
3
Step 3 — Evaluate Exceptions in Section IVException 1 (payroll processed without supervisory approval): This occurred once during the ten-month period. The user auditor should assess whether this was an isolated incident or indicative of a systemic weakness. Given it is a single occurrence, it may be considered a minor deviation, but the user auditor should test whether the unapproved payroll run resulted in any errors in Greenfield's records. Exception 2 (three late access-rights reviews): This relates to logical access controls. While not directly a transaction processing control, delayed access reviews increase the risk of unauthorized access. The user auditor should consider whether additional tests of Greenfield's reconciliation controls (a CUEC) provide compensating assurance.
Exceptions assessed as low-to-moderate risk; additional targeted substantive testing designed.
4
Step 4 — Test Complementary User Entity ControlsThe user auditor must verify that Greenfield has implemented all three CUECs. (a) Test whether Greenfield's HR department independently authorizes pay-rate changes by examining a sample of change forms and verifying they were approved before submission to PayMax. (b) Select a sample of months and verify that Greenfield's accounting team reconciled the payroll register to the general ledger. (c) Obtain a list of users with access to the PayMax portal and verify it matches authorized personnel per Greenfield's access policy.
All three CUECs confirmed as designed and operating effectively at Greenfield.
5
Step 5 — Address the Carved-Out Subservice OrganizationCloudVault Inc. was carved out of the SOC 1 report. The user auditor must determine whether CloudVault's data hosting services are relevant to Greenfield's financial reporting. Since CloudVault stores payroll data and transaction records, its controls over data integrity and availability are relevant. The user auditor should attempt to obtain CloudVault's own SOC 1 or SOC 2 report. If unavailable, alternative procedures such as direct inquiry or additional substantive testing of payroll data accuracy should be performed.
CloudVault SOC 2 Type II obtained; no material exceptions noted. Residual risk adequately addressed.
6
Step 6 — Formulate Overall Audit ResponseBased on the evaluation, the user auditor concludes: (1) reliance on the SOC 1 report is appropriate for the period January–October, (2) bridge procedures and targeted substantive testing cover November–December, (3) exceptions are mitigated by compensating controls and additional testing, (4) CUECs at Greenfield are operating effectively, and (5) the carved-out subservice organization has been independently addressed. The auditor documents this assessment in the working papers and adjusts the nature, timing, and extent of further audit procedures accordingly.
Planned audit response documented: moderate reliance on SOC 1 with supplemental substantive procedures.

Strengths and Limitations of SOC 1 Reports in Audit Planning

SOC 1 reports are an immensely valuable tool in the user auditor's arsenal, but they are not without limitations. Effective audit planning requires a clear-eyed understanding of both what the report can provide and where it falls short. The following table contrasts the key strengths and limitations that the user auditor should weigh when incorporating SOC 1 evidence into the overall audit strategy.

Strengths vs. Limitations of SOC 1 Reports
StrengthsLimitations
Provides independent, third-party evidence about controls at the service organization—more reliable than management representations alone.The report reflects a historical period; controls may change after the report date, creating gap-period risk.
Type II reports test operating effectiveness, directly supporting the user auditor's assessment of control risk.Exceptions or deviations in the report may not be clearly quantified, requiring professional judgment to evaluate materiality.
Efficient: one service auditor's examination serves hundreds of user auditors, reducing redundant audit effort.Carved-out subservice organizations create coverage gaps that require separate evaluation or alternative procedures.
Clearly identifies CUECs, alerting the user auditor to controls they must test at the user entity.User auditor cannot control scope, timing, or testing methodology—these are determined by the service auditor.
Structured format (AT-C §320) ensures consistency and comparability across different service organizations.A Type I report provides only design assurance—insufficient for testing operating effectiveness, which most audits require.
KEY TAKEAWAY
Think of a SOC 1 Type II report as a rigorous annual safety inspection of a supplier's factory. The inspection report gives you high-quality evidence about whether safety protocols were functioning during the inspection period. But the report cannot guarantee that the factory is still safe the day after the inspectors leave, that a supplier's sub-contractor is also safe, or that your own workers follow safety rules once the product arrives at your facility. The user auditor must supplement the SOC 1 evidence with bridge procedures, CUEC testing, and subservice organization evaluations to build a complete picture of control assurance—much as you would supplement the factory inspection with ongoing monitoring and your own safety checks.

Connection to Advanced Audit Theory — Integrated Audits & Risk Assessment Models

The use of SOC 1 reports in audit planning connects directly to the broader audit risk model (Audit Risk = Inherent Risk × Control Risk × Detection Risk). When a user auditor places reliance on a SOC 1 Type II report—and supplementary procedures confirm that reliance is justified—the assessed control risk for the relevant assertions can be set below maximum. This, in turn, permits the auditor to accept a higher detection risk, which translates into a reduced extent of substantive testing—saving time and audit cost. Conversely, if the SOC 1 report contains significant exceptions or the user entity has not implemented CUECs, control risk remains at maximum, and the auditor must rely entirely on substantive procedures.

SOC 1 in Basic vs. Advanced Audit Contexts
ConceptSOC 1 Report ContextAdvanced / Integrated Audit Context
Control Risk AssessmentSOC 1 Type II with no exceptions → supports assessing control risk below maximum for outsourced processes.In an integrated audit (PCAOB AS 2201), the auditor must issue an opinion on ICFR as a whole, including controls at service organizations that affect financial reporting.
Substantive TestingLower control risk → reduced sample sizes and fewer substantive procedures for assertions covered by service org controls.Auditor may use a dual-purpose testing approach, combining tests of controls with substantive procedures for efficiency.
Multi-Location ScopingSOC 1 used to assess risk at a single service provider; similar analysis needed if multiple service orgs are used.Group audit standards (AU-C §600) require assessing component auditors and service organizations collectively.
IT General Controls (ITGCs)SOC 1 may address ITGCs (access, change management) at the service org; user auditor maps these to IT-dependent controls.PCAOB inspections increasingly focus on auditor evaluation of IT controls at service organizations as part of ICFR audits.

Looking forward, as organizations adopt more complex technology ecosystems—cloud-native architectures, multi-layered SaaS platforms, and AI-driven automation—the number and complexity of subservice organization relationships will increase. Auditors will need to become proficient not only at reading SOC 1 reports but also at understanding SOC 2 reports (for IT security and availability controls), evaluating continuous monitoring tools, and potentially leveraging technology to automate the mapping of control objectives to financial statement assertions. The PCAOB has signaled heightened scrutiny of auditors' evaluation of service organizations, making this area a critical competency for all practicing auditors.

Practice Problems

PROBLEM 1CONCEPTUAL
A user auditor obtains a SOC 1 Type I report from a service organization. Explain why this report, standing alone, is generally insufficient for the user auditor to assess control risk below the maximum for assertions related to the outsourced process. What type of report would be more appropriate, and why?
PROBLEM 2BASIC CALCULATION
A user entity has a December 31 fiscal year-end. The SOC 1 Type II report from its payroll service provider covers January 1 through September 30. Calculate the length of the gap period in months and identify at least two bridge procedures the user auditor might perform to cover this gap.
PROBLEM 3INTERMEDIATE
You are auditing Alpha Corp., which uses BetaPay for payroll processing. The SOC 1 Type II report for BetaPay (covering January 1 – November 30) uses the carve-out method for its data hosting subservice organization, DataSecure LLC. The report lists one CUEC: Alpha Corp. must independently verify employee headcount before each payroll run. Alpha Corp.'s controller tells you they rely entirely on BetaPay's data and do not perform independent verification. How does this information affect your audit plan?
PROBLEM 4APPLIED
During the audit of Redwood Financial Services (fiscal year-end March 31), you obtain a SOC 1 Type II report from an investment custody service organization covering April 1 of the prior year through March 31 of the current year. The report contains an unqualified opinion but identifies five exceptions in access control testing out of 40 items tested (12.5% deviation rate). Two CUECs are identified, both confirmed as operating effectively at Redwood. No subservice organizations are used. Analyze how the exception rate affects your risk assessment and describe what further procedures you would perform.
PROBLEM 5CRITICAL THINKING
A large audit client uses twelve different service organizations for various financial processes (payroll, benefits administration, investment custody, loan servicing, etc.). Nine provide SOC 1 Type II reports, two provide only SOC 1 Type I reports, and one provides no SOC report at all. Discuss how the user auditor should design an integrated audit approach that addresses the varying levels of assurance available. Consider materiality, risk assessment, and the interplay between reliance on SOC 1 reports and substantive testing in your response.

Lesson Summary

When a user entity outsources critical financial processes to a service organization, the user auditor relies on SOC 1 reports—issued under AT-C Section 320 (SSAE 18)—to obtain evidence about controls relevant to internal control over financial reporting. A Type I report addresses control design at a point in time, while a Type II report tests both design and operating effectiveness over a specified period, making it the preferred evidence source for financial statement audits. The user auditor must evaluate the service auditor's competence and independence, verify that the report period aligns with the user entity's fiscal year (addressing any gap period through bridge procedures), and carefully review any exceptions noted in the service auditor's tests.

Equally important, the user auditor must test complementary user entity controls (CUECs) that the service organization's system assumes are in place, and address any carved-out subservice organizations by obtaining separate reports or performing alternative procedures. When the SOC 1 report supports reliance, the auditor can assess control risk below maximum, reducing the extent of substantive testing for the related assertions. When the report reveals significant weaknesses or gaps, the auditor must increase substantive procedures accordingly. Throughout this process, the user auditor retains full responsibility for the audit opinion and should never reference the service auditor in the audit report.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Service Organizations — Use SOC 1 Reports In Audit Planning