CPA TAX COMPLIANCE & PLANNING (TCP) • SYSTEM AND ORGANIZATIONAL CONTROLS ENGAGEMENTS

SOC Reporting and Opinions

Understanding how CPAs evaluate and report on the internal controls of service organizations to build stakeholder trust.

Historical Context & Motivation

As businesses increasingly outsourced critical functions—payroll processing, data hosting, financial transaction handling—to third-party service organizations throughout the late twentieth century, a profound question emerged: how could user entities and their auditors gain assurance that the controls at those service organizations were properly designed and operating effectively? Before the advent of standardized reporting frameworks, user auditors faced the laborious and often impractical task of independently auditing each service organization, a duplication of effort that strained resources across the profession. The SOC (System and Organization Controls) reporting framework arose to solve this exact problem—providing a single, authoritative examination report that multiple stakeholders could rely upon.

1992
SAS 70 Introduced
The AICPA issued Statement on Auditing Standards No. 70, establishing the first formal standard for reporting on controls at service organizations. SAS 70 created Type I and Type II reports focused on financial reporting controls.
2006
Trust Services Principles Developed
The AICPA and CICA jointly developed the Trust Services Principles and Criteria—Security, Availability, Processing Integrity, Confidentiality, and Privacy—laying the groundwork for non-financial SOC reports.
2011
SOC 1, SOC 2, and SOC 3 Framework Launched
The AICPA replaced SAS 70 with SSAE 16 and introduced the SOC suite of reports. SOC 1 addressed internal controls over financial reporting (ICFR), while SOC 2 and SOC 3 addressed the Trust Services Criteria.
2017
SSAE 18 and Revised Trust Services Criteria
SSAE 18 (AT-C Section 320) superseded SSAE 16, tightening requirements around complementary subservice organization controls and monitoring. The Trust Services Criteria were revised to align with the 2013 COSO Internal Control framework.
2020–Present
SOC for Cybersecurity and Supply Chain
The AICPA expanded the SOC family to include SOC for Cybersecurity and SOC for Supply Chain, reflecting the growing importance of enterprise-wide risk management and third-party ecosystem assurance in a digital economy.

The evolution from SAS 70 to the modern SOC framework reflects a broader transformation in how assurance engagements are conceived. The core question the SOC framework addresses is deceptively simple: Can stakeholders trust that a service organization's controls are suitably designed and operating effectively over a defined period? The practitioner's opinion—whether unqualified, qualified, adverse, or a disclaimer—communicates the answer and forms the centerpiece of every SOC report.

Core Principles & Definitions

Before diving into the mechanics of SOC reporting, it is essential to establish the foundational concepts that underpin every engagement. A service organization is any entity that provides services to user entities where those services are likely to be relevant to the user entities' internal controls over financial reporting or other operational domains. A user entity is the organization that engages the service organization—for instance, a company that outsources its payroll to ADP. The service auditor (the CPA practitioner) examines and reports on the controls at the service organization, issuing an opinion that user entities and their own auditors can rely upon.

1

Management's Description

The service organization's management prepares a written description of its system, including the types of services provided, the boundaries of the system, and the controls in place. The service auditor evaluates whether this description is fairly presented.
2

Suitability of Design

The auditor assesses whether the controls, as described, are suitably designed to meet the applicable control objectives (SOC 1) or trust services criteria (SOC 2). Design evaluation asks: 'If these controls work as intended, would they achieve the stated objectives?'
3

Operating Effectiveness

For Type II reports only, the auditor tests whether controls operated effectively throughout a specified reporting period (typically 6–12 months). This goes beyond design to ask: 'Did the controls actually function as designed over time?'
4

Control Objectives vs. Trust Services Criteria

SOC 1 reports evaluate controls against control objectives related to financial reporting. SOC 2 reports evaluate controls against the Trust Services Criteria: Security (always included), Availability, Processing Integrity, Confidentiality, and Privacy.
5

Types of Opinions

The service auditor issues one of four opinion types: unqualified (clean), qualified (exception noted but limited), adverse (pervasive deficiencies), or disclaimer (insufficient evidence to form an opinion). These mirror financial audit opinion categories.
KEY TAKEAWAY
Think of a SOC report like a home inspection report when purchasing real estate. The buyer (user entity) cannot practically tear apart every wall and pipe themselves, so they hire an independent inspector (service auditor) who evaluates whether the home's systems (controls) are properly built (suitability of design) and actually working (operating effectiveness). The inspector's final opinion tells the buyer whether to proceed with confidence, negotiate repairs, or walk away entirely—just as a SOC opinion guides stakeholders' trust in a service organization.

Visual Explanation — The SOC Reporting Ecosystem

This diagram illustrates the three primary stakeholders in the SOC reporting ecosystem—the service organization that operates the controls, the service auditor (CPA) who examines and opines on those controls, and the user entity that relies on the resulting report. Below, the three SOC report types are differentiated by their criteria, governing standards, and intended audience. The Type I versus Type II distinction at the bottom highlights whether the examination addresses a single point in time or a period of operating effectiveness.

As the diagram makes clear, the SOC reporting process involves a tripartite relationship. The service organization prepares a description of its system—covering the nature of services, principal service commitments, system components (infrastructure, software, people, procedures, and data), and control objectives or criteria. The service auditor then evaluates this description for fair presentation, assesses the suitability of control design, and—for Type II engagements—tests operating effectiveness over a specified period. The resulting SOC report, containing the auditor's opinion, management's assertion, the system description, and (for Type II) test results, is then distributed to user entities and their auditors to support their own risk assessments and audit planning. The opinion section is the most critical component, as it communicates the practitioner's professional judgment about the reliability of the service organization's controls.

How SOC Opinions Are Formed

Unlike a financial statement audit where the auditor evaluates whether account balances are materially misstated, a SOC engagement evaluates whether management's description is fairly presented, whether controls are suitably designed, and—for Type II—whether controls operated effectively. The opinion formation process is systematic, following a structured engagement workflow governed by professional standards. Understanding this workflow is essential for CPA candidates because the opinion's language and scope vary depending on the specific findings and the nature of any identified deviations.

The Three Pillars of a SOC Opinion

Every SOC 1 and SOC 2 opinion addresses three distinct assertions. First, the auditor opines on whether management's description of the service organization's system is fairly presented in all material respects. Second, the auditor evaluates whether the controls stated in the description were suitably designed to provide reasonable assurance that the control objectives (SOC 1) or trust services criteria (SOC 2) would be achieved if the controls operated effectively. Third, for a Type II report, the auditor opines on whether the controls operated effectively throughout the specified period.

Opinion Categories and Their Triggers

Summary of SOC opinion types and the conditions that trigger each
Opinion TypeConditionKey Language
Unqualified (Clean)Description is fairly presented, controls are suitably designed, and (Type II) controls operated effectively. No material exceptions."In our opinion, in all material respects…the controls were suitably designed and operating effectively."
QualifiedOne or more control deviations or misrepresentations are identified but are not pervasive. The exceptions are isolated and do not undermine the overall system."Except for [specific deviation]…the controls were suitably designed and operating effectively."
AdverseControl deficiencies or description misrepresentations are pervasive, material, and fundamentally undermine the system's ability to meet control objectives or criteria."In our opinion…the controls were NOT suitably designed [or operating effectively] in all material respects."
DisclaimerThe auditor is unable to obtain sufficient appropriate evidence to form an opinion—scope limitations are too significant to overcome."We do not express an opinion on…because we were unable to obtain sufficient appropriate evidence."
⚠️ Materiality in SOC Engagements
Unlike financial statement audits where materiality is typically quantified as a dollar threshold, materiality in SOC engagements is evaluated qualitatively. A control deviation is material if it could reasonably affect the decisions of the intended users of the report. For SOC 1, this relates to the potential impact on user entities' financial statements. For SOC 2, materiality is assessed against the trust services criteria—a security breach affecting all user entities, for example, would almost certainly be material.

Detailed Breakdown — SOC Report Components

A SOC report is a comprehensive document, and understanding its structure is critical for CPA candidates who must know not only what the opinion says but where it fits within the broader report. Each section of the report serves a distinct purpose and is prepared by a specific party—either management or the service auditor. The interplay between these sections provides the layered assurance that makes SOC reports valuable. Below, we break down the five core components of a SOC 2 Type II report—the most comprehensive and commonly examined variant.

This diagram presents the five sections of a SOC 2 Type II report in sequential order. Sections I (the opinion) and IV (test results) are the service auditor's responsibility, while Sections II (management's assertion), III (system description), and V (other information) are prepared by the service organization's management. Note that the auditor's opinion in Section I does not cover Section V.

Complementary Controls: CUECs and CSOCs

A crucial concept embedded within the system description is the identification of Complementary User Entity Controls (CUECs) and Complementary Subservice Organization Controls (CSOCs). CUECs are controls that the service organization assumes are in place at the user entity. For example, if a cloud hosting provider's security controls assume that user entities maintain strong password policies for their own employees' accounts, that password policy requirement is a CUEC. CSOCs operate similarly but apply when the service organization itself outsources components to a subservice organization—such as a data center provider. In the inclusive method, the subservice organization's controls are included in the scope of the examination and the service auditor's opinion. In the carve-out method, the subservice organization's controls are excluded from the scope, and management's description identifies the functions performed by the subservice organization without including its controls.

Worked Example — Determining the Appropriate SOC Opinion

Consider the following scenario: CloudPayPro, Inc. is a cloud-based payroll processing service organization that handles payroll for over 500 user entities. An independent CPA firm, Anderson & Associates, has been engaged to perform a SOC 1 Type II examination for the period January 1 through December 31, 2024. During the examination, the service auditor identifies several findings. Let us walk through the process of determining what opinion should be issued.

Scenario: CloudPayPro SOC 1 Type II Examination
1
Step 1 — Evaluate Management's DescriptionThe auditor reviews CloudPayPro's description of its payroll processing system. The description covers the system's boundaries, the five components (infrastructure, software, people, procedures, and data), the control objectives, and identified CUECs. The auditor confirms that the description accurately represents the system as it was designed and implemented. Finding: The description is fairly presented in all material respects.
Pillar 1: No exceptions — description is fairly presented.
2
Step 2 — Assess Suitability of DesignThe auditor evaluates whether each control, as described, is suitably designed to achieve the related control objectives. For example, Control Objective 3 requires that payroll calculations be accurate. CloudPayPro has designed automated calculation routines with built-in validation checks and supervisory review of exceptions. The auditor determines that, if operating as described, these controls would provide reasonable assurance of accurate payroll calculations. All 12 control objectives have appropriately designed controls. Finding: Controls are suitably designed for all control objectives.
Pillar 2: No exceptions — controls are suitably designed.
3
Step 3 — Test Operating EffectivenessThe auditor performs tests of operating effectiveness across the 12-month period—selecting samples of transactions, observing processes, inspecting documentation, and re-performing control procedures. Testing reveals that 11 of the 12 control objectives were met throughout the period. However, for Control Objective 7 (timely backup of payroll data), the auditor discovers that automated backups failed for a three-week period in August due to a storage configuration error, and management did not detect the failure until the monthly monitoring review. During this gap, 42 daily backups were missed.
Pillar 3: Exception identified — Control Objective 7 not met for three weeks.
4
Step 4 — Evaluate Materiality and PervasivenessThe auditor must now determine whether this deviation is material and, if so, whether it is pervasive. The three-week backup failure affected a single control objective out of twelve, and it was remediated once detected. No data was actually lost during the period, and other compensating controls (such as real-time replication to a secondary site) mitigated the risk. The auditor concludes that the deviation is material to Control Objective 7 specifically—it represents a meaningful operating effectiveness failure—but it is not pervasive because it does not affect the system's ability to meet the other eleven control objectives.
Assessment: Material but not pervasive — isolated to one control objective.
5
Step 5 — Determine the OpinionBecause the description is fairly presented and the controls are suitably designed, and because the operating effectiveness deviation is material but limited to a single control objective (not pervasive), the auditor issues a qualified opinion. The opinion states: "Except for Control Objective 7 related to timely data backup, in our opinion, in all material respects..." If the backup failure had been pervasive—affecting multiple control objectives or calling into question the reliability of the entire system—an adverse opinion would be warranted. If instead, management had refused to allow the auditor access to backup logs entirely, a disclaimer would be appropriate.
Final Opinion: QUALIFIED — "Except for" language applied to Control Objective 7.

Comparing SOC Report Types — Strengths, Limitations & Use Cases

Selecting the appropriate SOC report type is a critical decision that depends on the intended users, the nature of the controls being evaluated, and the service organization's objectives. While SOC 1, SOC 2, and SOC 3 all involve an examination engagement performed under attestation standards, they differ substantially in scope, criteria, distribution, and level of detail. Understanding these differences is essential for CPA candidates, as exam questions frequently test the ability to match a scenario to the correct report type.

Comparison of SOC 1, SOC 2, and SOC 3 Report Types
DimensionSOC 1SOC 2SOC 3
Governing StandardSSAE 18 (AT-C Section 320)AT-C Section 205AT-C Section 205
Subject MatterControls relevant to user entities' ICFRTrust Services Criteria (Security + optional categories)Trust Services Criteria (same as SOC 2)
Available TypesType I and Type IIType I and Type IIType II only (point-in-time seal)
DistributionRestricted: management, user entities, and user auditorsRestricted: management, user entities, business partners, and regulatorsGeneral use: publicly available
Level of DetailComprehensive: includes system description, test procedures, and resultsComprehensive: includes system description, test procedures, and resultsSummary: opinion and assertion only, no detailed test results
Primary Use CaseSupporting user entities' financial statement audits (e.g., payroll, loan servicing)Due diligence, vendor management, regulatory compliance (e.g., cloud, SaaS)Marketing, public trust-building (e.g., displaying trust seal on website)
Key LimitationFocused only on ICFR; does not address security, availability, or privacy broadlyRestricted distribution limits marketing value; detailed content is sensitiveLacks detail; cannot be used as a substitute for a full SOC 2 in audits
KEY TAKEAWAY
Think of SOC reports as different levels of credit reports. A SOC 2 Type II is like a full credit report with detailed account histories, payment patterns, and supporting documentation—immensely valuable for an underwriter evaluating a loan application, but too sensitive to post publicly. A SOC 3 is like a credit score summary—a single trust indicator suitable for public display, but insufficient for anyone conducting serious due diligence. A SOC 1, meanwhile, is like a specialized financial audit of a single business line, narrowly targeted to the needs of financial statement auditors.

Connection to Advanced Assurance Theory and Emerging Frameworks

SOC reporting does not exist in isolation; it connects to a broader ecosystem of assurance standards and frameworks that are evolving rapidly. Understanding these connections positions CPA candidates to navigate both current practice and emerging requirements. The relationship between SOC engagements and other assurance frameworks reveals how the profession is adapting to digital transformation, supply chain interdependencies, and heightened cybersecurity expectations.

SOC Reporting in the Broader Assurance Landscape
Framework / StandardRelationship to SOC ReportingKey Distinction
COSO 2013 FrameworkThe Trust Services Criteria used in SOC 2 and SOC 3 are mapped directly to the COSO 2013 Internal Control—Integrated Framework's 17 principles across the five components of internal control.COSO is a general internal control framework; SOC applies it specifically to service organization examinations with attestation-level assurance.
ISO 27001ISO 27001 certifications assess information security management systems (ISMS). Organizations often pursue both ISO 27001 and SOC 2 to satisfy different stakeholder demands.ISO 27001 is a certification standard (pass/fail) while SOC 2 provides a detailed examination report with a nuanced opinion. ISO is internationally recognized; SOC is primarily U.S.-centric.
SOC for CybersecurityExtends SOC concepts to an organization's entity-wide cybersecurity risk management program, not just specific services provided to user entities.SOC 2 examines controls for a specific service/system, while SOC for Cybersecurity evaluates the broader organizational cybersecurity posture. SOC for Cybersecurity reports are designed for general use.
SOC for Supply ChainAdapts SOC examination methodology to address controls over the production and distribution of goods, covering risks such as counterfeit materials, quality failures, and supply chain disruptions.While SOC 2 focuses on technology-centric controls, SOC for Supply Chain targets physical manufacturing and distribution processes, reflecting the growing need for supply chain transparency.

Looking ahead, the convergence of SOC reporting with environmental, social, and governance (ESG) assurance is an emerging area of interest. As regulators increasingly require third-party assurance over sustainability disclosures and data governance, the SOC engagement model—with its established framework of management assertions, practitioner examinations, and structured opinions—may serve as a template for new assurance domains. CPA candidates should anticipate that the foundational principles of SOC reporting—fair presentation of management's description, suitability of design, and operating effectiveness—will remain relevant even as the specific criteria and subject matter expand.

Practice Problems

PROBLEM 1CONCEPTUAL
A SaaS company wants to demonstrate to its clients that its data hosting environment meets stringent security, availability, and confidentiality standards. The company's clients need detailed information about specific controls and test results for their own vendor management programs. Which type of SOC report should the company obtain, and why would a SOC 3 report be insufficient for this purpose?
PROBLEM 2BASIC CALCULATION
A service auditor tests a daily automated reconciliation control for operating effectiveness over a 12-month SOC 1 Type II examination period. The control should execute once per business day. Assuming 252 business days in the period, the auditor selects a sample of 60 days for testing and finds that the reconciliation failed to execute on 4 of the sampled days. Calculate the deviation rate in the sample. If the auditor set the tolerable deviation rate at 5%, should this control be reported as an exception?
PROBLEM 3INTERMEDIATE
DataVault Corp. provides cloud storage services and uses a third-party data center operator, SecureFacility LLC, for its physical infrastructure. DataVault is undergoing a SOC 2 Type II examination. The service auditor must decide between the inclusive method and the carve-out method for addressing SecureFacility's controls. Describe both methods, explain which sections of the SOC report would be affected by the choice, and identify the key factor that should drive the decision.
PROBLEM 4APPLIED
You are the user auditor for MegaRetail Inc., which outsources its payroll processing to PayWorks LLC. PayWorks has provided you with a SOC 1 Type II report for the period July 1, 2023 through June 30, 2024. MegaRetail's fiscal year ends on December 31, 2024. The SOC report contains an unqualified opinion but identifies three CUECs that user entities are expected to have in place. Explain: (a) how you would address the gap between the SOC report period and MegaRetail's fiscal year-end, (b) what procedures you would perform regarding the CUECs, and (c) what additional steps might be needed if the SOC report had contained a qualified opinion.
PROBLEM 5CRITICAL THINKING
Consider a scenario where a service organization receives an adverse SOC 2 opinion due to pervasive deficiencies in its Security controls. The organization's management argues that it has since remediated all deficiencies and requests that the auditor reissue the report with an unqualified opinion reflecting the current state of controls. Evaluate management's request from both a professional standards perspective and a broader assurance theory perspective. What options, if any, does the service organization have to communicate improved controls to its stakeholders?

SOC Reporting and Opinions — Key Concepts Review

SOC reporting provides the assurance framework through which service organizations demonstrate the reliability of their controls to user entities and their auditors. The framework encompasses three report types: SOC 1 (controls relevant to ICFR, governed by SSAE 18), SOC 2 (Trust Services Criteria with restricted distribution), and SOC 3 (summary report for general use). Each report may be issued as a Type I (design as of a date) or Type II (design and operating effectiveness over a period), except SOC 3 which is Type II only.

The service auditor's opinion addresses three pillars: fair presentation of management's description, suitability of design, and operating effectiveness (Type II only). Opinions may be unqualified (clean), qualified (material but not pervasive exceptions), adverse (pervasive deficiencies), or a disclaimer (insufficient evidence). Key concepts include CUECs (controls assumed at user entities), CSOCs (controls at subservice organizations), and the distinction between the inclusive method and carve-out method for addressing subservice organizations. Mastery of these concepts is essential for CPA candidates, as SOC reporting bridges the domains of audit, attestation, tax compliance, and information systems.

Varsity Tutors • CPA Tax Compliance & Planning (TCP) • SOC Reporting and Opinions