Download Presentation - Plante Moran
Download Presentation - Plante Moran
Download Presentation - Plante Moran
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
SOC – Types of Engagements<br />
Regardless of whether a SOC 1 or 2 is chosen, there are two types of SOC<br />
examinations. A Type I examination provides assurance over the design of controls<br />
and a Type II examination provides assurance over the design of controls and their<br />
operating effectiveness. SOC 3 examinations provide assurance over both the design<br />
of controls and their operating effectiveness (i.e., Type II).<br />
Type I<br />
Coverage A Type I report examines the suitability of the<br />
design of controls in meeting specified control<br />
objectives or the applicable trust services<br />
criteria, as of a specified date (e.g. June 30).<br />
Control Design An opinion is given on (1) the fairness of the<br />
presentation of management’s description of<br />
its system, and (2) the suitability of the design<br />
of controls in meeting the specified control<br />
objectives (SOC 1) or trust services criteria<br />
(SOC 2 and 3).<br />
Type II<br />
A Type II report examines the suitability of the<br />
design of controls, and the operating<br />
effectiveness of the controls over a specified<br />
period (e.g. January 1 to June 30).<br />
An opinion is given on (1) the fairness of the<br />
presentation of management’s description of<br />
its system, and (2) the suitability of the design<br />
of controls in meeting the specified control<br />
objectives (SOC 1) or trust services criteria<br />
(SOC 2 and 3) during the period specified.<br />
Control<br />
Effectiveness<br />
N/A<br />
An opinion is given on the (3) operating<br />
effectiveness of the controls in meeting the<br />
specified control objectives (SOC 1) or trust<br />
services criteria (SOC 2 and 3) during the<br />
period specified.<br />
11