Please do not leave this page until complete. This can take a few moments.
For the small business owner that regularly deals with the data of outside parties, there's a risk in sensitive data getting into the wrong hands.
Maybe you’re involved in providing payroll services to companies. Maybe a cloud-based storage system or a customer service platform. If you’re engaged in any of these activities, you may want to think about preparing a SOC report with a trusted adviser. SOC reports, in short, help companies vet and understand the safeguards in place when they outsource business (and sensitive data) to outside vendors.
If your business has ever been through an audit, you’ve likely been asked for System and Organization Controls, or SOC, reports. While these reports have been around in some form for quite a while, it’s not unusual (and I assure you it’s OK) for mention of it to give you a feeling of mild to significant confusion.
SOC reports are internal control reports about the services provided by an outsourced company that provide valuable information about the potential risks of that organization. For example, a SOC report about a cloud-based storage service would provide information about the processes in place to safeguard user data within that system.
Essentially, a SOC report gives assurance to customers that use an outsourced system and business partners that an organization’s controls over the system are suitably designed to achieve the objectives and commitments related to the use of the system.
While SOC reports have become most common in industries like technology, claims processors and finance, we’ve also seen them benefit various cloud providers, service organizations, data analysts, and much more.
There are a few different kinds of SOC reports, but the two most commonly required are:
Most SOC reports will contain the following components:
The auditor’s opinion. The core part of a SOC report is what’s known as the Service Auditors’ Report. This portion of the report documents an auditor’s opinion about the quality of the service organization’s controls over the system. This opinion includes an assessment of the suitability of the control design the service provider has in place. This essentially means determining if the control will likely achieve what it is intended to do.
The results of an independent auditor’s testing will also be contained within a SOC report, including a description of the controls implemented by the service organization and the corresponding tests performed by the auditor to check the effectiveness of controls.
Deviations during testing. The auditor will also include any exceptions that are identified during testing, such as when a system control did not operate effectively. For the benefit of the report user, a SOC report will include a description of the exceptions and can include a note from management to provide what they will do about it.
A word from management. Another key component of SOC reports is what’s known as management assertions. This is additional information about the functions performed by the service provider and the criteria management has used in establishing its control objectives and service commitments.
Trust as a two-way street. SOC reports also contain information about the controls that the service organization assumes will be implemented by user entities to ensure control objectives will be met.
When dealing with transaction processing, information technology, software, data and other high-sensitivity operations, SOC reports can be a valuable way of understanding the controls that are in place to guard those processes and information. It might sound confusing at first, but SOC reports can help provide clarity and peace of mind about the systems that safeguard important information and business processes.
Patrick Morin is a principal at Baker Newman Noyes and leader of the firm’s information systems and risk assurance practice. He has worked at Baker Newman since 1995 and is based out of its Portland office. He can be reached at PMorin@bnncpa.com.
The Giving Guide helps nonprofits have the opportunity to showcase and differentiate their organizations so that businesses better understand how they can contribute to a nonprofit’s mission and work.
Learn MoreWork for ME is a workforce development tool to help Maine’s employers target Maine’s emerging workforce. Work for ME highlights each industry, its impact on Maine’s economy, the jobs available to entry-level workers, the training and education needed to get a career started.
Learn MoreFew people are adequately prepared for all the tasks involved in planning and providing care for aging family members. SeniorSmart provides an essential road map for navigating the process. This resource guide explores the myriad of care options and offers essential information on topics ranging from self-care to legal and financial preparedness.
Learn moreThe Giving Guide helps nonprofits have the opportunity to showcase and differentiate their organizations so that businesses better understand how they can contribute to a nonprofit’s mission and work.
Work for ME is a workforce development tool to help Maine’s employers target Maine’s emerging workforce. Work for ME highlights each industry, its impact on Maine’s economy, the jobs available to entry-level workers, the training and education needed to get a career started.
Few people are adequately prepared for all the tasks involved in planning and providing care for aging family members. SeniorSmart provides an essential road map for navigating the process. This resource guide explores the myriad of care options and offers essential information on topics ranging from self-care to legal and financial preparedness.
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
In order to use this feature, we need some information from you. You can also login or register for a free account.
By clicking submit you are agreeing to our cookie usage and Privacy Policy
Already have an account? Login
Already have an account? Login
Want to create an account? Register
This website uses cookies to ensure you get the best experience on our website. Our privacy policy
To ensure the best experience on our website, articles cannot be read without allowing cookies. Please allow cookies to continue reading. Our privacy policy
0 Comments