Your Ask Joey ™ Answer

What is a type I service organization control report?

In a type I service organization control (SOC) report, the service auditor will only report on the design and implementation of the service organization’s system of internal controls. There will not be any assessment performed on the operating effectiveness of the internal controls as that is covered in a type II SOC report.

A type I report is not useful for the user auditor as it does not allow the user auditor to reduce their control testing on the user organization.

As a reminder, the visual below illustrates the four parties involved in a SOC type I and type II report:


Back To All Questions

You might also be interested in...

  • What is a service organization control (SOC) report?

    A service organization control report is intended to build trust and confidence for user organizations that rely on service organizations. Basically, a service organization provides services to a user company, and the SOC report is prepared by a firm to make sure that the service organization has proper controls around their processes. There are two...