SOC 1 Examinations

Delivering SOC Reports With IT, Internal Audit, And External Audit Expertise

SOC 1 examinations evaluate your organization’s operational processes and IT controls. The reports are specifically designed to meet the needs of entities that use service organizations and their external auditors as they evaluate the effect of the controls at the service organization on user entities’ financial statements. Use of these reports is restricted to the management team of the service organization, user entities and user auditors.

Examples of Service Organizations that Benefit from SOC 1 Engagements:

  • Application Service Providers
  • Back Office Services
  • Claims Processing and Healthcare Benefits Administration
  • Collection Services
  • Data Centers or Data Processing Service Bureaus
  • Expense Management and Bill Processing
  • Facilities Maintenance and Vendor Management
  • Inventory Management/Logistics/Reverse Logistics Services
  • Investment Management Services / Retirement Plan Administration
  • Mortgage, Title, Closing and Appraisal Services
  • Payroll Processing Services
  • Third-Party Administrators
  • Web or Cloud Hosting Services

What Type of SOC 1 Engagement is Right for You?

Readiness Assessment – Readiness Assessments are non-attest consulting engagements designed to identify control gaps and advise the service organization of necessary corrective actions in preparation for a successful SOC examination. We work closely with service organizations to ensure mutual agreement on the control objectives and risks significant to user organizations.

SOC 1 Type 1 – Evaluate the fairness of the presentation of the service organization’s system description and the suitability of the design of the controls in meeting the related control objectives as of a specific date. SOC 1 Type 1 may benefit organizations that have never completed an examination, since it assesses the design of controls at a specified date.

SOC 1 Type 2 – Evaluate the fairness of the presentation of the service organization’s system description and the suitability of the design and operating effectiveness of the controls in meeting the related control objectives over a specified period. The SOC 1 Type 2 examination is recommended for those who have completed a readiness assessment or a Type 1 examination, as it evaluates both the design and operating effectiveness of controls over time.

Insights for Specific Risk Areas

We also provide SOC 3 examinations and other specialized reports, such as SOC for Cybersecurity and SOC for Supply Chain, to address the risk areas most important to you and your organization.

Not sure if your organization needs a SOC examination? Download our SOC service overview or take our SOC assessment quiz to find out.

Ready to Get Started Contact us for more information on our SOC solutions and capabilities.

Big Thinking. Personal Focus.

Recognized for our deep SOC experience and established service model, we are leaders in the field and sought-after speakers on SOC reporting requirements both regionally and nationally. Key benefits of working with Schneider Downs include:

  • Client-first approach to drive maximum value for you and your customers
  • Collaborative working style to ensure knowledge transfer between our clients and team
  • Incorporation of Schneider Downs’ professionals based on the subject matter expertise required for each engagement
  • IT leaders experienced in system controls (e.g., SOX, NIST, CMMC, COBIT, PCI DSS v4.0, CSA Star, HIPAA, HITRUST, and ISO 27001)
  • Leaders with global project management expertise
  • Registered as a firm with the AICPA and subject to peer review requirements
  • Member of the AICPA Enhanced Oversight Committee for SOC reports
  • Well-versed in reporting on controls at service organizations

SOC Services

SOC Resources

Visit our SOC Resource Library for helpful thought leadership, including case studies and FAQs.

About Schneider Downs SOC Services

Schneider Downs employs a distinctive approach to SOC reports by blending the expertise of IT, internal audit, and external audit professionals. Our integration of diverse knowledge and project management skills ensures we meet and exceed our clients’ expectations. To ensure our SOC reports meet your needs, we employ a rigorous Quality Control system and have peer reviews completed by external assessors on a regular basis. To explore how we can support your organization, please contact us to get started.

Learn how we’ve Solved Big Problems For our clients

Big Problem: Company Impacted By Ransomware.

Big Thinking: Restore System On-site And Avoid Six-figure Ransom.

Read Case Study

Big Problem: Inefficient Tax Credit Realization.

Big Thinking: Identified A $900,000 Tax Credit, Nearly Twice As Much As Prior Years.

Read Case Study

OUR THOUGHTS ON

Have a question? Ask us!

We’d love to hear from you. Drop us a note, and we’ll respond to you as quickly as possible.

Breached?

Every moment counts. For urgent requests, contact the Schneider Downs digital forensics and incident response team at 1-800-993-8937. For all other requests, please complete the form below.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.