SOC 1
Also known as: SSAE 18 report, ICFR audit report
A SOC 1 report is an audit performed by a CPA firm to evaluate the controls at a service organization that are relevant to their clients' internal control over financial reporting (ICFR). Unlike other SOC reports, it focuses specifically on the financial impact of a provider's services rather than general security or privacy. It provides assurance to users and their auditors that the service provider has appropriate controls in place to prevent material misstatements in financial data.
In practice
An auditor will request a SOC 1 Type II report from a vendor, such as a payroll processor or trust company, to ensure the vendor's internal processes operated effectively over a period of time. The practitioner then verifies that their own organization has implemented the "Complementary User Entity Controls" (CUECs) specified in the report.