SSAE 18 - Attestation Standards (SOC Reporting)
Evidence request list. 67 controls, 67 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
AUP
AUP engagements involve performing specific procedures and reporting findings without providing an opinion or conclusion, with intended users acknowledging procedures are sufficient for their purposes.
- Engagement letter with specific procedures listed
- Acknowledgement from intended users of procedure sufficiency
- Findings report listing each procedure and result
- No expression of opinion or conclusion in report
- User acknowledgement missing from file
- Report inadvertently expresses conclusion
- Procedures vague rather than specific
Acceptance
The practitioner must establish preconditions including suitable and available criteria, sufficient evidence access, and responsible party willingness to provide written representations.
- Pre-engagement evaluation memo documenting preconditions
- Criteria suitability assessment
- Confirmation of evidence access and management cooperation
- Written agreement on terms of engagement
- Preconditions evaluation not documented
- Criteria not measurable or relevant
- Engagement accepted despite scope limitations
Documentation
Documentation must be sufficient to enable an experienced practitioner with no previous connection to the engagement to understand the work performed, evidence obtained, and conclusions reached.
- Work papers with preparer, reviewer, and date stamps
- Index linking work papers to report assertions
- Final file assembly within 60 days of report release
- Retention for minimum five years
- Work papers missing reviewer sign-off
- Cross-references broken or missing
- Late additions to file after lockdown
Ethics
The practitioner must be independent of the responsible party and comply with the AICPA Code of Professional Conduct throughout the engagement period.
- Independence confirmations from all engagement team members
- Threats and safeguards analysis where non-attest services exist
- Ethics training records for engagement team
- Monitoring of independence during engagement period
- Independence assessed only at acceptance not ongoing
- Non-attest services not analysed for self-review threat
- Family member relationships not declared
Evidence
The practitioner must obtain written representations from the responsible party regarding responsibility for the subject matter, completeness of information provided, and other relevant assertions.
- Signed representation letter dated as of report date
- Representations covering responsibility, completeness, disclosure
- Subsequent events representations included
- Refusal to provide representations escalated
- Representations dated significantly before report
- Missing representations for specific risk areas
- Letter signed by inappropriate party
Examination
Examination engagements provide a high level of assurance and require obtaining sufficient appropriate evidence to reduce attestation risk to an acceptably low level, expressed as an opinion.
- Engagement plan documenting risk assessment and procedures
- Sufficient appropriate evidence to support positive opinion
- Work papers showing nature, timing, and extent of procedures
- Opinion letter in form prescribed by AT-C 205
- Procedures designed without documented risk assessment
- Evidence insufficient for reasonable assurance level
- Opinion form not aligned with AT-C 205 illustrations
General Standards
SSAE 18 reorganises attestation standards into a common concepts section (AT-C 105) that applies to all attestation engagements, including examination, review, and agreed-upon procedures.
- Firm methodology referencing AT-C 105 common concepts
- Engagement templates aligned to clarified standards
- Staff training records on SSAE 18 changes from SSAE 16
- Quality manual addressing all attestation service types
- Methodology still references SSAE 16 or SAS 70
- Templates not updated for clarified standards
- Training not refreshed for new staff
Planning
The practitioner must obtain an understanding of the subject matter and assess risks of material misstatement to design responsive procedures.
- Subject matter understanding memo
- Risk assessment linking risks to assertions
- Planning analytics where applicable
- Procedures designed responsive to assessed risks
- Risk assessment is generic template
- No linkage from risks to specific procedures
- Subject matter understanding shallow
The practitioner must consider materiality when planning procedures and evaluating findings, recognising that materiality in attestation may be qualitative as well as quantitative.
- Materiality determination memo
- Quantitative and qualitative factors considered
- Reassessment during the engagement when conditions change
- Documentation of materiality applied to findings evaluation
- Materiality not documented for non-financial subject matter
- Qualitative factors ignored
- No reassessment despite changes
Quality
Firms must implement a system of quality management with engagement-level controls including engagement quality reviews for high-risk engagements such as SOC reports.
- Firm QM 1 system documentation
- Risk assessment of attestation services for EQR triggers
- EQR documentation completed before report release
- Annual internal monitoring inspections
- EQR not performed for SOC engagements
- QM system not updated for new standards
- Monitoring inspections deferred
Reporting
When other information accompanies the subject matter information, the practitioner must read it for material inconsistencies with the attestation subject matter and respond appropriately.
- Documentation of reading other information
- Discussion of inconsistencies with management
- Disclaimer or other-information paragraph where required
- Section V management responses reviewed
- Section V responses not read
- Inconsistencies not raised with management
- No disclaimer paragraph despite extensive other information
When circumstances warrant, the practitioner must modify the standard report through qualification, adverse opinion, or disclaimer, with reasons clearly described.
- Memo documenting circumstances requiring modification
- Modification language consistent with AICPA illustrations
- Basis for modification paragraph with specifics
- Engagement quality review of modification
- Qualification language vague
- Pervasive issues qualified rather than adverse
- Disclaimer used to avoid difficult conclusions
Reports on subject matter intended for specified parties must include a restricted use paragraph identifying intended users and prohibiting general distribution.
- Restricted use paragraph in report
- Identification of intended parties in engagement letter
- Service organisation distribution controls
- Process for handling requests from non-specified parties
- Restricted use paragraph omitted from SOC 1 or SOC 2
- Intended users not identified
- Distribution controls weak at service organisation
Review
Review engagements provide limited assurance through inquiry and analytical procedures, expressed as a conclusion about whether anything has come to attention that the subject matter is materially misstated.
- Review program emphasising inquiry and analytical procedures
- Documentation of unexpected results investigation
- Limited assurance conclusion in report
- Engagement letter specifying review service
- Review conducted as if examination without scope clarity
- Analytical procedures not documented
- Conclusion phrased as opinion rather than limited assurance
SOC 1
AT-C 320 governs SOC 1 engagements over controls at a service organisation relevant to user entity ICFR, requiring written assertion, system description, and (for Type 2) operating effectiveness testing.
- AT-C 320 engagement letter and management assertion
- Description meeting DC section 200 criteria
- Tests of design and (for Type 2) operating effectiveness
- Report following AICPA SOC 1 illustrative format
- Engagement performed under outdated SSAE 16 references
- Description omits required components
- Reports labelled SOC 1 when subject matter is non-ICFR
SOC 1 - Internal Controls over Financial Reporting
The service organization demonstrates a commitment to integrity and ethical values. Management establishes structure, authority, and responsibility, and attracts, develops, and retains competent individuals.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
The service organization identifies risks to the achievement of its objectives and analyzes risks as a basis for determining how the risks should be managed.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
The service organization generates and uses relevant, quality information to support the functioning of internal control. Communication provides the information necessary to carry out responsibilities.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
The service organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
The service organization selects and develops control activities that contribute to the mitigation of risks to the achievement of financial reporting objectives.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
Controls over the completeness, accuracy, timeliness, and authorization of transaction processing on behalf of user entities.
- System description
- Control matrix
- Evidence library
- Auditor report
- Description thin
- Matrix incomplete
- Evidence stale
- Opinion qualified
SOC 2
SOC 2 engagements apply AT-C 205 examination standards to controls relevant to the Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy.
- Selection of trust services categories with rationale
- Mapping of controls to applicable TSC points of focus
- Description meeting DC section 200 criteria for SOC 2
- Examination report following AICPA SOC 2 illustrative format
- Only security selected when availability is also implied
- Points of focus not addressed in description
- SOC 2 used for ICFR purposes (should be SOC 1)
SOC 2 - Additional Trust Services Categories
The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and enable implementation of additional capacity.
- Availability commitments register
- Environmental and backup control records
- Recovery plan exercise reports
- Capacity planning records
- Commitments unwritten
- Restore tests skipped
- RTO unmet
- Capacity reactive
The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure.
- Availability commitments register
- Environmental and backup control records
- Recovery plan exercise reports
- Capacity planning records
- Commitments unwritten
- Restore tests skipped
- RTO unmet
- Capacity reactive
The entity tests recovery plan procedures supporting system recovery to meet its objectives.
- Availability commitments register
- Environmental and backup control records
- Recovery plan exercise reports
- Capacity planning records
- Commitments unwritten
- Restore tests skipped
- RTO unmet
- Capacity reactive
The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.
- Confidential information inventory
- Encryption and access control records
- Disposal certificates
- Contractual confidentiality terms
- Inventory thin
- Encryption gaps
- Disposal undocumented
- Contracts stale
The entity disposes of confidential information to meet the entity's objectives related to confidentiality.
- Confidential information inventory
- Encryption and access control records
- Disposal certificates
- Contractual confidentiality terms
- Inventory thin
- Encryption gaps
- Disposal undocumented
- Contracts stale
The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy.
- Privacy notice and versioning
- Choice and consent records
- Data subject request logs
- Personal information inventory
- Notice outdated
- Consent not granular
- Requests aging
- Inventory incomplete
The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects.
- Privacy notice and versioning
- Choice and consent records
- Data subject request logs
- Personal information inventory
- Notice outdated
- Consent not granular
- Requests aging
- Inventory incomplete
The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product or service specifications.
- Privacy notice and versioning
- Choice and consent records
- Data subject request logs
- Personal information inventory
- Notice outdated
- Consent not granular
- Requests aging
- Inventory incomplete
The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.
- Privacy notice and versioning
- Choice and consent records
- Data subject request logs
- Personal information inventory
- Notice outdated
- Consent not granular
- Requests aging
- Inventory incomplete
The entity implements policies and procedures over system inputs, including controls over completeness, accuracy, and timeliness of inputs and error handling.
- Privacy notice and versioning
- Choice and consent records
- Data subject request logs
- Personal information inventory
- Notice outdated
- Consent not granular
- Requests aging
- Inventory incomplete
SOC 2 - Logical and Physical Access Controls
The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity also selects and develops general control activities over technology to support the achievement of objectives.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity removes access to protected information assets when an individual no longer requires access.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity restricts physical access to facilities and protected information assets to authorized personnel.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.
- Access provisioning workflows
- User registration and authorisation records
- Access removal evidence within SLA
- Physical access logs and badge inventory
- Threat detection configuration
- Data transmission encryption evidence
- Provisioning manual and inconsistent
- Removal SLA missed
- Physical access not reviewed
- Encryption gaps for transit
SOC 2 - Security (Common Criteria)
The entity demonstrates a commitment to integrity and ethical values.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The board of directors demonstrates independence from management and exercises oversight of internal control development and performance.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity internally communicates information, including objectives and responsibilities for internal control.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity communicates with external parties regarding matters affecting the functioning of internal control.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity specifies objectives with sufficient clarity to enable identification and assessment of risks relating to objectives.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how to manage them.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity considers the potential for fraud in assessing risks to the achievement of objectives.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
The entity identifies and assesses changes that could significantly impact the system of internal control.
- Policies mapped to COSO 17 principles
- Risk assessment workpapers
- Internal and external communication evidence
- Fraud risk assessment results
- Change management evidence
- Principles not mapped
- Fraud assessment skipped
- Communication ad hoc
- Changes lack analysis
SOC 2 - System Operations and Change Management
To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in introduction of new vulnerabilities and susceptibilities to newly discovered vulnerabilities.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet objectives.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity identifies, develops, and implements activities to recover from identified security incidents.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
The entity assesses and manages risks associated with vendors and business partners.
- Monitoring configuration and alert rules
- Anomaly detection logs
- Security event evaluation records
- Incident response playbooks
- Recovery and post incident reports
- Change management tickets with approvals
- Monitoring blind spots
- Events not triaged
- Recovery untested
- Vendor reviews stale
SOC 3
SOC 3 reports provide an examination opinion on controls relevant to the Trust Services Criteria for general distribution, without the detailed description and test results found in SOC 2.
- Management's assertion suitable for general distribution
- Short-form examination report
- Use of SOC 3 logo and seal in accordance with AICPA rules
- Underlying SOC 2 examination work supporting SOC 3 opinion
- SOC 3 issued without underlying SOC 2 examination
- Distribution restrictions inappropriately applied to SOC 3
- Seal usage not registered with AICPA
Specialised
AT-C 310 governs examinations and reviews of pro forma financial information, requiring the practitioner to evaluate management's assumptions and consistency with historical financial statements.
- Pro forma assumptions documented and assessed for reasonableness
- Reconciliation to historical financial statements
- Examination or review procedures aligned with assurance level
- Report following AT-C 310 illustrative format
- Pro forma issued as audit rather than attestation
- Assumptions not separately tested
- Historical link to underlying audited statements weak
AT-C 315 provides standards for examinations and reviews of an entity's compliance with specified requirements, including the effectiveness of internal control over compliance.
- Specified compliance requirements clearly identified
- Examination procedures over compliance and related controls
- Findings of noncompliance evaluated for materiality
- Report following AT-C 315 illustrative format
- Compliance requirements not clearly stated in report
- Internal control over compliance not separately addressed
- Findings not quantified or qualified
AT-C 305 covers examinations of financial forecasts and projections, requiring evaluation of assumptions, preparation, and presentation in accordance with AICPA guidelines.
- Evaluation of assumptions and supporting evidence
- Computational accuracy and consistency checks
- Disclosure of significant assumptions in presentation
- Report referencing AICPA Guide for Prospective Financial Information
- Forecast and projection terminology conflated
- Assumptions not separately listed
- Restricted use paragraph missing for projections
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SSAE 18 - Attestation Standards (SOC Reporting) framework page.