AICPA SOC 1
What is AICPA SOC 1?
Service Organization Controls for financial reporting. It comprises 25 controls organised across 5 domains, published by AICPA, and applies in the United States.
How AICPA SOC 1 maps to other frameworks
All 25 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains AICPA SOC 1 groups its controls into
Where AICPA SOC 1 overlaps with the standards you already hold
More AICPA SOC 1 comparisons
What AICPA SOC 1 means in your sector
What AICPA SOC 1 means for your job
Questions people ask about AICPA SOC 1
What is AICPA SOC 1?
How many controls does AICPA SOC 1 have?
Where does AICPA SOC 1 apply?
What frameworks does AICPA SOC 1 map to?
How do I get started with AICPA SOC 1 compliance?
Query AICPA SOC 1 programmatically
AICPA SOC 1, its 25 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
AICPA SOC 1 API reference and MCP config →What AICPA SOC 1 requires, control by control
Each page carries the requirement text for one AICPA SOC 1 control and what an assessor expects to see as evidence.
- CO-CHANGEMGMT-3 Segregation of Duties in Change Deployment
- CO-CHANGEMGMT-5 Infrastructure and Database Change Control
- CO-LOGICALACCESS-1 User Access Provisioning
- CO-LOGICALACCESS-4 Privileged Access Management
- CO-LOGICALACCESS-7 Segregation of Duties in Financial Systems
- CO-NEWDEV-2 Secure Coding and Code Review
- CO-OTHER-1 Risk Assessment for ICFR
How ready are you for AICPA SOC 1?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.