SOC 1
What is SOC 1?
An AICPA audit report on controls at a service organisation relevant to user entities' financial reporting. Available as Type I (design only) or Type II (design and operating effectiveness).
Related terms
Frameworks that govern soc 1
What the standards actually require on soc 1
Requirements naming soc 1 across 2 standards, quoted from the control text.
AT-C 320 governs SOC 1 engagements over controls at a service organisation relevant to user entity ICFR, requiring written assertion, system description, and (for Type 2) operating effectiveness testing.
SSAE-05 · SOC 1 Engagements (AT-C 320) →Lloyds MS11.13 Security Awareness and Insider Risk - mandatory annual cyber security awareness training for all personnel + Senior Manager Function holders + Board + role-based deep training for IT + security + claims handlers + underwriters + actuaries + fina...
LLOYDS-MS11-Security-Awareness-Insider-Risk-Penetration-Testing-Independent-Assurance-MS11-13-16 · Lloyds MS11 Security Awareness + Insider Risk + Pen Testing + Assurance + MS11.13-16 →Questions people ask about soc 1
What is SOC 1?
Why is SOC 1 important for compliance?
What concepts are related to SOC 1?
Which compliance frameworks address SOC 1?
Where can I learn more about SOC 1?
See how SOC 1 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.