Skip to content

SOC 1

What is SOC 1?

An AICPA audit report on controls at a service organisation relevant to user entities' financial reporting. Available as Type I (design only) or Type II (design and operating effectiveness).

Audit

What the standards actually require on soc 1

Requirements naming soc 1 across 2 standards, quoted from the control text.

AT-C 320 governs SOC 1 engagements over controls at a service organisation relevant to user entity ICFR, requiring written assertion, system description, and (for Type 2) operating effectiveness testing.

SSAE-05 · SOC 1 Engagements (AT-C 320)

Lloyds MS11.13 Security Awareness and Insider Risk - mandatory annual cyber security awareness training for all personnel + Senior Manager Function holders + Board + role-based deep training for IT + security + claims handlers + underwriters + actuaries + fina...

LLOYDS-MS11-Security-Awareness-Insider-Risk-Penetration-Testing-Independent-Assurance-MS11-13-16 · Lloyds MS11 Security Awareness + Insider Risk + Pen Testing + Assurance + MS11.13-16

Questions people ask about soc 1

What is SOC 1?
An AICPA audit report on controls at a service organisation relevant to user entities' financial reporting. Available as Type I (design only) or Type II (design and operating effectiveness).
Why is SOC 1 important for compliance?
SOC 1 is a key concept in Audit. Understanding soc 1 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to SOC 1?
Key concepts related to SOC 1 include SOC 2. Understanding these interconnected concepts provides a more comprehensive view of Audit requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address SOC 1?
SOC 1 appears in the requirement text of SSAE 18 - Attestation Standards (SOC Reporting), Lloyd's Minimum Standards - Cyber Security. Across these standards we have identified 2 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about SOC 1?
Explore our compliance framework pages to see how soc 1 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how SOC 1 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.