What is the job of SERVICE AUDITORS in SOC 1 examinations?
Service Auditors determine if management’s description of the service organization’s system is FAIRLY STATED IN ALL MATERIAL RESPECTS, based on the criteria in management’s assertion
What is a FAIRLY STATED management description of the service organization’s system?
It is one that meets the needs of the intended report users
What does a SOC 1 EXAMINATION do?
It provides assurance about how the service organization affects user entities’ internal controls over financial reporting
What should the service auditor do to determine if MISSTATEMENTS are MATERIAL?
What is an UNQUALIFIED OPINION?
What is a QUALIFIED OPINION?
It is an opinion that indicates that the financial statements are true and fair, except for ONE issue
What is an ADVERSE opinion?
It is an opinion that indicates to financial statement users that the auditors conclude that the financial statements don’t give a true and fair view
What is a SCOPE LIMITATION?
This opinion is when the auditor cannot obtain enough audit evidence to conclude if the financial statements as a whole are NOT free from material misstatements
Who are the intended users of a SOC 2 report?
What do SOC 2 reports REPORT ON?
For each vendor that management classifies as a SUBSERVICE ORGANIZATION, management must choose to use:
What happens under the CARVE-OUT METHOD?
What do the boundaries of a service organization’s system include?
Infrastructure
Software
Data
Procedures
Employees
If a utility company provides no other services:
Management would classify it as a VENDOR
To classify a 3rd party provider as a SUBSERVICE ORGANIZATION, all of the following apply except:
What is an example of when a service organization would classify the 3rd party as a vendor, and NOT a subservice organization?
What is DC?
Description Criteria for a Description of a Service Organization’s System in a SOC 2 report
DC Section 100
DC Section 200
SOC for organization’s system description
DC Section 300
SOC for Supply Chain examinations
When do description misstatements occur?
What does management’s description of the service organization’s system also include WHEN the INCLUSIVE method is used for 1+ subservice organizations?
It includes the subservice organization’s control objectives and controls
In all SOC examinations (NOT SOC 1), what serves as suitable criteria for measuring/evaluating controls?
Trust Services Criteria (AICPA)
The AICPA Trust Services Criteria ___ with the COSO Framework and EXTEND the guidance to measure or evaluate controls related to security, availability, processing integrity, confidentiality, or privacy
ALIGN