Understand how System and Organization Controls (SOC) reports can assure clients and stakeholders that a business securely manages data, protects privacy and maintains reliable operations.
DESIGNED FOR
Members of the Emerging Technologies Interest Group
BENEFITS
Learn how to:
Identify the key sections of a vendor SOC report that are most relevant to CPA firm practice management.
Interpret the SOC auditor’s opinion and recognize the practical significance of clean, qualified, adverse or disclaimer opinions.
Evaluate complementary user entity controls, and explain why a firm’s own control responsibilities affect reliance on the SOC report.
Assess the strength of control testing by distinguishing stronger evidence, such as examination, testing and sampling, from weaker procedures, such as inquiry of management.
Apply SOC report findings to practical vendor oversight decisions, including onboarding, annual review, renewal, risk escalation and internal documentation.HIGHLIGHTS
Highlights include:
Why vendor SOC reports matter to CPA firms
SOC reports in plain English
Is this report useful? Opinion, scope, period and relevance
User control considerations: What the firm must do
Testing language: What did the SOC auditor actually do?
Turning the SOC review into practice-management valuePREREQUISITES
None
ADVANCE PREPARATION
None