Assurance on security of service provision
Many businesses outsource some of their financial and other processes to service organisations. These processes may include payroll accounting, IT services (cloud solutions, infrastructure, etc.), asset management, back-office processes, etc. A disruption of these processes can have a major impact on the continuity of their business operations. That is why they want the assurance that a service organisation is in control of its processes, for instance when it comes to risk management, internal control or data integrity. Moore DRV’s IT auditors can help you provide that assurance to your customers by issuing an independent SOC 2 assurance report.
What is a SOC 2 audit?
SOC stands for System and Organisation Controls. A SOC 2 audit addresses the effectiveness of the internal controls governing the Trust Service Criteria defined by the American Institute of Certified Public Accountants (AICPA). These Trust Services Criteria are security, availability, processing integrity, confidentiality and privacy. This makes SOC 2 relevant for users wanting to provide assurance on the quality of information security and privacy.
What is the difference between a SOC 2 Type I and Type II report?
There are two types of SOC 2 reports, i.e. Type I and Type II. What are they and what is the difference? First off, we should say that there are many similarities between the two types. The difference lies mainly in the level of scope. A Type I report provides assurance on the design and the existence of the internal controls at a specific point in time. A Type II report provides assurance on the design, existence and operational effectiveness of the internal controls over a specific period of time.
Benefits of a SOC 2 audit
- Verifiable risk management and application of quality standards.
- Assurance for customers, suppliers and end users, creating a competitive advantage.
- National and international recognition by regulatory authorities.
- External review of internal control system.
- Better control of internal processes.
How is a SOC 2 audit different from an ISAE 3000 or ISAE 3402 audit?
The ISAE 3402 standard applies if financial processes have been outsourced to a service organisation, such as a provider of payroll accounting, back-office, asset management or credit management services. An ISAE 3402/SOC 1 assurance report addresses the service organisation’s management of risks associated with financial processes. The internal control objectives and controls are optional and subject to the auditor’s professional judgement.
A SOC 2 or ISAE 3000 audit focuses not only on financial processes but also on the Trust Services Criteria defined by the American Institute of Certified Public Accountants (AICPA). These Trust Services Criteria are security, availability, processing integrity, confidentiality and privacy. As a result, SOC 2/ISAE 3000 is much more targeted at information security and privacy than ISAE 3402, which focuses exclusively on financial processes.
Why would a SOC 2 audit be useful for my business?
A SOC 2 audit is typically useful for businesses that store, process or use data for their customers, such as customer or third-party data. The sector tends to be less relevant; these businesses are usually driven by a high level of automation. Examples include cloud service providers, hosting parties, data centres and Software-as-a-Service (SaaS) platforms.
Organisations governed by the Dutch Financial Supervision Act or the Dutch Pensions Act must be able to demonstrate that they are in control of their financial and other processes, which makes a SOC 2 assurance report a relevant proposition for providers of services to banks, notaries, pension funds and insurance companies.
Obtaining a SOC 2 report
A SOC 2 report must address the Trust Services Criteria defined by the American Institute of Certified Public Accountants (AICPA), i.e. security, availability, processing integrity, confidentiality and privacy. Security is the only criterion that is required for every SOC 2 audit. The other criteria are optional based on the services provided.
The AICPA has described the focus areas of each of the Trust Services Criteria. They are related to the five components of the COSO Framework. Each component comes with about 61 aspects, which brings the total number of focus areas to approximately 300. The focus areas offer valuable guidance for how to define and report on the internal controls governing the Trust Services Criteria.
Considering the above, our report will not only offer your customers insight into the reliability and quality of your service provision, but it will also give them confirmation in a third-party memorandum (TPM) that you have internal controls in place and that these controls are effective.
Want to make the right start with SOC 2? We can help by:
- Setting up a framework for you.
- Having our certified IT auditors review your framework.
Want to find out more about SOC 2?
For more information about how Moore DRV can help you become SOC 2-certified, please leave your contact details here and we will reach out to you for a no-obligation consultation.