SOC 1: Guide to Financial Reporting Controls
SOC 1 reports, governed by SSAE 18 (Statement on Standards for Attestation Engagements No. 18), examine the internal controls at a service organization that are relevant to their client's financial reporting. If your service affects your customers' financial statements, SOC 1 is likely the right report.
What SOC 1 Covers
Unlike SOC 2 which focuses on security, availability, and processing integrity broadly, SOC 1 is specifically concerned with controls that could impact a user entity's financial reporting. This includes transaction processing controls, data integrity safeguards, IT general controls, logical access restrictions, and change management for systems that process financial data.
The scope is tailored to each organization — you define the services, systems, and controls relevant to your customers' financial reporting, and the auditor tests those controls.
Type I vs. Type II
- Type I — Evaluates the design of controls at a specific point in time. Useful as a first step or when time is limited.
- Type II — Evaluates both the design and operating effectiveness of controls over a period (typically 6 to 12 months). This is what most customers require.
Who Needs SOC 1
SOC 1 is essential for service organizations whose activities impact client financial reporting. Common examples include payroll processors, payment processors, loan servicing companies, claims administrators, data center hosting providers for financial applications, and SaaS companies that process financial transactions.
If your customers' auditors ask about your controls over financial reporting, you need a SOC 1 report. If their questions center on data security and availability more broadly, SOC 2 may be more appropriate.
Audit Process
- Scope definition — Identify services and controls relevant to client financial reporting
- Readiness assessment — Evaluate current control design and effectiveness
- Remediation — Address gaps identified during readiness
- Observation period — For Type II, operate controls for 6-12 months
- CPA audit — Independent CPA firm tests controls and issues the report
- Report delivery — Share the report with customers under NDA
Cost Drivers
The largest cost components are CPA firm audit fees and internal staff time. Organizations with complex processing environments, multiple service lines, or numerous ITGC controls should expect costs toward the higher end of the range.
Key Control Categories Explained
Controls over transaction processing — The heart of any SOC 1 report. These controls ensure transactions are initiated, authorized, recorded, and settled accurately. A payroll processor's controls over calculating gross pay, tax withholdings, and net disbursements are a classic example. Auditors test for completeness (all transactions captured), accuracy (amounts are correct), and timeliness (transactions processed within defined windows).
Controls over financial data integrity — Addresses how data is protected from corruption, unauthorized modification, or loss between entry and reporting. Reconciliation controls, data validation rules, and segregation between data entry and approval functions all belong here.
IT general controls (ITGC) supporting financial reporting — The infrastructure controls that underpin the reliability of all other controls. Includes logical access restrictions to financial systems, change management procedures (preventing unauthorized code changes from affecting calculations), computer operations (ensuring processing runs complete and errors are detected), and availability controls.
Logical access controls to financial systems — Who has access to what in your financial processing environment. Auditors examine user provisioning and de-provisioning processes, privileged access management, and multi-factor authentication for financial system access.
Change management for financial applications — Any change to a system that processes financial data is a risk. SOC 1 requires that changes be formally requested, approved, tested in a separate environment, and only promoted to production through a controlled process. Emergency change procedures must also be documented.
SOC 1 vs. SOC 2: Which Report Do You Need?
This is the most common question from organizations entering the SOC reporting universe. The answer comes down to what your customers need assurance about.
Choose SOC 1 if your service directly affects your customers' financial statements — you process their transactions, run their payroll, manage their accounts receivable, or provide data that flows into their general ledger.
Choose SOC 2 if your customers care primarily about the security, availability, and privacy of data you process on their behalf, rather than the accuracy of financial transactions. Most SaaS companies, cloud providers, and data processors need SOC 2, not SOC 1.
Many organizations — particularly payroll processors, payment providers, and banking technology companies — need both. The control overlap is approximately 40%, so some evidence can be reused, but the reports serve distinct audiences.
The Audit Process Step by Step
Step 1 — Scope definition. Work with your auditing firm to identify which services, systems, and controls are relevant to user entity financial reporting. The scope should be specific enough to be meaningful and broad enough to satisfy your customers' auditors.
Step 2 — Readiness assessment. Evaluate the design of your controls before the observation period begins. Identifying and remediating design gaps before the clock starts avoids exceptions in the final report.
Step 3 — Observation period. For Type II, controls must operate for the period being reported — typically 6 to 12 months. The annual reporting period is most common; new clients often request a shorter initial period (6 months) before transitioning to annual.
Step 4 — CPA audit fieldwork. Your licensed CPA firm selects samples across the observation period, reviews documentation, and interviews control owners. ITGC controls receive particular scrutiny because weaknesses there can undermine the reliability of all other controls.
Step 5 — Draft report and management response. The draft report gives you an opportunity to review findings and provide management responses before finalization.
Step 6 — Report distribution. SOC 1 reports are restricted-use documents shared with user entities and their auditors under NDA. They are not for public distribution.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| Readiness assessment | $8,000 | $25,000 |
| CPA audit fee — Type I | $15,000 | $50,000 |
| CPA audit fee — Type II | $25,000 | $100,000 |
| Internal staff time | $15,000 | $50,000 |
| Remediation costs (varies widely) | $5,000 | $75,000 |
| Typical Type II total | $50,000 | $200,000 |
Timeline: 3 to 9 months. Type I can complete in 3 to 4 months; Type II requires a minimum 6-month observation period.
How SOC 1 Relates to COSO
The COSO Internal Control — Integrated Framework is the conceptual foundation for SOC 1 control design. When a SOC 1 auditor evaluates your control environment, they are assessing whether your controls meet the intent of COSO's five components: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
Organizations using COSO as the basis for SOX compliance will find significant overlap with SOC 1 requirements — roughly 70%. The documentation, testing methodologies, and evidence types are similar enough that teams managing both can consolidate significantly.
How Automation Helps
Evidence collection for SOC 1 is substantial — transaction logs, access provisioning records, change tickets, reconciliation sign-offs, and batch processing completion reports all need to be gathered and organized for auditor sampling. Manual collection across a 12-month observation period is resource-intensive.
Compliance automation that integrates with your financial systems, identity providers, and change management tools can automate much of this collection. LowerPlane supports SOC 1 controls alongside its broader framework library (50-plus frameworks) and provides evidence organization that makes auditor sampling significantly faster. At $4,000/year entry pricing with a free tier, it is accessible well before your audit engagement begins. AuditXYZ rates it 9.4/10. See Best Compliance Automation Platforms.
Frequently Asked Questions
What is the difference between SOC 1 and SOC 2? SOC 1 reports on controls relevant to your customers' financial reporting. SOC 2 reports on controls relevant to the security, availability, processing integrity, confidentiality, and privacy of your service. If your service processes financial transactions for customers, you likely need SOC 1. If your service stores customer data and customers care about security posture, you need SOC 2. Many organizations need both.
Who can perform a SOC 1 audit? Only licensed CPA firms with attest authority can issue SOC 1 reports under SSAE 18. This is a legal requirement. Consultants and non-CPA security firms can assist with readiness, but the final report must come from a CPA firm.
How long is a SOC 1 report valid? A SOC 1 Type II report covers a specific observation period (typically 12 months). After the period ends, the report represents historical evidence. Enterprise customers typically expect reports with an end date within the past 12 months. Annual re-audits keep your report current.
Can we share a SOC 1 report publicly? No. SOC 1 reports are restricted-use documents intended for user entities (your customers) and their auditors. They are not suitable for general public distribution. If you want a publicly shareable compliance signal, SOC 3 provides an auditor's summary that can be publicly distributed alongside a SOC 2 engagement.
Does SOC 1 replace SOX compliance? No. SOC 1 is a service organization report. SOX compliance obligations fall on the publicly traded user entity (your customer), not on you. However, your SOC 1 report helps your customers' auditors satisfy their own SOX audit requirements related to your services — which is exactly why they request it.