SOC 1
SOC 1 Type II Audit Readiness Checklist
A SOC 1 checklist for control objectives relevant to user entities’ internal control over financial reporting.
- Estimated time
- 6–12 Months
- Audience
- Payroll, Payments, and Other ICFR-Relevant Service Organizations
- Last updated
Operational reference for SOC 1 Type II preparation. Only a licensed CPA firm can issue a SOC 1 report.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Relevance
Phase 2: Control Design
Phase 3: Operating Evidence
Phase 4: Examination
FAQ
SOC 1 vs SOC 2?+–
SOC 1 is about controls relevant to customer ICFR. SOC 2 is Trust Services Criteria (security, etc.).
Who can issue it?+–
A licensed CPA firm.
Do SaaS companies need both?+–
If you touch payroll, billing ledgers, or similar, customers’ SOX auditors may want SOC 1 in addition to SOC 2.
Type I vs II?+–
Type II covers operating effectiveness over a period and is what most user auditors want.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer