Question

Difficulty: EasySecurity Audits, Assessments, and Attestations

An enterprise finance company is onboarding a cloud payroll vendor and requires third-party assurance specifically regarding the vendor's internal controls over financial reporting. Which of the following reports should the enterprise request from the vendor?

  1. SOC 1 reportAnswer
  2. B
    SOC 2 report
  3. C
    SOC 3 report
  4. D
    Penetration testing report

Answer

The SOC 1 report is the correct choice because it evaluates internal controls over financial reporting.
A SOC 1 (System and Organization Controls 1) report is specifically designed to audit and attest to a service organization's internal controls relevant to user entities' internal controls over financial reporting (ICFR).

Step-by-Step Solution

1
Identify the primary compliance requirement stated in the scenario.
The requirement is assurance over internal controls relevant to financial reporting (ICFR).
Matching the organization's business requirement to the standard attestation framework.
2
Evaluate the scope of SOC report types.
SOC 1 addresses financial controls, whereas SOC 2 and SOC 3 address IT security and trust criteria.
Differentiating financial reporting audit standards from general operational security audit standards.

Key Concept

SOC 1 Attestation for Internal Controls Over Financial Reporting
Rate this question