A healthcare organization is reviewing third-party compliance documentation for a cloud-based medical billing platform. The compliance team specifically requires independent verification that the vendor's internal controls over financial reporting (ICFR) operating within the platform are effectively designed and operating as intended over time. Which of the following audit reports should the organization request to satisfy this requirement?
- SOC 1 Type II reportAnswer
- BSOC 2 Type II report
- CSOC 3 report
- DExternal vulnerability assessment report
Answer
SOC 1 Type II report
The SOC 1 Type II report is specifically designed to assess a third-party service provider's controls that are relevant to a user entity's internal control over financial reporting (ICFR). The Type II designation confirms that an independent auditor evaluated both the suitability of the control design and its operating effectiveness over a specified testing window.
Step-by-Step Solution
Key Concept
SOC 1 vs SOC 2 Scope and Attestation Types