A chief risk officer at a commercial financial institution is reviewing third-party compliance requirements for a newly selected SaaS general ledger processing vendor. The bank's internal regulatory compliance charter mandates that external service providers affecting financial accounting must provide independent attestation regarding the design and operational effectiveness of internal controls over financial reporting (ICFR) across a full 12-month evaluation window. Which of the following audit attestation reports specifically satisfies this requirement?
- A SOC 1 Type II reportCevap
- BA SOC 2 Type II report
- CA SOC 1 Type I report
- DA SOC 3 report
Cevap
A SOC 1 Type II report is the required independent audit attestation.
A SOC 1 Type II report is specifically scoped for Service Organization Controls related to Internal Controls over Financial Reporting (ICFR). Furthermore, the Type II designation confirms that an independent auditor evaluated both the design suitability and the operational effectiveness of those controls over a specified period (such as 12 months).
Adım Adım Çözüm
Anahtar Kavram
Distinguishing SOC Report Scope and Types (SOC 1 vs SOC 2 vs SOC 3, Type I vs Type II)