Soru

Zorluk: Çok zorSecurity Audits, Assessments, and Attestations

A fintech organization is onboarding a third-party payment settlement service. The organization's risk manager must verify that the vendor's internal controls relevant to user entities' financial reporting (ICFR) have been rigorously tested for operational effectiveness over a sustained six-month evaluation period, rather than merely evaluated for design suitability at a single point in time. Which of the following independent attestations should the risk manager request to meet this objective?

  1. A SOC 1 Type II reportCevap
  2. B
    A SOC 1 Type I report
  3. C
    A SOC 2 Type II report
  4. D
    A SOC 3 report

Cevap

The risk manager should request a SOC 1 Type II report.
A SOC 1 Type II report is specifically scoped around SSAE 18 (formerly SSAE 16 / SAS 70) to evaluate internal controls over financial reporting (ICFR). The Type II designation confirms that an independent auditor tested the operational effectiveness of those controls over a specified period (e.g., six months).

Adım Adım Çözüm

1
Determine the audit domain required by the scenario.
The requirement specifies internal controls over financial reporting (ICFR).
SOC 1 reports focus specifically on financial reporting controls, whereas SOC 2 and SOC 3 address Trust Services Criteria.
2
Distinguish between Type I and Type II attestation scopes.
Type II reports test operational effectiveness over a specified historical period, whereas Type I reports assess control design at a single point in time.
The requirement explicitly demands verification of operational effectiveness over a sustained six-month evaluation period.
3
Synthesize the domain and report type to identify the correct attestation.
A SOC 1 Type II report fulfills both the financial reporting scope (SOC 1) and operational effectiveness testing requirement over time (Type II).
This report type provides independent verification of ICFR design and sustained operational performance.

Anahtar Kavram

Distinguishing SOC 1 vs SOC 2/3 reports and Type I vs Type II attestation scopes
Tahmini Süre:2m 0s
Bu soruyu puanla