A fintech organization is onboarding a third-party payment settlement service. The organization's risk manager must verify that the vendor's internal controls relevant to user entities' financial reporting (ICFR) have been rigorously tested for operational effectiveness over a sustained six-month evaluation period, rather than merely evaluated for design suitability at a single point in time. Which of the following independent attestations should the risk manager request to meet this objective?
- A SOC 1 Type II reportCevap
- BA SOC 1 Type I report
- CA SOC 2 Type II report
- DA SOC 3 report
Cevap
The risk manager should request a SOC 1 Type II report.
A SOC 1 Type II report is specifically scoped around SSAE 18 (formerly SSAE 16 / SAS 70) to evaluate internal controls over financial reporting (ICFR). The Type II designation confirms that an independent auditor tested the operational effectiveness of those controls over a specified period (e.g., six months).
Adım Adım Çözüm
Anahtar Kavram
Distinguishing SOC 1 vs SOC 2/3 reports and Type I vs Type II attestation scopes
Tahmini Süre:2m 0s