By Stephen Halbrook, Manager, BrightLine
Is your organization ready for a SOC 2 examination? Here are five steps to help successfully prepare for one:
- Validate the nature of the request. Does your client base understand the various SOC reporting options and what they are asking of your organization from a compliance reporting perspective? Is there a connection to internal controls over financial reporting (ICFR) of the services that you provide to your clients, or are you looking at general controls of a system that are relevant to security, availability processing integrity, confidentiality, and privacy? SOC 1 can oftentimes be misused by the general public as a generic reference to third-party audits. There is misconception in the marketplace; help prevent it.
- Understand the trust service principles. Experience has shown that the best way to reach an effective solution is by considering the needs of customers and other interested third parties. First, communicating and determining the information the user organization will want, need, and expect should help determine the best trust service principles (TSP) to select. Also, service organizations must look at their control environment and identify which TSPs are applicable based on the criteria. Several times an organization or the interested third party will demand specific TSPs, however, after reviewing the criteria, the organization’s business processes, and the control environment, the principal would not even be applicable in the service organization’s environment. For example, a cloud service provider most likely will not need to focus on processing integrity, but it is vital for a payroll provider.
- Determine preparedness. Once you understand the different TSPs, consider your options and preparedness prior to determining how to proceed. If the environment to be audited is relatively new and has never been through an audit, it might be best to start with a readiness assessment and/or Type 1 examination, and then move to a Type 2 engagement. Be mindful of the review date and review period as they relate to Type 1 and Type 2, respectively.
- Identify key person(s) within the organization. This person(s) will be responsible for the overall audit effort. Determine whether your organization has the bandwidth necessary to provide the time and resources required of the engagement. Although not mandatory, oftentimes it is helpful to assign an internal point person with audit experience to the engagement.
- Contract and start planning. It is necessary to perform due diligence when selecting your service auditor. Speak with at least three different firms. Confirm that the firms have the proper licensing and credentials to operate in the state(s) that your services are located, have skilled and credentialed personnel, and are a good fit overall with your organization. Remember, the least costly firm is not always the best option. Some questions to ask:
- How many SOC 2 engagements have you performed as a company?
- How many SOC 2 engagements have been performed for other companies in your industry?
- How much experience do your personnel have in performing SOC 2 engagements?
- How do you provide pricing?
A properly planned engagement with an experienced audit firm will help your SOC 2 examination be successful. Good luck!