AUD Review 5 Flashcards
Describe the differences between the System and Organization Controls (SOC) reports.
SOC 1: Internal Control over Financial Reporting (ICFR)
- This report is used to provide assurance related to the financial information and that it is being handled safely and securely.
SOC 2: Trust Services Criteria
- This report is used to provide assurance to a more broad set of users regarding the internal controls relevant to the trust service criteria; security, availability, processing integrity, confidentiality, and privacy.
Type 1:
Is reporting on the design and implementation of internal control(IC) but does NOT provide assurance on the operating effectiveness of IC
Type 2:
Is reporting on the design, implementation, AND operating effectiveness of internal control and provides assurance.
What are the components of Internal Control (IC)