SlideShare a Scribd company logo
Gaining Assurance Over
Third Party Processors –
SOC 1 & SOC 2 Reporting
Gaining Assurance Over Third Party
Processors – SOC 1 & SOC 2 Reporting
DEMANDS FOR ASSURANCE OVER
THIRD PARTY PROCESSORS
Third party processing organizations spanning a
variety of business sectors including distribution,
financial services, technology, life sciences, services
and healthcare are being requested by their custom-
ers (a.k.a., user organizations) to obtain an assurance
report on controls related to the integrity of certain
processes and security over sensitive information
being handled by those third parties.
Many user organizations realize that while they have
outsourced certain aspects of their business, they
continue to be responsible for the activities conduct-
ed by the third party processing organization. A good
deal of this concern has been driven by regulations
and standards such as HIPAA, HITECH, the GLB
Act, the Meaningful Use standards of the Centers for
Medicare and Medicaid Services (CMS), and others
including various State and International privacy laws.
THE EVOLUTION OF SOC 1 AND SOC 2
Statements on Standards for Attestation Engage-
ments No. 16 (SSAE 16) is an update to the previous
standard, known as Statement on Auditing Standards
No. 70 (a.k.a., SAS 70) created in the early ‘90s by
the American Institute of Certified Public Accountants
(AICPA) in which an auditor would provide assurance
regarding specified control objectives over process-
es related to financial reporting. Service Organization
Control No. 1 (SOC 1) reports are conducted using
SSAE 16.
AT Section 101 was developed in 2001 by the
AICPA to place requirements for CPAs examining and
issuing reports on controls over matters not related
to financial reporting. These requirements are codified
within AT Section 101, Attest Engagements, of the
AICPA’s attestation standards. Reports issued under
AT 101 often utilize the AICPA’s Trust Services Prin-
ciples which relate to security, availability, processing
integrity, confidentiality and privacy.
Lately, many of the audits issued under AT-101 that
are gaining prominence in the market place include
Service Organization Controls No. 2 (SOC 2) and
Service Organization Controls No. 3 (SOC 3) reports.
Each of the five Trust Services Principles is supported
by dozens of Criteria and third party processors may
choose to comply with either one, several, or all five
principles.
© 2014 SMART DEVINE; All rights reserved.
TRUST SERVICES PRINCIPLES OVERVIEW
SECURITY
The system is protected, both logically and physi-
cally, against unauthorized access.
AVAILABILITY
The system is available for operation and use as
committed or agreed to.
PROCESSING INTEGRITY
The system processing is complete, accurate,
timely, and authorized.
CONFIDENTIALITY
Information that is designed “confidential” is
protected as committed or agreed.
PRIVACY
Personal information is collected, used, retained,
and disclosed in conformity with the commitments
in the entity’s privacy notice and with the privacy
principles put forth by the American Institute of
Certified Public Accountants (AICPA) and the
Canadian Institute of Chartered Accountants (CICA).
smartdevine.com 267-670-7300
© 2014 SMART DEVINE; All rights reserved.
REVISIONS TO SOC 2 STANDARD
In February 2014 the AICPA issued a revision to
the Trust Services Principles and Criteria for a few
reasons:
•	 Increase the clarity of certain criteria;
•	 Eliminate redundancy amongst the criteria; and
•	 Update the criteria based upon the changing
	 technology and business environment as the
	 original Trust Service Principles were derived
	 from the SysTrust principles and criteria.
The AICPA’s Assurance Services Executive Com-
mittee (ASEC) is responsible for changes to the
updated Standard. The following is a brief summary of
the AICPA’s changes.
Common Criteria: ASEC has created “common cri-
teria” that represent criteria that are applicable to four
of the five principles, namely Security, Confidentiality,
Availability and Processing Integrity. A number of third
party processing organizations have cited overlap-
ping criteria across four of the five principles within the
previous Standard, and the associated inefficiency.
The Common Criteria constitutes the complete set
of criteria for the Security Principle and is organized
into seven categories following the key concepts of
the Committee of Sponsoring Organizations of the
Treadway Commission (COSO) framework, including:
•	 Organization and Management
•	 Communications
•	 Monitoring of Controls
•	 Risk Management and Design and
	 Implementation of Controls
•	 Logical & Physical Controls
•	 System Operations
•	 Change Management
Separate Criteria: for the principles of Availability,
Processing Integrity, and Confidentiality, a complete
set of criteria is comprised of all of the Common Cri-
teria and all of the criteria applicable to the princi-
ple being reported upon. For instance, the updated
Standard indicates the principle of Availability has three
unique criteria; Processing Integrity has six unique
criteria; and Confidentiality also has six unique criteria.
Privacy Principle: The Privacy principle will remain
distinct and is being revised by a separate task force.
An exposure draft has not been created related to
Privacy, at this time.
Risk Assessment: The updated Standard em-
phasizes an assessment of risks that any particular
criteria will not be met. Illustrative examples of criteria
and controls, and their corresponding risks has been
included in the updated standard.
The AICPA has indicated the new reporting
Standard will go into effect for periods ending after
December 15, 2014, however earlier implementation
is permitted.
smartdevine.com 267-670-7300
A c c o u n t i n g T a x A d v i s o r y
Smart Devine provides a full range of accounting, advisory, tax and investigative forensic and litigation services
to organizations across a variety of industries.
Smart Devine | 1600 Market Street | 32nd Floor | Philadelphia, PA 19103 | T 267-670-7300 | info@smartdevine.com
© 2014 SMART DEVINE; All rights reserved.
SMART DEVINE OFFERS A FULL LINE OF SOLUTIONS INCLUDING:
ACCOUNTING & AUDIT
•	Audit, Reviews & Compilation
•	Accounting & Tax Due Diligence
•	Accounting Outsourcing
•	Agreed Upon Procedures
•	Business Valuation
•	Finance Process & Reporting Optimization
•	Forecasts and Projections
•	Forensic Accounting & Litigation Support
•	Internal Control Study & Evaluation
•	Personal Financial Statements
•	Retirement Plan Audits & Prep
•	Trust Accounting
•	SEC Advisory Services
•	Special Project Coordination & Support
•	Technical Accounting Consulting
•	Transaction Advisory Services
•	SSAE 16/SOC 1 and SOC 2 Reviews
RISK SERVICES
•	Corporate Governance Regulatory
	Compliance
•	Enterprise Risk Management
•	Business Risk Assessment
•	IT Risk Assessment
•	Internal Audit Services
•	IT Internal Auditing
•	Internal Audit Transformation
•	Quality Assessment Reviews
•	Sarbanes Oxley/Model Audit Rule/NAIC 	
	Compliance
•	SSAE 16/SOC 1 and SOC 2 Readiness 	
	Assessments
TAX
•	Tax Return Compliance
•	Accounting for Income Taxes
•	ASC 740 (FAS 109) Tax Provision Services
•	International Taxation
•	IC-DISC
•	Tax Planning and Advisory
•	Tax Controversy
•	Transfer Pricing
•	Research and Development Tax Credit
•	State and Local Taxation
BUSINESS ADVISORY
•	Financial Advisory
•	Management Consulting Services
•	Technology Consulting Services
INSURANCE ADVISORY SERVICES
•	Accounting
•	Reviews
•	Claims Services
•	Underwriting/Premium
•	Forensic Accounting
FORENSIC AND LITIGATION SERVICES
•	Litigation Services
•	Environmental Litigation
•	Forensic Investigations
•	Trustee & Monitoring Services
•	Digital Forensics & eDiscovery
For more information, please contact John McLaughlin, Managing Director at
610-994-1534 or jmclaughlin@smartdevine.com

More Related Content

PDF
SOC 2: Build Trust and Confidence
PDF
SOC 2 and You
PPTX
Soc 2 attestation or ISO 27001 certification - Which is better for organization
PDF
SOC 1 Overview
PPTX
Moss Adams SSAE 16 SOC Audits
PDF
Everything You Need To Know About SOC 1
PPTX
Achieving SSAE 16 Certification
PPTX
Auditor Reporting on Controls at Service Organizations
SOC 2: Build Trust and Confidence
SOC 2 and You
Soc 2 attestation or ISO 27001 certification - Which is better for organization
SOC 1 Overview
Moss Adams SSAE 16 SOC Audits
Everything You Need To Know About SOC 1
Achieving SSAE 16 Certification
Auditor Reporting on Controls at Service Organizations

What's hot (19)

PDF
SSAE 16 Transitions Overview
PPTX
Iso iec 20000 foundation training course by interprom
PDF
What is iso iec 20000
PDF
CSA STAR Program
PDF
The CSA STAR Program: Certification & Attestation
PDF
How Your Organization Can Become ISO Certified...It's easier than you think
PPT
Iso 20000 standard implementation
PDF
Iso 20000 itsms implementation steps-lakshy
PDF
ISO 20000 Implementation Presentation
PDF
EPCS Overview
PPTX
Vendor risk management webinar 10022019 v1
PDF
Soc 2 vs iso 27001 certification withh links converted-converted
PPTX
Control Standards for Information Security
PPTX
Compliance Management Software
PDF
Corporate Compliance Management
PPTX
Continuous Compliance Monitoring
PPS
ISO/I20000 in a nutshell
PPTX
General Data Protection Regulation (GDPR)
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
SSAE 16 Transitions Overview
Iso iec 20000 foundation training course by interprom
What is iso iec 20000
CSA STAR Program
The CSA STAR Program: Certification & Attestation
How Your Organization Can Become ISO Certified...It's easier than you think
Iso 20000 standard implementation
Iso 20000 itsms implementation steps-lakshy
ISO 20000 Implementation Presentation
EPCS Overview
Vendor risk management webinar 10022019 v1
Soc 2 vs iso 27001 certification withh links converted-converted
Control Standards for Information Security
Compliance Management Software
Corporate Compliance Management
Continuous Compliance Monitoring
ISO/I20000 in a nutshell
General Data Protection Regulation (GDPR)
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Ad

Similar to Gaining assurance over 3rd party soc 1 and soc 2 reporting 7-2014 (20)

PPTX
Due dilligence on a cpa firm or other accounting services provdier
PDF
The Retirement Of Sas 70 Article
PPTX
Service Organizational Control (SOC 2) Compliance - Kloudlearn
DOCX
TRUST SERVICES CRITERIA IN SOC 2 AUDITS- A SAAS COMPLIANCE GUIDE.docx
PDF
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
PDF
SOC 2 Certification Unveiled: Understanding the Core Principles
PPTX
SOC 2 presentation. Overview of SOC 2 assessment
PDF
365 infographic-compliance
PDF
Data Center Audit Standards
DOCX
Untitled document (4).docx
PPTX
What Data Center Compliance Means for Your Business
PDF
Navigating the SOC 2 Certification Maze: What You Need to Know
PDF
The relationship between SOC 2 certification
PPTX
Secrets for Successful Regulatory Compliance Projects
PDF
Analytical Procedures With Conforming Changes As Of March 1 2012 Aicpa
PDF
CISSP Domain 06 Security Assessment and Testing.pdf
PDF
(eBook PDF) Principles of Auditing Other Assurance Services 19th
DOCX
Why should I do SOC2?
PDF
(eBook PDF) Principles of Auditing Other Assurance Services 19th
PDF
(eBook PDF) Principles of Auditing Other Assurance Services 19th
Due dilligence on a cpa firm or other accounting services provdier
The Retirement Of Sas 70 Article
Service Organizational Control (SOC 2) Compliance - Kloudlearn
TRUST SERVICES CRITERIA IN SOC 2 AUDITS- A SAAS COMPLIANCE GUIDE.docx
Internal Control Certification – It’s Not Just an Accounting Thing (Credit Un...
SOC 2 Certification Unveiled: Understanding the Core Principles
SOC 2 presentation. Overview of SOC 2 assessment
365 infographic-compliance
Data Center Audit Standards
Untitled document (4).docx
What Data Center Compliance Means for Your Business
Navigating the SOC 2 Certification Maze: What You Need to Know
The relationship between SOC 2 certification
Secrets for Successful Regulatory Compliance Projects
Analytical Procedures With Conforming Changes As Of March 1 2012 Aicpa
CISSP Domain 06 Security Assessment and Testing.pdf
(eBook PDF) Principles of Auditing Other Assurance Services 19th
Why should I do SOC2?
(eBook PDF) Principles of Auditing Other Assurance Services 19th
(eBook PDF) Principles of Auditing Other Assurance Services 19th
Ad

More from Accounting_Whitepapers (14)

PDF
Why Data Standards?
PDF
Permanent Establishment May Not Be So Permanent (Prepare for Change)
PDF
The Continuing Evolution of Tax Law, at Home and Abroad
PDF
Reinsurance commutation 0315
PDF
Quest for tax reform-white paper - 8-2014
PDF
Form 8300-compliance - smart devine
PDF
Faculty workload analysis by Mary Lynn Kudey
PDF
Smart devine-act now before its too late-0313-v6
PDF
Re engineering-0313-v10
PDF
Non profit-role-review-0213
PDF
Non profit-9-questions #3 5-2013
PDF
How the new asu will impact your organization by christopher niwinski
PDF
Cyber risk management-white-paper-v8 (2) 2015
PDF
Hiring Household Employees Regulatory Requirements 2015
Why Data Standards?
Permanent Establishment May Not Be So Permanent (Prepare for Change)
The Continuing Evolution of Tax Law, at Home and Abroad
Reinsurance commutation 0315
Quest for tax reform-white paper - 8-2014
Form 8300-compliance - smart devine
Faculty workload analysis by Mary Lynn Kudey
Smart devine-act now before its too late-0313-v6
Re engineering-0313-v10
Non profit-role-review-0213
Non profit-9-questions #3 5-2013
How the new asu will impact your organization by christopher niwinski
Cyber risk management-white-paper-v8 (2) 2015
Hiring Household Employees Regulatory Requirements 2015

Recently uploaded (20)

PDF
Introduction to Generative Engine Optimization (GEO)
PDF
Digital Marketing & E-commerce Certificate Glossary.pdf.................
PDF
Keppel_Proposed Divestment of M1 Limited
PDF
Charisse Litchman: A Maverick Making Neurological Care More Accessible
PDF
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
PDF
Booking.com The Global AI Sentiment Report 2025
PPT
Lecture notes on Business Research Methods
PPTX
Astra-Investor- business Presentation (1).pptx
PDF
1911 Gold Corporate Presentation Aug 2025.pdf
DOCX
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
PDF
Solaris Resources Presentation - Corporate August 2025.pdf
PPTX
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
PDF
Module 3 - Functions of the Supervisor - Part 1 - Student Resource (1).pdf
PDF
Tata consultancy services case study shri Sharda college, basrur
PPTX
basic introduction to research chapter 1.pptx
DOCX
Hand book of Entrepreneurship 4 Chapters.docx
PPTX
Slide gioi thieu VietinBank Quy 2 - 2025
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PDF
Blood Collected straight from the donor into a blood bag and mixed with an an...
PDF
Module 2 - Modern Supervison Challenges - Student Resource.pdf
Introduction to Generative Engine Optimization (GEO)
Digital Marketing & E-commerce Certificate Glossary.pdf.................
Keppel_Proposed Divestment of M1 Limited
Charisse Litchman: A Maverick Making Neurological Care More Accessible
Nante Industrial Plug Factory: Engineering Quality for Modern Power Applications
Booking.com The Global AI Sentiment Report 2025
Lecture notes on Business Research Methods
Astra-Investor- business Presentation (1).pptx
1911 Gold Corporate Presentation Aug 2025.pdf
Handbook of Entrepreneurship- Chapter 5: Identifying business opportunity.docx
Solaris Resources Presentation - Corporate August 2025.pdf
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
Module 3 - Functions of the Supervisor - Part 1 - Student Resource (1).pdf
Tata consultancy services case study shri Sharda college, basrur
basic introduction to research chapter 1.pptx
Hand book of Entrepreneurship 4 Chapters.docx
Slide gioi thieu VietinBank Quy 2 - 2025
2025 Product Deck V1.0.pptxCATALOGTCLCIA
Blood Collected straight from the donor into a blood bag and mixed with an an...
Module 2 - Modern Supervison Challenges - Student Resource.pdf

Gaining assurance over 3rd party soc 1 and soc 2 reporting 7-2014

  • 1. Gaining Assurance Over Third Party Processors – SOC 1 & SOC 2 Reporting
  • 2. Gaining Assurance Over Third Party Processors – SOC 1 & SOC 2 Reporting DEMANDS FOR ASSURANCE OVER THIRD PARTY PROCESSORS Third party processing organizations spanning a variety of business sectors including distribution, financial services, technology, life sciences, services and healthcare are being requested by their custom- ers (a.k.a., user organizations) to obtain an assurance report on controls related to the integrity of certain processes and security over sensitive information being handled by those third parties. Many user organizations realize that while they have outsourced certain aspects of their business, they continue to be responsible for the activities conduct- ed by the third party processing organization. A good deal of this concern has been driven by regulations and standards such as HIPAA, HITECH, the GLB Act, the Meaningful Use standards of the Centers for Medicare and Medicaid Services (CMS), and others including various State and International privacy laws. THE EVOLUTION OF SOC 1 AND SOC 2 Statements on Standards for Attestation Engage- ments No. 16 (SSAE 16) is an update to the previous standard, known as Statement on Auditing Standards No. 70 (a.k.a., SAS 70) created in the early ‘90s by the American Institute of Certified Public Accountants (AICPA) in which an auditor would provide assurance regarding specified control objectives over process- es related to financial reporting. Service Organization Control No. 1 (SOC 1) reports are conducted using SSAE 16. AT Section 101 was developed in 2001 by the AICPA to place requirements for CPAs examining and issuing reports on controls over matters not related to financial reporting. These requirements are codified within AT Section 101, Attest Engagements, of the AICPA’s attestation standards. Reports issued under AT 101 often utilize the AICPA’s Trust Services Prin- ciples which relate to security, availability, processing integrity, confidentiality and privacy. Lately, many of the audits issued under AT-101 that are gaining prominence in the market place include Service Organization Controls No. 2 (SOC 2) and Service Organization Controls No. 3 (SOC 3) reports. Each of the five Trust Services Principles is supported by dozens of Criteria and third party processors may choose to comply with either one, several, or all five principles. © 2014 SMART DEVINE; All rights reserved. TRUST SERVICES PRINCIPLES OVERVIEW SECURITY The system is protected, both logically and physi- cally, against unauthorized access. AVAILABILITY The system is available for operation and use as committed or agreed to. PROCESSING INTEGRITY The system processing is complete, accurate, timely, and authorized. CONFIDENTIALITY Information that is designed “confidential” is protected as committed or agreed. PRIVACY Personal information is collected, used, retained, and disclosed in conformity with the commitments in the entity’s privacy notice and with the privacy principles put forth by the American Institute of Certified Public Accountants (AICPA) and the Canadian Institute of Chartered Accountants (CICA).
  • 3. smartdevine.com 267-670-7300 © 2014 SMART DEVINE; All rights reserved. REVISIONS TO SOC 2 STANDARD In February 2014 the AICPA issued a revision to the Trust Services Principles and Criteria for a few reasons: • Increase the clarity of certain criteria; • Eliminate redundancy amongst the criteria; and • Update the criteria based upon the changing technology and business environment as the original Trust Service Principles were derived from the SysTrust principles and criteria. The AICPA’s Assurance Services Executive Com- mittee (ASEC) is responsible for changes to the updated Standard. The following is a brief summary of the AICPA’s changes. Common Criteria: ASEC has created “common cri- teria” that represent criteria that are applicable to four of the five principles, namely Security, Confidentiality, Availability and Processing Integrity. A number of third party processing organizations have cited overlap- ping criteria across four of the five principles within the previous Standard, and the associated inefficiency. The Common Criteria constitutes the complete set of criteria for the Security Principle and is organized into seven categories following the key concepts of the Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework, including: • Organization and Management • Communications • Monitoring of Controls • Risk Management and Design and Implementation of Controls • Logical & Physical Controls • System Operations • Change Management Separate Criteria: for the principles of Availability, Processing Integrity, and Confidentiality, a complete set of criteria is comprised of all of the Common Cri- teria and all of the criteria applicable to the princi- ple being reported upon. For instance, the updated Standard indicates the principle of Availability has three unique criteria; Processing Integrity has six unique criteria; and Confidentiality also has six unique criteria. Privacy Principle: The Privacy principle will remain distinct and is being revised by a separate task force. An exposure draft has not been created related to Privacy, at this time. Risk Assessment: The updated Standard em- phasizes an assessment of risks that any particular criteria will not be met. Illustrative examples of criteria and controls, and their corresponding risks has been included in the updated standard. The AICPA has indicated the new reporting Standard will go into effect for periods ending after December 15, 2014, however earlier implementation is permitted.
  • 4. smartdevine.com 267-670-7300 A c c o u n t i n g T a x A d v i s o r y Smart Devine provides a full range of accounting, advisory, tax and investigative forensic and litigation services to organizations across a variety of industries. Smart Devine | 1600 Market Street | 32nd Floor | Philadelphia, PA 19103 | T 267-670-7300 | info@smartdevine.com © 2014 SMART DEVINE; All rights reserved. SMART DEVINE OFFERS A FULL LINE OF SOLUTIONS INCLUDING: ACCOUNTING & AUDIT • Audit, Reviews & Compilation • Accounting & Tax Due Diligence • Accounting Outsourcing • Agreed Upon Procedures • Business Valuation • Finance Process & Reporting Optimization • Forecasts and Projections • Forensic Accounting & Litigation Support • Internal Control Study & Evaluation • Personal Financial Statements • Retirement Plan Audits & Prep • Trust Accounting • SEC Advisory Services • Special Project Coordination & Support • Technical Accounting Consulting • Transaction Advisory Services • SSAE 16/SOC 1 and SOC 2 Reviews RISK SERVICES • Corporate Governance Regulatory Compliance • Enterprise Risk Management • Business Risk Assessment • IT Risk Assessment • Internal Audit Services • IT Internal Auditing • Internal Audit Transformation • Quality Assessment Reviews • Sarbanes Oxley/Model Audit Rule/NAIC Compliance • SSAE 16/SOC 1 and SOC 2 Readiness Assessments TAX • Tax Return Compliance • Accounting for Income Taxes • ASC 740 (FAS 109) Tax Provision Services • International Taxation • IC-DISC • Tax Planning and Advisory • Tax Controversy • Transfer Pricing • Research and Development Tax Credit • State and Local Taxation BUSINESS ADVISORY • Financial Advisory • Management Consulting Services • Technology Consulting Services INSURANCE ADVISORY SERVICES • Accounting • Reviews • Claims Services • Underwriting/Premium • Forensic Accounting FORENSIC AND LITIGATION SERVICES • Litigation Services • Environmental Litigation • Forensic Investigations • Trustee & Monitoring Services • Digital Forensics & eDiscovery For more information, please contact John McLaughlin, Managing Director at 610-994-1534 or jmclaughlin@smartdevine.com