When an organization relies on a service provider such as a payroll processor, cloud host or data center, it usually cannot audit that provider's controls itself. It would be impractical for thousands of customers to send auditors to the same provider. Instead, the provider engages an independent auditor to evaluate its controls and issue a report that customers can rely on. These are System and Organization Controls (SOC) reports, issued by certified public accountants under attestation standards from the American Institute of Certified Public Accountants (AICPA). Internationally, a similar attestation exists under the ISAE 3402 standard. The exam focuses on the three SOC report types and on Type I versus Type II.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.