SOC Communication & Stakeholder Relations 2 — Questions and Answers
Question 1: Under SOC 2, which section of the report is specifically dedicated to communicating the service organization's description of its system?
- Section I – Auditor's Opinion
- Section II – Management's Description (Correct answer)
- Section III – Trust Services Criteria
- Section IV – Complementary Controls
Correct answer: Section II – Management's Description
Section II of a SOC 2 report contains management's written description of the service organization's system, including its boundaries and controls.
Question 2: A user entity receives a SOC 2 Type II report but cannot share it with its own customers due to confidentiality restrictions. What is the most appropriate way to address stakeholder inquiries?
- Ignore inquiries until the restriction is lifted
- Provide a summary of key findings without distributing the full report (Correct answer)
- Share the full report since it is already publicly available
- Refer all stakeholders directly to the service auditor
Correct answer: Provide a summary of key findings without distributing the full report
User entities may share summarized conclusions or relevant excerpts while honoring the confidential distribution restrictions common to SOC 2 reports.
Question 3: Which stakeholder group is the PRIMARY intended audience for a SOC 1 report?
- General public investors
- User entities and their financial statement auditors (Correct answer)
- Regulatory bodies such as the SEC
- The service organization's internal audit committee
Correct answer: User entities and their financial statement auditors
SOC 1 reports are designed for user entities and their financial auditors who need to understand controls relevant to financial reporting.
Question 4: During a SOC examination, the service auditor identifies a gap between how management describes a control and how it actually operates. How should this be communicated?
- Omit the discrepancy to avoid alarming stakeholders
- Note the gap in the management representation letter only
- Include a qualified or adverse opinion in the auditor's report (Correct answer)
- Communicate only to the board without documenting in the report
Correct answer: Include a qualified or adverse opinion in the auditor's report
A material discrepancy between the description and actual control operation would result in a qualified or adverse opinion communicated formally in the auditor's report.
Question 5: What is a 'bridge letter' in the context of SOC reporting stakeholder communications?
- A letter from the regulator authorizing the SOC audit
- A written update from the service organization covering the period after the report's end date (Correct answer)
- A summary letter sent to subservice organizations
- An introductory letter attached to every SOC 2 report
Correct answer: A written update from the service organization covering the period after the report's end date
A bridge letter (also called a gap letter) is issued by the service organization to update stakeholders on any material changes in controls after the SOC report period ends.
Question 6: Which of the following BEST describes complementary user entity controls (CUECs) in a SOC 2 report?
- Controls the auditor adds to strengthen the service organization's environment
- Controls the user entity must implement for the service organization's controls to be effective (Correct answer)
- Optional controls suggested by the AICPA for advanced SOC compliance
- Automated controls built into the service organization's platform
Correct answer: Controls the user entity must implement for the service organization's controls to be effective
CUECs are controls that the service organization assumes the user entity has in place; without them, the service organization's controls alone cannot achieve the stated control objectives.
Question 7: A prospective customer asks a service organization to share its SOC 3 report. Which statement BEST describes the appropriate response?
- Decline since SOC 3 reports are classified
- Share the SOC 3 report freely, as it is intended for general use (Correct answer)
- Provide only the management assertion section of the SOC 3
- Require the customer to sign an NDA before sharing the SOC 3
Correct answer: Share the SOC 3 report freely, as it is intended for general use
SOC 3 reports are general-use reports that may be freely distributed to any interested party, including prospective customers.
Under SOC 2, which section of the report is specifically dedicated to communicating the service organization's description of its system?