SOC Project Planning & Execution 2 — Questions and Answers
Question 1: During a SOC 2 audit engagement, which document formally defines the scope, objectives, and boundaries of the project?
- Statement of Applicability
- Project Charter (Correct answer)
- Risk Register
- Service Organization Description
Correct answer: Project Charter
A Project Charter formally authorizes the project and defines its scope, objectives, stakeholders, and high-level constraints.
Question 2: A SOC audit team discovers mid-project that a key third-party vendor is out of scope per the original plan but processes critical data. What is the BEST next step?
- Ignore it since the vendor is out of scope
- Issue a qualified opinion immediately
- Perform a scope change review and obtain stakeholder approval (Correct answer)
- Terminate the engagement
Correct answer: Perform a scope change review and obtain stakeholder approval
A formal scope change review ensures all stakeholders agree on revised boundaries before expanding audit work.
Question 3: Which scheduling technique identifies the longest path of dependent tasks to determine the minimum project duration?
- Gantt Chart Analysis
- Critical Path Method (CPM) (Correct answer)
- Monte Carlo Simulation
- Resource Leveling
Correct answer: Critical Path Method (CPM)
The Critical Path Method identifies the sequence of dependent tasks that determines the shortest possible project completion time.
Question 4: In SOC project execution, a 'control gap' is identified late in the testing phase. Who should be notified FIRST?
- The external regulator
- The engagement partner or project manager (Correct answer)
- The user entities of the service organization
- The AICPA directly
Correct answer: The engagement partner or project manager
Control gaps should be escalated to the engagement partner or project manager first to determine proper handling before broader communication.
Question 5: What does a RACI matrix define in a SOC audit project plan?
- Risk, Assurance, Control, and Impact levels
- Responsible, Accountable, Consulted, and Informed roles (Correct answer)
- Revenue, Audit, Compliance, and Infrastructure domains
- Reporting, Assessment, Certification, and Implementation stages
Correct answer: Responsible, Accountable, Consulted, and Informed roles
A RACI matrix clarifies team roles by defining who is Responsible, Accountable, Consulted, and Informed for each task.
Question 6: During SOC 2 Type II audit planning, what period does the auditor's testing typically cover?
- A single point in time
- A minimum of six months of operational history (Correct answer)
- The prior fiscal year only
- Exactly ninety days
Correct answer: A minimum of six months of operational history
SOC 2 Type II reports cover a period of time, typically a minimum of six months, to assess the operating effectiveness of controls.
Question 7: Which risk response strategy is most appropriate when the cost of mitigating a project risk exceeds the potential impact?
- Avoid
- Transfer
- Accept (Correct answer)
- Escalate
Correct answer: Accept
Risk acceptance is appropriate when the cost or effort of mitigation outweighs the potential negative impact of the risk.
During a SOC 2 audit engagement, which document formally defines the scope, objectives, and boundaries of the project?