SOC Quality Assurance & Improvement 2 — Questions and Answers
Question 1: Which SOC 2 principle requires that a service organization's controls operate effectively over the entire review period rather than just at a point in time?
- Point-in-time attestation
- Period-of-time (Type 2) reporting (Correct answer)
- Bridge letter coverage
- Complementary user entity controls
Correct answer: Period-of-time (Type 2) reporting
SOC 2 Type 2 reports cover a defined period (typically 6–12 months), requiring controls to operate effectively throughout that window.
Question 2: A quality assurance reviewer finds that a control was performed correctly but not documented. Under SOC standards, how should this be treated?
- Acceptable if verbal confirmation is obtained
- A control deficiency because undocumented controls cannot be tested (Correct answer)
- Immaterial if the control category is low-risk
- Resolved by retroactively creating documentation
Correct answer: A control deficiency because undocumented controls cannot be tested
SOC auditors rely on evidence; if a control leaves no documentation trail it cannot be tested, making it a control deficiency regardless of intent.
Question 3: What is the primary purpose of a management assertion in a SOC 1 report?
- To summarize user entity responsibilities
- To confirm the service auditor's independence
- To state that the description of the system and controls is fairly presented (Correct answer)
- To list all subservice organizations used
Correct answer: To state that the description of the system and controls is fairly presented
Management's assertion in a SOC 1 report attests that the system description is fairly presented and that controls were suitably designed and, in Type 2, operated effectively.
Question 4: During a SOC engagement, the service auditor identifies a deviation rate of 8% for a key control against an expected rate of 3%. What is the most appropriate next step?
- Ignore it if no customer complaints were received
- Accept the control as effective because most samples passed
- Evaluate whether the deviation rate constitutes a significant deficiency or material weakness (Correct answer)
- Immediately issue an adverse opinion
Correct answer: Evaluate whether the deviation rate constitutes a significant deficiency or material weakness
An unexpected deviation rate requires the auditor to evaluate severity—whether it rises to a significant deficiency or material weakness—before determining the opinion.
Question 5: Which concept best describes the process of identifying improvements to controls based on lessons learned from prior SOC audit cycles?
- Root cause analysis and remediation tracking (Correct answer)
- Complementary subservice organization controls
- Carve-out vs. inclusive method selection
- Trust Services Criteria mapping
Correct answer: Root cause analysis and remediation tracking
Root cause analysis paired with remediation tracking is the cornerstone QA improvement process, addressing why deficiencies occurred and preventing recurrence.
Question 6: A SOC 2 engagement covers the Availability category. Which metric would most directly evidence continuous improvement in availability controls?
- Number of new employees hired in IT
- Trend analysis showing declining unplanned downtime over successive periods (Correct answer)
- Size of the disaster recovery plan document
- Frequency of user access reviews
Correct answer: Trend analysis showing declining unplanned downtime over successive periods
Trend data showing declining unplanned downtime demonstrates that availability controls are improving in effectiveness over time.
Question 7: In the context of SOC engagements, a 'bridge letter' is used to:
- Connect the service auditor and the user auditor via formal protocol
- Extend coverage assurance from the SOC report end date to the user entity's fiscal year end (Correct answer)
- Replace a SOC report when deadlines are missed
- Document the carve-out of subservice organization controls
Correct answer: Extend coverage assurance from the SOC report end date to the user entity's fiscal year end
A bridge letter (also called a gap letter) provides management's representation that no significant changes to controls occurred between the SOC report end date and the user entity's audit date.
Which SOC 2 principle requires that a service organization's controls operate effectively over the entire review period rather than just at a point in time?