SOC Quality Assurance & Improvement 3 — Questions and Answers
Question 1: Under the AICPA's Trust Services Criteria, which category addresses the accuracy and completeness of information processed by a system?
- Availability
- Confidentiality
- Processing Integrity (Correct answer)
- Privacy
Correct answer: Processing Integrity
Processing Integrity ensures that system processing is complete, valid, accurate, timely, and authorized.
Question 2: A SOC 1 report is specifically designed to address controls relevant to:
- A user entity's cybersecurity risk management program
- Internal control over financial reporting at user entities (Correct answer)
- Privacy obligations under GDPR and CCPA
- Environmental, social, and governance disclosures
Correct answer: Internal control over financial reporting at user entities
SOC 1 reports (SSAE 18 AT-C 320) focus on a service organization's controls that may affect user entities' internal control over financial reporting (ICFR).
Question 3: Which quality improvement tool is most commonly used to prioritize deficiencies identified during a SOC readiness assessment?
- Pareto analysis (80/20 rule) (Correct answer)
- Balanced scorecard
- SWOT analysis
- Five Whys only
Correct answer: Pareto analysis (80/20 rule)
Pareto analysis helps teams focus remediation effort on the 20% of deficiencies that account for 80% of risk exposure.
Question 4: When a service organization uses the 'inclusive method' in a SOC report, what does this mean regarding subservice organizations?
- Subservice organizations are excluded and their controls are out of scope
- The subservice organization's controls are included within the scope of the SOC report (Correct answer)
- The primary organization carves out all vendor relationships
- The report covers only logical access controls at the primary site
Correct answer: The subservice organization's controls are included within the scope of the SOC report
Under the inclusive method, the subservice organization's relevant controls are incorporated into the description and tested as part of the engagement.
Question 5: A continuous monitoring program designed to support SOC quality assurance would most likely include which activity?
- Annual penetration tests only
- Real-time alerts and periodic control self-assessments between audit cycles (Correct answer)
- Quarterly rotation of service auditors
- Monthly reissuance of the SOC report
Correct answer: Real-time alerts and periodic control self-assessments between audit cycles
Continuous monitoring uses automated alerts and periodic self-assessments to detect control gaps between formal audit cycles, supporting ongoing quality improvement.
Question 6: Which of the following best characterizes a 'complementary user entity control' (CUEC) in a SOC 2 report?
- A control operated by the service organization on behalf of the user
- A control the user entity must implement for the service organization's controls to be effective (Correct answer)
- An optional enhancement listed in the report appendix
- A control tested solely by the subservice organization
Correct answer: A control the user entity must implement for the service organization's controls to be effective
CUECs are controls that the user entity is responsible for implementing; without them, the service organization's controls alone may not achieve the stated control objectives.
Question 7: During a SOC Type 2 quality review, an auditor discovers that a key automated control failed for three consecutive weeks due to a system outage but was not reported to management. This most likely represents:
- A compensating control that mitigated the risk fully
- A material weakness in the monitoring and communication components of internal control (Correct answer)
- An immaterial deviation because automation generally performs well
- A user entity responsibility, not a service organization issue
Correct answer: A material weakness in the monitoring and communication components of internal control
Failure to communicate a prolonged control failure to management indicates a weakness in both the monitoring and information-and-communication components of the control environment.
Under the AICPA's Trust Services Criteria, which category addresses the accuracy and completeness of information processed by a system?