SOC Reporting Frameworks and Standards 3 — Questions and Answers
Question 1: Under the carve-out method for subservice organizations in a SOC report, the service auditor:
- Tests the subservice organization's controls directly
- Includes the subservice organization's controls in scope and tests them
- Excludes subservice organization controls from the scope and notes their existence (Correct answer)
- Requires the subservice organization to obtain its own SOC report
Correct answer: Excludes subservice organization controls from the scope and notes their existence
Under the carve-out method, the service auditor excludes the subservice organization's controls from the scope of the engagement, only describing their existence.
Question 2: The SOC for Cybersecurity report is based on which criteria developed by the AICPA?
- Trust Services Criteria
- Cybersecurity Risk Management Reporting Framework (Correct answer)
- NIST Cybersecurity Framework
- ISO/IEC 27001 Annex A
Correct answer: Cybersecurity Risk Management Reporting Framework
The SOC for Cybersecurity engagement uses the AICPA's Cybersecurity Risk Management Reporting Framework as the criteria for evaluating an entity's cybersecurity risk management program.
Question 3: Which of the following best describes a 'qualified' opinion in a SOC report?
- The auditor found no exceptions during testing
- The auditor found material exceptions in one or more control areas (Correct answer)
- The auditor was unable to complete testing
- The report is limited to a specific time period
Correct answer: The auditor found material exceptions in one or more control areas
A qualified opinion indicates that, except for noted exceptions or deviations, the controls are suitably designed and/or operating effectively.
Question 4: Which Trust Services Criteria category is MANDATORY for every SOC 2 engagement?
- Availability
- Processing Integrity
- Security (Common Criteria) (Correct answer)
- Confidentiality
Correct answer: Security (Common Criteria)
Security, defined using the Common Criteria, is the only required category in a SOC 2 engagement; all other categories are optional based on the service commitments.
Question 5: A SOC 3 report differs from a SOC 2 report primarily because the SOC 3:
- Covers financial reporting controls instead of Trust Services Criteria
- Can be freely distributed to the public without restriction (Correct answer)
- Requires testing over a minimum 12-month period
- Includes detailed descriptions of the service auditor's tests and results
Correct answer: Can be freely distributed to the public without restriction
SOC 3 reports are general-use reports that can be freely distributed and posted publicly, unlike restricted-use SOC 2 reports.
Question 6: In the context of SOC reporting, the 'description criteria' established by the AICPA for SOC 2 engagements refers to:
- The criteria against which the auditor evaluates control effectiveness
- The standards management must use when describing the service organization's system (Correct answer)
- The format requirements for the auditor's opinion letter
- The minimum period the SOC 2 Type II must cover
Correct answer: The standards management must use when describing the service organization's system
Description criteria (DC Section 200) define the elements management must include when preparing the description of the service organization's system in a SOC 2 report.
Question 7: When a SOC 2 report uses the 'inclusive method' for subservice organizations, what is the service auditor's responsibility?
- Issue a separate SOC report for the subservice organization only
- Extend audit procedures to include testing of subservice organization controls (Correct answer)
- Accept the subservice organization's own SOC report as audit evidence
- Carve out the subservice organization's controls from the description
Correct answer: Extend audit procedures to include testing of subservice organization controls
Under the inclusive method, the service auditor's procedures extend to include the subservice organization's controls within the scope of the engagement.
Under the carve-out method for subservice organizations in a SOC report, the service auditor: