SOC Risk and Control Objectives 2 — Questions and Answers
Question 1: Which SOC 2 Trust Services Criterion requires an entity to identify and assess risks that could prevent it from achieving its objectives?
- CC6.1
- CC3.1 (Correct answer)
- CC5.2
- CC7.3
Correct answer: CC3.1
CC3.1 requires management to identify and analyze risks to the achievement of objectives as part of the COSO risk assessment component.
Question 2: In the context of SOC 2 risk assessment, what does 'risk tolerance' refer to?
- The maximum financial loss an entity can absorb
- The acceptable level of variation in performance relative to achieving an objective (Correct answer)
- The number of control failures permitted per year
- The percentage of systems allowed to be unpatched
Correct answer: The acceptable level of variation in performance relative to achieving an objective
Risk tolerance is the acceptable level of variation in performance relative to the achievement of objectives, as defined under COSO principles.
Question 3: A SOC 2 auditor finds that an organization has no formal process for identifying new risks when business objectives change. Which control objective is most directly unmet?
- Monitoring of controls
- Risk identification linked to objective changes (Correct answer)
- Logical access provisioning
- Incident response procedures
Correct answer: Risk identification linked to objective changes
CC3.1 requires that risk identification processes respond to changes in objectives, making this a direct gap in the risk assessment control objective.
Question 4: Under SOC 1 (SSAE 18), what is the primary purpose of a complementary user entity control (CUEC)?
- To replace the service organization's controls entirely
- To document controls that user entities must implement for the service organization's controls to be effective (Correct answer)
- To provide additional testing procedures for the auditor
- To describe subservice organization responsibilities
Correct answer: To document controls that user entities must implement for the service organization's controls to be effective
CUECs identify controls that user entities are responsible for implementing so that the service organization's control objectives are fully achieved.
Question 5: Which of the following best describes a 'residual risk' in a SOC audit context?
- The risk that remains after controls have been applied (Correct answer)
- The initial risk before any mitigation is considered
- The risk transferred to a third-party vendor
- The risk documented in the system description but not tested
Correct answer: The risk that remains after controls have been applied
Residual risk is the remaining level of risk after management has applied controls or other risk responses.
Question 6: When assessing fraud risk under SOC 2, which COSO component does the service organization primarily address?
- Control Environment
- Risk Assessment (Correct answer)
- Information and Communication
- Monitoring Activities
Correct answer: Risk Assessment
Fraud risk assessment falls under the COSO Risk Assessment component, specifically the requirement to consider fraud in the risk identification process.
Question 7: A service organization outsources its data center operations to a subservice organization. Under the carve-out method, how are the subservice organization's controls treated in the SOC report?
- They are fully tested and included in the report
- They are excluded from the report scope and description
- They are included in the description but not tested by the service auditor (Correct answer)
- They are replaced by complementary user entity controls
Correct answer: They are included in the description but not tested by the service auditor
Under the carve-out method, the subservice organization's services are described but its controls are excluded from the scope of the service auditor's testing.
Which SOC 2 Trust Services Criterion requires an entity to identify and assess risks that could prevent it from achieving its objectives?