SOC Examinations

SOC 1, SOC 2, and SOC 3 attestation.

System and Organization Controls examinations under AICPA SSAE 18, issued for service organizations under our Colorado CPA license.

7.1

SOC 1 examinations

Examinations of controls at a service organization relevant to user entities' internal control over financial reporting, under AT-C 320. Issued as Type I (design, as of a point in time) or Type II (design and operating effectiveness, over a review period, typically six or twelve months).

Common for payroll processors, fund administrators, loan servicers, and SaaS platforms handling financial transactions on behalf of clients. The report includes management's description of the system, the service auditor's opinion, and — for Type II — a detailed schedule of controls tested and results, giving user auditors what they need to rely on the report for their own audits.

7.2

SOC 2 examinations

Examinations against the AICPA Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy — under AT-C 105 and AT-C 205. Issued as Type I or Type II, scoped to the criteria relevant to the service being reported on; security is mandatory, the other four are selected based on the nature of the service.

Engagements begin with a scoping exercise to confirm system boundaries and applicable criteria, followed by control design walkthroughs, evidence collection, and — for Type II — testing of operating effectiveness across the review period. Deliverables include the system description, management assertion, and the service auditor's report with test results.

7.3

SOC 3 examinations

A general-use report derived from the SOC 2 examination, presenting the auditor's opinion without the detailed description of tests and results — suitable for public distribution, marketing, and website publication. A SOC 3 report can only be issued alongside or following a SOC 2 examination covering the same period; it is not a lighter-weight standalone alternative.

7.4

Readiness assessments & bridge letters

Pre-examination readiness assessments to identify control gaps before the formal engagement begins — typically run as a gap analysis against the target Trust Services Criteria or the SOC 1 control objectives, with remediation recommendations before fieldwork is scheduled.

Bridge letters cover the period between a prior SOC report's end date and a client's fiscal year end, confirming to user entities and their auditors that no material changes occurred to the control environment in the gap period.