The basics, in plain language.
Short answers to the questions clients most often ask before an engagement, what SOC reports are, the difference between Type 1 and Type 2, what ITGC means, and the cloud security standards auditors use.
SOC 1, SOC 2 and SOC 3, what they are.
SOC stands for System and Organization Controls. These are independent assurance reports issued by a CPA firm about the controls operating at a service organisation. The right report depends on what your customers care about, financial reporting impact, or security and trust.
The difference between Type 1 and Type 2.
Both SOC 1 and SOC 2 come in two flavours, Type 1 and Type 2. The names sound similar but the assurance value is very different.
Information systems and IT general controls.
ITGC and IS audit are foundational concepts in any technology-heavy audit, whether it is part of a financial statement audit, a SOC engagement, or an internal audit.
Cloud security and CIS Benchmarks.
Most modern audits include a cloud component, AWS, Azure, or Google Cloud. The questions below explain the standards used to evaluate cloud configurations.
Readiness and process basics.
How engagements are typically scoped, sequenced, and delivered.
Talk it through with a Chartered Accountant.
If you are evaluating whether you need a SOC report, scoping an ITGC review, or planning a cloud security assessment, a short call is usually the fastest way to clarity.