Several new system and organization controls (SOC) 2 tools on the market are designed to help improve the SOC 2 examination experience for service organizations. These platforms offer a new breadth of functionality and scope. According to the Association of International Certified Professional Accountants (the Association), use of this type of SOC 2 tool might affect how the service auditor meets relevant requirements of the attestation standards.
Provider offerings can vary greatly, so if you’re considering adopting a compliance software program to assist in compliance efforts, it’s critical to thoroughly evaluate potential vendors as well as their capabilities and limitations.
While some compliance programs can increase efficiency and organization, others could add complexities and examination responsibilities for the service organization and the auditor.
Here, we discuss key considerations—including software benefits, limitations, selection criteria, and associated responsibilities—to keep in mind when evaluating compliance software options. To learn more about SOC examinations, see our SOC report guide.
The right SOC 2 tool could help your service organization streamline its preparation for its first SOC 2 audit or execution of annual subsequent SOC 2 audits, which could result in time and cost savings.
Quality programs will allow your organization to:
Compliance platforms are part of an emerging market that has significant potential. However, it’s presently limited in its capabilities. While certain compliance platforms can be used to support aspects of an organization’s SOC 2 examination, it’s essential to understand where limitations exist.
Evaluate the following to identify potential limitations:
For these reasons, it’s important to not let the use of compliance software create a false sense of confidence in controls or processes that may not be designed securely—especially in situations where the service organizations rely on the SOC 2 tool provider and don’t understand their control design and implementation.
For auditors, SOC 2 tools can force reliance on their integrations between the compliance platform and software commonly utilized by the organizations—regardless of the quality of their own SOC 2 report or validation of the completeness and accuracy of the data pulled via the integration.
To make an informed decision and select a compliance software that’s right for your organization, be sure to:
Since the functionality and scope of the current compliance software available on the market vary considerably by the vendor, you can use the following to help with your evaluation:
Understanding the provider’s limitations up front can prevent additional complexity resulting in increased overhead for staff to care for and maintain the product.
If you decide to proceed with a SOC 2 tool, there are additional responsibilities for the service organization and its auditors to keep in mind to increase adoption and help avoid common implementation pain points.
To help prevent your organization from placing excess reliance on the SOC 2 tool and its results, properly balance your organization’s responsibilities with the capabilities of the program by doing the following:
Unfortunately, SOC 2 tools don’t lessen the responsibilities of the service auditor as defined in the SOC 2 Guide and professional standards. As an auditor, it’s essential to still:
To learn more about SOC examinations explore our on-demand webcasts or contact your Moss Adams professional.
To learn more about this new market for SOC 2 tools or for questions about your SOC 2 examination process, please contact your Moss Adams professional.
Baker Tilly US, LLP, Baker Tilly Advisory Group, LP and Moss Adams LLP and their affiliated entities operate under an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations and professional standards. Baker Tilly Advisory Group, LP and its subsidiaries, and Baker Tilly US, LLP and its affiliated entities, trading as Baker Tilly, are members of the global network of Baker Tilly International Ltd., the members of which are separate and independent legal entities. Baker Tilly US, LLP and Moss Adams LLP are licensed CPA firms that provide assurance services to their clients. Baker Tilly Advisory Group, LP and its subsidiary entities provide tax and consulting services to their clients and are not licensed CPA firms. ISO certification services offered through Moss Adams Certifications LLC. Investment advisory offered through either Moss Adams Wealth Advisors LLC or Baker Tilly Wealth Management, LLC.