Financial reporting assurance
Prepare controls relevant to customers’ financial reporting.
SOC 1 addresses controls at a service organization that may be relevant to user entities’ internal control over financial reporting. We help providers define the service, identify relevant control objectives, operate controls, and prepare for an independent CPA examination.
Our implementation focus
Make the requirements operational.
- 01
Determine whether buyer requests call for SOC 1
- 02
Define the service system and financial reporting interfaces
- 03
Design and assign relevant control objectives
- 04
Operate controls and collect evidence
- 05
Prepare management’s description and examiner handoff
SOC 1 produces an independent CPA attestation report, not a certification. Normstone provides readiness advisory and does not issue the report.
Questions we hear
Get the distinctions right.
When is SOC 1 more relevant than SOC 2?
SOC 1 is relevant when the service can affect customers’ internal control over financial reporting. SOC 2 addresses controls relevant to security and other selected Trust Services Criteria.
Does Normstone issue SOC 1 reports?
No. An independent licensed CPA firm performs the examination and issues the report.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.