Complementary User Entity Controls, Explained

Complementary User Entity Controls, Explained

Somewhere in the middle of almost every SOC report there is a table that readers skim past on their way to the test results. It lists things the customer is expected to do. Those are complementary user entity controls, and they are the part of the report that quietly...
When Your Client’s Auditor Asks for a SOC 1

When Your Client’s Auditor Asks for a SOC 1

If an email lands from your customer’s external auditor asking for your SOC 1 report, something specific has happened: they have concluded that your service is part of their client’s internal control over financial reporting, and they cannot audit what...