If an email lands from your customer’s external auditor asking for your SOC 1 report, something specific has happened: they have concluded that your service is part of their client’s internal control over financial reporting, and they cannot audit what they cannot see.

That framing matters, because it tells you what they need and what they do not. They are not running a security review. They are trying to get comfortable that transactions flowing through your platform into their client’s financial statements are complete, accurate, authorized and properly recorded. A SOC 1 report is the standard instrument for giving them that comfort without sending an audit team to your office.

Why they are asking you and not their client

Under the audit standards their profession works to, an auditor must understand the components of internal control relevant to the audit — including relevant controls performed by service organizations. When a company outsources payroll, claims processing, payment handling, loan servicing or a core piece of transaction processing, some of those controls now live at the service provider.

The user auditor has three options. They can rely on controls their client performs over your output — reconciliations, review of exception reports, independent recalculation — and test those instead. They can come and test your controls directly. Or they can obtain a SOC 1 report from an independent service auditor and evaluate that.

The third option is why they wrote to you. It is also the cheapest option for everyone involved, which is worth remembering when the request feels like an imposition.

The four questions to ask before you scope anything

1. Which of our services do you consider in scope?

You may deliver five things and only one of them touches their client’s financial statements. Getting this answer narrows the examination considerably, and getting it in writing prevents an argument later.

2. What is your client’s fiscal year end?

This is the deadline that actually governs. A SOC 1 Type 2 covering a period that does not align with their audit period is much less useful to them. Most service organizations issuing SOC 1s pick a period ending a few months before the typical year end of their customer base, then cover the remainder with a bridge letter.

3. Type 1 or Type 2?

A Type 1 addresses whether your control objectives are fairly stated and controls suitably designed as of a date. A Type 2 adds whether they operated effectively over a period, and includes the auditor’s tests and results. If the user auditor intends to place reliance on your controls to reduce their own substantive testing, they will generally need a Type 2 — design alone tells them nothing about whether the control ran. Ask them directly rather than guessing.

4. Which financial statement assertions are you concerned with?

Completeness, accuracy, existence, valuation, cut-off. Their answer shapes your control objectives more than anything else. An auditor concerned with cut-off cares intensely about the timing of transaction capture; one concerned with valuation cares about your calculation logic.

Control objectives are yours to write, and that is the hard part

Unlike a SOC 2, a SOC 1 has no standard criteria to work from. Management defines the control objectives, and the service auditor examines whether they are fairly stated, whether controls are suitably designed to achieve them, and — in a Type 2 — whether they operated.

The discipline is to work backwards from what could go wrong in the user entity’s financial statements. For a payroll processor: pay rates and deductions are set up completely and accurately based on authorized input; payroll calculations are accurate; payments are made to the correct recipients in the correct period; changes to master data are authorized.

Two failure modes are common. Objectives written too narrowly leave the user auditor unable to rely on the report, and you will hear about it. Objectives written too broadly commit you to controls you cannot consistently evidence, which produces exceptions.

Supporting all of this sits your IT general controls — access, change management, operations — because a well-designed transaction control means little if someone can alter the processing logic without approval.

Complementary user entity controls are not a dumping ground

Every SOC 1 lists complementary user entity controls: things the user entity must do for your control objectives to be achieved. Reviewing output reports, submitting authorized input, maintaining their own user access lists, reconciling your reports to their records.

These are legitimate and necessary. They are also occasionally abused, and experienced user auditors notice. If your CUEC list transfers responsibility for everything that could go wrong onto your customers, the report loses credibility and the auditor may decide they cannot place much reliance on it.

Write CUECs as things the customer genuinely must do, then tell your customers about them. A CUEC nobody at the user entity knows exists is a control that is not operating.

Timing, bridge letters and the gap period

Your report period will rarely end exactly on your customer’s fiscal year end, and you will have many customers with different year ends. The usual approach is to pick a consistent annual period and cover the tail with a bridge letter — a signed management statement that no material changes to the control environment occurred between the end of the examination period and a later date.

A bridge letter is a representation from you, not an auditor’s opinion, and there is no examination behind it. User auditors know this. Practice varies on how long a gap they will accept; a short gap is routinely fine, a long one usually is not, and the only way to know is to ask.

If you do not have a SOC 1 yet

Say so plainly, and quickly. The user auditor has an audit to finish and needs to plan an alternative, which usually means either testing your controls directly under an agreed arrangement, or their client performing more work on your output.

Neither is a disaster, but both consume time from people who did not budget for it. Being straightforward in week one is far better than being vague until week six.

Then decide whether to build the report. If one customer asks, it may not be worth it. If three ask in a year, or if you are selling into companies that get audited routinely, the SOC 1 stops being an expense and starts being a sales asset — because the next prospect’s auditor will ask too.

What to do next

Reply to the auditor with the four questions above. Ask specifically which services they consider in scope and whether they need a Type 2. Copy your customer’s finance contact, because the commercial relationship is with them and they should know the request exists.

Then look at your own transaction processing and ask what could go wrong that would land in someone else’s financial statements. That list is the first draft of your control objectives. Assurion is a licensed CPA firm and performs SOC 1 examinations; if you are being asked for one for the first time, the scoping conversation is the part worth getting right.