How long does it take to get a SOC Report?

How long does it take to get a SOC Report?

Posted on

SOC COMPLIANCE

By Scott M. McAuliffe, CPA, CISA, CFE | Risk Advisory Services Partner

Part 2 of a 4 Part Series on SOC Reporting

Service Organizations May Not Be Ready For the SOC Report Examination Process.

Once a service organization has determined the type of SOC report that is appropriate for the services it provides, the next question that a service organization executive asks, is how long will it take to get the report? In most cases, the service organization is not be ready to immediately go through the SOC report examination process. To determine if your service organization is ready, you need to ask the following:

  • For the services that you provide to customers, are your processes, systems, and controls thoroughly documented?
  • How strong are your entity-level controls? Do you have a Code of Conduct? Do you perform background checks, have job descriptions, and provide adequate training to employees? Do you conduct risk assessments?
  • Do you have controls in place to monitor the service organizations that you use and rely upon as part of the services you provide to your customers?
  • Do you maintain support for your controls so that they can be tested? For instance, are you aware of any reviews/approvals that are not documented (e.g., an approval that is provided verbally or not specifically notated or maintained)?
  • Are your controls consistently performed? For example, for every change to a user’s access is there a properly approved user access request form or in certain cases when time does not permit or the approver is out of the office, was the request processed without the approval to keep the business going?

Performing A Readiness Assessment

In most cases, a service provider will answer yes to most or all of these questions. As a result, the majority of service organization going through the SOC process for the first time will want to have a Readiness Assessment performed. During a Readiness Assessment, a CPA firm or other competent consultant will assist the service provider with documenting its processes, systems, and controls, as well as perform a gap analysis to determine if there are missing controls or controls do not seem to be operating consistently. Depending on the scope and complexity of the organization, the Readiness Assessment process can take from a couple of weeks to several months.

Once the Readiness Assessment is completed, the service organization will need to remediate any control gaps prior to starting the SOC report examination process. Depending on the service provider, it can take weeks to months to remediate these gaps depending on its resources, motivation (how hard customers are pressuring for the report), and complexity/severity of the gaps.

As one can see, a service organization will need to plan ahead when seeking to obtain a SOC report to provide it with adequate time to go through a readiness assessment process and remediate any gaps.


Are you considering a SOC report and need help with the Readiness Assessment? Keiter’s Risk Advisory Services team can help you.

Access all of our articles in our SOC Reporting series


About the Author

Scott leads the Firm’s Risk Advisory Services practice, which focuses on providing cybersecurity services, internal audits, information technology audits, Service Organization Control (SOC) audits, and Sarbanes-Oxley assistance. Scott focuses on providing his clients with cost effective solutions to build strong, efficient internal control systems/practices that support their strategic objectives. Read more of Scott’s insights on our blog.

More Insights from Scott M. McAuliffe, CPA, CISA, CFE


The information contained within this article is provided for informational purposes only and is current as of the date published. Online readers are advised not to act upon this information without seeking the service of a professional accountant, as this article is not a substitute for obtaining accounting, tax, or financial advice from a professional accountant.

Contact

How Can We Help You and Your Business?

Innsbrook Corporate Center
4401 Dominion Boulevard
Glen Allen, Virginia 23060

804.747.0000 or 804.273.6200

Directions