Our SOC 1 and SOC 2 audit solutions are ideal for service organisations that need to provide assurance to clients and stakeholders around financial reporting (SOC 1) or the security and integrity of systems and data (SOC 2)
We provide skilled professionals to support your clients through SOC 1 and SOC 2 audit engagements; executed in line with international standards and tailored to the expectations of UK and global markets. Whether your clients require a readiness assessment, a formal assurance engagement, or full audit execution, our outsourced professionals deliver clarity, compliance, and confidence across the entire process.
Outsourced SOC 1 Audits
SOC 1 reports are issued in accordance with SSAE No. 19 in the USA. For organisations operating outside the USA; including the UK; SOC 1 audits are conducted under the ISAE 3402 standard (Assurance Reports on Controls at a Service Organisation), issued by the International Auditing and Assurance Standards Board (IAASB).
Our professionals are familiar with both standards and provide assurance engagements that meet international expectations while aligning with your clients’ local regulatory environments.
Outsourced SOC 2 Audits
A SOC 2 audit evaluates a service organisation’s controls in relation to data security, privacy, and system integrity. These audits are guided by the Trust Services Criteria; a framework developed by the AICPA; covering the following five core principles:
- Security – Protection of systems against unauthorised access
- Availability – System and data availability for authorised users
- Processing Integrity – Accuracy, completeness, and timeliness of processing
- Confidentiality – Protection of sensitive client or proprietary data
- Privacy – Safeguarding of personal information and compliance with privacy regulations
Outside of the US, SOC 2 audits are performed under ISAE 3000, using the Trust Criteria as the audit framework.
Your clients may choose to be assessed on all five trust principles or a customised selection. Our professionals guide organisations through this selection, ensuring the scope aligns with business objectives and stakeholder expectations.
SOC AUDIT
COSO Points of Focus
In addition to the Trust Principles, SOC 2 audits incorporate key COSO components to assess broader governance and risk management practices. These points of focus help organisations evaluate the design and implementation of their control environment.
- Control Environment
- Communication and Information
- Risk Assessment
- Monitoring Activities
- Control Activities
SOC AUDIT
Type I vs Type II Reports
Some organisations begin with a readiness assessment to identify gaps in control design. Once addressed, they may move directly to a Type II report to demonstrate both the adequacy and effectiveness of their control environment.
Both SOC 1 and SOC 2 reports can be issued as either Type I or Type II reports.
Type I Report
Assesses whether controls are suitably designed and implemented as of a specific date. It provides a snapshot of control design but does not test operational effectiveness.
Type II Report
Covers both control design and operational effectiveness over a defined review period (typically 12 months). This is considered the more valuable report; as it includes testing of control performance.
Frequently Asked Questions
What’s the difference between SOC 1 and SOC 2?
SOC 1 focuses on controls relevant to clients’ financial reporting; while SOC 2 focuses on IT and data-related controls such as security, privacy, and availability.
How long does a SOC 2 audit take?
The timeline for a SOC 2 audit depends on your readiness and the type of report required. A Type I audit, which assesses controls at a single point in time, can be completed in a few weeks to two months once preparation is done. A Type II audit, which evaluates controls over an extended period (typically 6–12 months), takes longer as it requires evidence of consistent performance. By outsourcing your SOC 2 audit to ResourcePlus, you benefit from experienced auditors who can streamline preparation, reduce delays, and help ensure a smooth, efficient process from start to finish.
How often are SOC 2 audits done?
SOC 2 audits are typically conducted annually to ensure ongoing compliance and provide up-to-date assurance to clients and stakeholders. An annual cycle demonstrates that your controls around security, availability, processing integrity, confidentiality, and privacy are operating effectively year after year. Outsourcing your SOC 2 audit to ResourcePlus ensures the process is handled efficiently, with minimal disruption to your operations, while maintaining the trust and confidence of your customers.
Turning compliance into client confidence