Outsourced SOC Audits

& Alternate Independent Assurance

Our SOC 1 and SOC 2 audit solutions are ideal for service organisations that need to provide assurance to clients and stakeholders around financial reporting (SOC 1) or the security and integrity of systems and data (SOC 2)

 

We provide skilled professionals to support your clients through SOC 1 and SOC 2 audit engagements; executed in line with international standards and tailored to the expectations of UK and global markets. Whether your clients require a readiness assessment, a formal assurance engagement, or full audit execution, our outsourced professionals deliver clarity, compliance, and confidence across the entire process.

Outsourced SOC 1 Audits

SOC 1 reports are issued in accordance with SSAE No. 19 in the USA. For organisations operating outside the USA; including the UK; SOC 1 audits are conducted under the ISAE 3402 standard (Assurance Reports on Controls at a Service Organisation), issued by the International Auditing and Assurance Standards Board (IAASB).

Our professionals are familiar with both standards and provide assurance engagements that meet international expectations while aligning with your clients’ local regulatory environments.

Outsourced SOC 2 Audits

A SOC 2 audit evaluates a service organisation’s controls in relation to data security, privacy, and system integrity. These audits are guided by the Trust Services Criteria; a framework developed by the AICPA; covering the following five core principles:

  • Security – Protection of systems against unauthorised access
  • Availability – System and data availability for authorised users
  • Processing Integrity – Accuracy, completeness, and timeliness of processing
  • Confidentiality – Protection of sensitive client or proprietary data
  • Privacy – Safeguarding of personal information and compliance with privacy regulations

Outside of the US, SOC 2 audits are performed under ISAE 3000, using the Trust Criteria as the audit framework.

Your clients may choose to be assessed on all five trust principles or a customised selection. Our professionals guide organisations through this selection, ensuring the scope aligns with business objectives and stakeholder expectations.

SOC AUDIT

COSO Points of Focus

In addition to the Trust Principles, SOC 2 audits incorporate key COSO components to assess broader governance and risk management practices. These points of focus help organisations evaluate the design and implementation of their control environment.

  • Control Environment
  • Communication and Information
  • Risk Assessment
  • Monitoring Activities
  • Control Activities

SOC AUDIT

Type I vs Type II Reports

Some organisations begin with a readiness assessment to identify gaps in control design. Once addressed, they may move directly to a Type II report to demonstrate both the adequacy and effectiveness of their control environment.

Both SOC 1 and SOC 2 reports can be issued as either Type I or Type II reports.

Type I Report
Assesses whether controls are suitably designed and implemented as of a specific date. It provides a snapshot of control design but does not test operational effectiveness.

Type II Report
Covers both control design and operational effectiveness over a defined review period (typically 12 months). This is considered the more valuable report; as it includes testing of control performance.

Turning compliance into client confidence

SOC Audit Enquiry

US in House Vs SA Outsourced Staff Calculator

Included in the US all-in rate is an average overhead covering IT, software, HR, office space, training, and related costs.
Billable time might differ based on individual needs.