Compliance · SSAE 18 attestation
For when your service affects your customers' financial statements.
SOC 1 is an attestation over controls relevant to your customers' internal control over financial reporting (ICFR). If your platform processes payroll, payments, billing, or anything that lands in a client's financials, their auditors will ask for it.
ICFR
Control focus
I & II
Report types
SSAE 18
Standard
SOC 1 is narrower than SOC 2 — it only cares about controls that could affect a customer's financial statements.
Unlike SOC 2's fixed criteria, you write control objectives describing what must be true for your customers' financial data to be reliable — then the auditor tests controls against them.
Type I is design at a point in time; Type II is operating effectiveness over a period. Customer auditors almost always want Type II so they can rely on it during their own audit.
SOC 1 reports specify complementary controls your customers must run on their side. Getting these right protects you when something goes wrong downstream.
Service organizations whose processing flows into someone else's books.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We identify precisely which of your processes touch customer financial reporting — and keep everything else out of scope.
We draft objectives that are defensible to auditors without over-committing you to controls you can't sustain.
We build the access, change, processing, and reconciliation controls the objectives require.
We prepare populations and evidence so auditor sampling doesn't turn into an archaeology project.
We document the complementary controls your customers must perform, clearly and defensibly.
We manage the CPA firm's request list and keep the examination on schedule.
Map which services and systems affect customer financial reporting.
Define control objectives and the controls that satisfy them.
Close design gaps and assign control owners.
Operate controls and accumulate evidence for Type II.
Support the audit, then reuse overlapping controls for SOC 2.
SOC 1 is about controls affecting your customers' financial reporting (ICFR). SOC 2 is about security, availability, processing integrity, confidentiality, and privacy. They answer different questions — many service providers eventually need both, and the underlying controls overlap.
Only if your service affects customers' financial statements. A SOC 2 doesn't satisfy a customer's financial auditor, because it doesn't opine on ICFR-relevant control objectives. If payroll, billing, or payments flow through you, expect to be asked for SOC 1.
A licensed CPA firm performs the SSAE 18 examination and issues the opinion. intSignal handles readiness, control design, remediation, and evidence, and supports you through the audit — we are not the auditor.
They're the controls your customers must operate for your controls to work — like promptly removing terminated users or reviewing output reports. Defining them properly is both an audit requirement and a meaningful liability boundary.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.