Compliance · SSAE 18 attestation

SOC 1 — controls relevant to financial reporting

For when your service affects your customers' financial statements.

SOC 1 is an attestation over controls relevant to your customers' internal control over financial reporting (ICFR). If your platform processes payroll, payments, billing, or anything that lands in a client's financials, their auditors will ask for it.

ICFR

Control focus

I & II

Report types

SSAE 18

Standard

What SOC 1 covers

SOC 1 is narrower than SOC 2 — it only cares about controls that could affect a customer's financial statements.

Control objectives

Unlike SOC 2's fixed criteria, you write control objectives describing what must be true for your customers' financial data to be reliable — then the auditor tests controls against them.

Type I vs. Type II

Type I is design at a point in time; Type II is operating effectiveness over a period. Customer auditors almost always want Type II so they can rely on it during their own audit.

User entity controls

SOC 1 reports specify complementary controls your customers must run on their side. Getting these right protects you when something goes wrong downstream.

Who needs SOC 1

Service organizations whose processing flows into someone else's books.

  • Payroll, billing, and payment processors
  • Claims administrators and benefits platforms
  • Loan servicers and financial back-office providers
  • ERP or accounting SaaS whose output feeds client financials

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

ICFR scoping

We identify precisely which of your processes touch customer financial reporting — and keep everything else out of scope.

Control objectives

We draft objectives that are defensible to auditors without over-committing you to controls you can't sustain.

Control implementation

We build the access, change, processing, and reconciliation controls the objectives require.

Evidence & sampling

We prepare populations and evidence so auditor sampling doesn't turn into an archaeology project.

User entity controls

We document the complementary controls your customers must perform, clearly and defensibly.

Audit support

We manage the CPA firm's request list and keep the examination on schedule.

How the engagement runs

1

Scope ICFR impact

Map which services and systems affect customer financial reporting.

2

Write objectives

Define control objectives and the controls that satisfy them.

3

Remediate

Close design gaps and assign control owners.

4

Observation window

Operate controls and accumulate evidence for Type II.

5

Examination & reuse

Support the audit, then reuse overlapping controls for SOC 2.

Frequently asked questions

What's the difference between SOC 1 and SOC 2?

SOC 1 is about controls affecting your customers' financial reporting (ICFR). SOC 2 is about security, availability, processing integrity, confidentiality, and privacy. They answer different questions — many service providers eventually need both, and the underlying controls overlap.

Do we need SOC 1 if we already have SOC 2?

Only if your service affects customers' financial statements. A SOC 2 doesn't satisfy a customer's financial auditor, because it doesn't opine on ICFR-relevant control objectives. If payroll, billing, or payments flow through you, expect to be asked for SOC 1.

Who issues the report?

A licensed CPA firm performs the SSAE 18 examination and issues the opinion. intSignal handles readiness, control design, remediation, and evidence, and supports you through the audit — we are not the auditor.

What are complementary user entity controls?

They're the controls your customers must operate for your controls to work — like promptly removing terminated users or reviewing output reports. Defining them properly is both an audit requirement and a meaningful liability boundary.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

SOC 1 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.