Control Objectives, Control Criteria, Controls
SOC Reporting
PPCs
Testing
Audit Lifecycle
100

ITGC and Transaction Processing

What are SOC 1 control objectives?

100

This report is for a point in time.

What is a type 1 report?

100

The PPCs forms that are completed during planning.

What are P forms?

100

Evidence cannot be provided to suffice testing or the evidence does not support the control.

What are exceptions noted?

100

This is executed first in order to start the audit.

What is the engagement letter?

200

The 5 Trust Services Criteria.

What is Security, Availability, Processing Integrity, Confidentiality and Privacy?

200

This section of the report is excluded from the opinion.

What is Section 5?

200

The PPC form that is completed when exceptions are noted.

What is a C1?

200

Samples are pulled either high or low.

What is the risk reliance?

200

This is done at the conclusion of planning to obtain team approval of the testing approach.

What is the TPM?

300

Change Management

What is CC8?

300

A general use report with no section 4.

What is a SOC 3 report?

300

The PPC form that is completed throughout the duration of the engagement.

What is P8?

300

The amount tested for automated controls.

What is a sample of 1?

300

The last and final step.

What is archiving?

400

Typically PI 1.2, PI1.3, PI1.4 are N/A.

What are SaaS providers?

400

This report opines on the operating effectiveness, suitability of design, and system description.

What is a Type 2 report?

400

The risk assessment PPC form for SOC 1.

What is P3?

400

Test of controls that begin with "Per inspection..."

What is no testing performed?

400
The questions asked throughout the engagement from start to finish.

Management Inquiries

500
Controls are written in ____ tense and TOCs are written in ____ tense.

What is present and past?

500

This type of report requires a written assertion from the SSO and their controls are tested.

What is an inclusive report?

500

The date on this PPC form is the date in which the Engagement Letter was signed.

What is P2?

500

The testing results for if applicable or as applicable controls.

What is no exceptions noted?
500

The Assertion and Management Representation Letter must be signed for this to happen.

What is the issuance of the final report?