主要联系人: Eric M. 赖特CPA, CITP

System and Organization Controls (SOC) reports (formerly SSAE 16, SAS 70 report) are examinations provided by CPAs in connection with system-level controls of a service organization or entity-level controls at other organizations.

Business owners need to ensure sensitive data is protected, especially as it relates to financial and personally identifiable information (PII) and protected health information (PHI) of customers. Organizations also continue to face pressure from regulators and customers to demonstrate that adequate controls are in place with respect to the processing of transactions and internal controls over financial reporting. 政府规定, including Section 404 of the Sarbanes-Oxley Act of 2002 (SOX 404), Gramm-Leach-Bliley Act (GLBA) and Health Insurance Portability and Accountability Act (HIPAA) stress the need for effective internal controls. System and Organization Controls (SOC) examinations provide management with assurance regarding the effectiveness of an organization’s internal controls, while also providing insights for opportunities to improve internal controls and risk mitigation activities.  进一步, standard contracts typically require organizations to attest to the effectiveness of their internal controls. Obtaining a SOC report has become increasingly relevant for organizations of all sizes, as the resulting report can be provided to customers and prospective customers to demonstrate that effective internal controls and related safeguards have been implemented. 

Ensuring the company has robust internal controls and policies and practices in place is essential. In fact, many may expect to see a SOC report before doing business with a company. This examination (often referred to as a “SOC audit”) verifies that the controls, processes and procedures have been tested and indicates whether controls are effective. Some organizations may desire a SOC 1 examination, while others will obtain more value from a SOC 2 or SOC 3 report. 无论你想要什么程度的保证, it’s important to work with an experienced provider to drive the process.

Schneider Downs provides SOC examinations nationally to over 100 clients annually in a variety of 行业. Our dedicated group of professionals spend the majority of their time providing services related to the evaluation, optimization and testing of internal controls and control environments in support of SOC reports, internal audit co-sourcing or outsourcing, 萨班斯-奥克斯利法案404条款, and several other RAS practice offerings.





Schneider Downs employs a unique approach to SOC reports, integrating the expertise of information technology, internal audit and external audit professionals. By combining cross-disciplinary knowledge and project management expertise, we are able to effectively deliver on our clients' expectations. If you are interested in learning how we can assist your organization, please 新葡新京十大正规网站 to get started and learn more about our practice at

Does your organization need a system and organization controls (SOC) report?


Let’s discuss preventing ransomware attacks on your company. 直接给我发邮件 <a href=''>在这里</a>.
Let’s discuss preventing ransomware attacks on your company. 直接给我发邮件 在这里.
Let’s discuss opportunities to reduce your company’s tax burden. 直接给我发邮件 <a href=''>在这里</a>.
Let’s discuss opportunities to reduce your company’s tax burden. 直接给我发邮件 在这里.