0 6 min 3 weeks

Many companies bringing in a SOC 1 prep specialist for the first time rely on price and turnaround time to make the call.

But it takes more than that to find the right person for the job.  A bad hire doesn’t just lose that budget – it threatens the independence of your report, opening the door for your competitor’s bridge letter to come into play. This article includes questions to help you choose the right professional the first time.

Table of Contents

5 Questions To Vet SOC 1 Consultants

To assist with your SOC 1 consultants USA search, use these five questions to scope out the professionals.

1. Are you preparing my controls or auditing them?

This is the question that will reveal whether the firms you’re considering truly “get it,” or whether they’re the kind of firms who will do your work in a way that invites skepticism (or outright rejection) from lenders/investors/clients and their auditors.

The AICPA’s independence rules generally bar the same firm from designing your controls and doing your attestation work for obvious reasons. If a firm insists you can “get your SOC” with them or says they can do both “under one roof” that could be a real convenience… for the wrong kind of buyer.

Ask directly: is this firm the readiness consultant, the attestation firm, or would I be turned over to an affiliated CPA practice for that part?

Get the answer in writing. A firm that’s dodgy on this question, or that seems to regard the independence rules as more of a suggestion, is telegraphing you a lot of other information about their business approach.

2. What’s your actual SOC 1 experience, not just SOC 2?

SOC 1 and SOC 2 may look similar at a distance, but they are not synonymous engagements.

  • SOC 1 focuses on internal control over financial reporting (ICFR), and is written for a user entity’s external auditor.
  • SOC 2 is written for a different user and focuses on security, availability, and a collection of other trust criteria.

Many firms derived the bulk of their revenue a decade ago from SOC 2 work and now call themselves “SOC consultants.” That doesn’t mean they know how a user auditor consumes the report, how you translate financial statement assertions into controls, or how to structure a scoping document that will make the customer happy.

Just ask for SOC 1 engagements specifically. Ask how many they’ve done. If the reply starts to meander into the number of SOC 2 clients they have, keep pressing.

3. How do you approach scoping, subservice organizations, and bridge letters?

This question does a lot of work in a short conversation. A good consultant will likely address Type I versus Type II without prompting and specify which one the user entity is actually asking for.

Type I versus Type II

Type I assesses whether controls are suitably designed at a single point in time, whereas Type II evaluates their operating effectiveness throughout a specified period, usually six to twelve months.

Most enterprise customers eventually want Type II. If your candidate defaults to Type I without asking who’s requesting the report, that’s a scoping shortcut, not a recommendation. Then push on subservice organizations.

If you rely on a payroll processor, a data center, or a cloud host, you need to address those third parties through either the carve-out method or the inclusive method.

A consultant who can’t explain the difference hasn’t scoped a real SOC 1 report before.

Lastly, bridge letters. User entities often need a comfort letter covering the gap between your last report period and your next one. A prepared consultant will raise this before you ask, not after your customer emails asking where it is.

4. Who’s actually doing the work?

You should also ask detailed questions about the team that will staff your engagement.

Who are the managers and directors? Get names. Titles.

Which staff are CPAs, and which are analysts supporting the engagement? This is where a lot of engagements go sideways: a senior partner runs the sales conversation, and then a junior team you’ve never met is the group who actually executes the gap analysis and then disappears for weeks at a time.

Ask for references from companies in your industry, at a similar revenue stage, going through a similar report scope. If a firm can’t produce two or three relevant references without hesitation, that’s worth noting.

5. What’s included in the fee, and what happens when scope changes?

A gap analysis and remediation plan is standard. What varies is whether project management, coordination with your external audit firm, and management’s written assertion drafting support are bundled in or billed separately.

Ask what happens if your user entity suddenly requests a bridge letter mid-engagement, or if the audit firm flags additional controls after fieldwork starts.

Firms with real SOC 1 experience have already answered this question a hundred times. Firms without it will improvise in front of you, and that’s the tell you’re looking for.

Run these five questions before you sign anything. The right consultant will answer them without hesitation, because they’ve heard every one of them before. That confidence, more than any pitch deck, is what tells you they know AT-C 320 well enough to get your report done right the first time.

Leave a Reply

Your email address will not be published. Required fields are marked *