SOC Reports Overview


System and Organization Controls (SOC) reports (formerly SSAE 16, SAS 70 report) are examinations provided by CPAs in connection with system-level controls of a service organization or entity-level controls at other organizations.

Business owners need to ensure sensitive data is protected, especially as it relates to financial and personally identifiable information (PII) and protected health information (PHI) of customers. Organizations also continue to face pressure from regulators and customers to demonstrate that adequate controls are in place with respect to the processing of transactions and internal controls over financial reporting. Government regulations, including Section 404 of the Sarbanes-Oxley Act of 2002 (SOX 404), Gramm-Leach-Bliley Act (GLBA) and Health Insurance Portability and Accountability Act (HIPAA) stress the need for effective internal controls. System and Organization Controls (SOC) examinations provide management with assurance regarding the effectiveness of an organization’s internal controls, while also providing insights for opportunities to improve internal controls and risk mitigation activities.  Further, standard contracts typically require organizations to attest to the effectiveness of their internal controls. Obtaining a SOC report has become increasingly relevant for organizations of all sizes, as the resulting report can be provided to customers and prospective customers to demonstrate that effective internal controls and related safeguards have been implemented. 

Ensuring the company has robust internal controls and policies and practices in place is essential. In fact, many may expect to see a SOC report before doing business with a company. This examination (often referred to as a “SOC audit”) verifies that the controls, processes and procedures have been tested and indicates whether controls are effective. Some organizations may desire a SOC 1 examination, while others will obtain more value from a SOC 2 or SOC 3 report. Whatever the desired level of assurance, it’s important to work with an experienced provider to drive the process.

Schneider Downs provides SOC examinations nationally to over 100 clients annually in a variety of industries. Our dedicated group of professionals spend the majority of their time providing services related to the evaluation, optimization and testing of internal controls and control environments in support of SOC reports, internal audit co-sourcing or outsourcing, Sarbanes-Oxley Section 404, and several other RAS practice offerings.

Learn more about our practice at

SOC Services

SOC Resources

About Schneider Downs SOC Services

Schneider Downs employs a unique approach to SOC reports, integrating the expertise of information technology, internal audit and external audit professionals. By combining cross-disciplinary knowledge and project management expertise, we are able to effectively deliver on our clients' expectations. If you are interested in learning how we can assist your organization, please contact us to get started and learn more about our practice at

Does your organization need a system and organization controls (SOC) report?

case studies
                                    Company impacted by ransomware.
big problem:
Company impacted by ransomware.
big thinking:
Restore system on-site and avoid six-figure ransom.
                                    Inefficient tax credit realization.
big problem:
Inefficient tax credit realization.
big thinking:
Identified a $900,000 tax credit, nearly twice as much as prior years.

contact us

Metropolitan Washington