Section 3: 15–25%I13
Performing and Reporting on SOC Engagements
Exam insight
Once you know the report types and criteria, the exam tests how the engagement is actually run and how the service auditor reaches and reports an opinion. Knowing what triggers a qualified, adverse, or disclaimer opinion, and how subservice organizations and CUECs shape the report, is essential to ISC reporting questions.
What AICPA wants you to know
- 1Distinguish management's responsibilities from the service auditor's responsibilities in a SOC engagement.
- 2Describe how the service auditor tests controls and identifies deviations (exceptions).
- 3Identify the four opinion types and what triggers each.
- 4List the major sections of a SOC report and the purpose of the restricted-use paragraph.
- 5Explain how subservice organizations (carve-out vs inclusive) and CUECs affect the opinion and report.
- 6Evaluate test results to determine whether an exception affects the opinion.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
The SOC OpinionGrade the opinion by severity: unmodified when fair, qualified for a limited problem, adverse when pervasive, disclaimer when scope is lost.The SOC MechanicsKnow the roles and ownership: the service organization writes the description and assertion, the auditor opines, and CUECs sit with the user.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.