CPA Exam Lab
Section 3: 15–25%I13

Performing and Reporting on SOC Engagements

Exam insight

Once you know the report types and criteria, the exam tests how the engagement is actually run and how the service auditor reaches and reports an opinion. Knowing what triggers a qualified, adverse, or disclaimer opinion, and how subservice organizations and CUECs shape the report, is essential to ISC reporting questions.

What AICPA wants you to know

  • 1Distinguish management's responsibilities from the service auditor's responsibilities in a SOC engagement.
  • 2Describe how the service auditor tests controls and identifies deviations (exceptions).
  • 3Identify the four opinion types and what triggers each.
  • 4List the major sections of a SOC report and the purpose of the restricted-use paragraph.
  • 5Explain how subservice organizations (carve-out vs inclusive) and CUECs affect the opinion and report.
  • 6Evaluate test results to determine whether an exception affects the opinion.

Exam tip

Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.