Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
SOC 1

SOC 1: the controls your customers' auditors rely on

Run the controls relevant to your customers' financial reporting with automated checks and sealed evidence, and take the SOC 1 Type 1 or Type 2 examination inside Viglyn, with the same auditor workflow as SOC 2.

What is SOC 1?

SOC 1 is an attestation report on the controls at a service organization that are relevant to its customers' internal control over financial reporting, examined by an independent CPA firm under the AICPA's attestation standards (SSAE 18, AT-C section 320). It exists because a customer's financial auditor must understand every system that feeds the customer's accounts, including the ones a vendor runs: payroll, billing, payment processing, claims, fund administration, financial SaaS. The service organization describes its system and the control objectives it has set; the auditor tests the controls against those objectives. A Type 1 report opines on whether the controls were suitably designed at a point in time; a Type 2 tests whether they operated effectively over a period, usually six to twelve months, and is what customers' auditors want. Where SOC 2 is about the Trust Services Criteria, SOC 1 is about the controls a customer's auditor relies on, and the two share most of their underlying evidence.

In one paragraph

A SOC 1 report is an independent CPA's examination of the controls at a service organization that are relevant to its customers' internal control over financial reporting, performed under the AICPA's attestation standards. Customers' financial auditors rely on it when the service affects the numbers in the customer's accounts: payroll, billing, payments, claims processing, loan servicing, financial SaaS. Like SOC 2 it comes as a Type 1, controls designed at a point in time, or a Type 2, controls operating over a review period.

Who it's for

Payroll, billing, payments, fund administration, claims and financial SaaS providers whose customers' auditors ask how the service could affect their financial statements.

With Viglyn

How Viglyn runs SOC 1

  • Control objectives and the controls under them defined with our practitioners, with automated checks where the evidence lives in your systems and structured evidence requests where it does not
  • Change management, access, processing and reconciliation evidence collected as the actual system response, hashed at capture
  • The system description and the complementary user entity controls held as controlled documents with a full audit trail
  • Shared evidence with SOC 2: the security controls are evidenced once and reported twice
  • The examination run inside Viglyn, with your CPA firm working through scoped access and workpapers that export with integrity hashes
Straight answers

The SOC 1 questions that decide it

Do we need SOC 1 or SOC 2?

SOC 1 if your service affects your customers' financial statements and their auditors ask about it; SOC 2 if customers ask about security, availability and privacy. Many financial SaaS companies need both, and in Viglyn the shared security controls are evidenced once for the two reports.

How long does SOC 1 take?

A Type 1 is achievable in weeks once the control objectives are defined and the controls exist. A Type 2 reports on a review period, usually six to twelve months, so the real timeline is the period plus the examination. We tell you the honest timeline for your starting point before you commit.

How much does SOC 1 cost with Viglyn?

SOC 1 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The CPA firm's fee is separate and paid by you directly; we take no commission.

Compared with

SOC 1 against the standards it is weighed with

FAQ

More SOC 1 questions

What are complementary user entity controls?
Controls the service organization assumes its customers operate for the control objectives to be met, for example that the customer approves its own users' access. They are listed in the report, and Viglyn keeps the list with the system description so it stays current.
Who reads a SOC 1 report?
Your customers' financial auditors, who need to understand your controls to audit their client's accounts, and the customers' own finance and risk teams. It is a restricted-use report, shared under NDA with those parties.
Is SOC 1 the same as SSAE 18?
SSAE 18 is the attestation standard the CPA follows; SOC 1 is the report produced under it (AT-C section 320). Outside the United States the equivalent standard is ISAE 3402, and many firms issue a report that satisfies both.

See SOC 1 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.