SOC 1 (SSAE 18 / ISAE 3402)
Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402)

SOC 1 (SSAE 18 / ISAE 3402) A.1: SOC 1 A.1 Engage an independent service auditor under AT-C 320 or ISAE 3402, choose type 1 or type 2, and define the system, the services and the period or date

The service organisation engages an independent service auditor to examine under AT-C 320 (and, where user entities abroad need it, ISAE 3402) a defined system: the services covered and the function the system performs, the user entities served, and either a specified date, for a type 1 report covering the description and how the controls are designed, or a specified period for a type 2 report that adds operating effectiveness and the tests and results. The scope and the description must not be so limited that user entities and their auditors could not use the report, which is a precondition the auditor tests before accepting.

Maintained by Gerard BlokdykControl text last updated

Other controls in Engagement scope and the service organisation's responsibilities – SOC 1 (SSAE 18 / ISAE 3402)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.