SOC 1 (SSAE 18 / ISAE 3402)
The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402)

SOC 1 (SSAE 18 / ISAE 3402) D.10: SOC 1 D.10 Use of the report by user entities and their auditors, and the user entity's own complementary controls

User entities receive the report, evaluate whether the objectives and tested controls cover the transactions they outsource, implement the complementary user entity controls the description assumes and keep evidence of them, and pass the report to their auditors, who use it under AU-C 402 (ISA 402) as evidence about the service organisation's controls after considering the auditor's competence and independence, the period, the tests and results, the deviations and the carve-outs; the held practice aid walks a user auditor's review through those points. The user entity, not the service organisation, remains responsible for its own financial reporting.

Maintained by Gerard BlokdykControl text last updated

Other controls in The assertion, representations, the report package and its use – SOC 1 (SSAE 18 / ISAE 3402)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.