Mastering SOC-1 Attestation Reports Under SSAE 16: Auditing Service Organizations Controls in the Cloud
Recording of a 110-minute CPE webinar with Q&A
This course will provide audit and attest professionals with a practical and comprehensive guide to issuing and interpreting SSAE 16 (SOC 1) audit reports of outside service companies. The panel will discuss the specific features and functions of an SOC 1 report, focusing on the peculiarities of preparing an internal controls report for a service provider and will provide useful details on the the attestation standards for external service organizations.
Outline
- Uses and framework for SOC 1 reports
- IT considerations for audit and attest professionals in preparing SOC 1 reports
- Testing and sampling criteria and considerations
- SOC 1 Type 2 report special considerations
- Internal audit function
- Monitoring
- Subservice organization reporting
- Additional reporting options under SSAE 16
Benefits
The panel will discuss these and other important issues:
- Differentiating SOC 1 reports from SOC 2 and SOC 3 engagements
- How SOC 1 reports under SSAE 16 differ from previous SAS 70 standards
- Incorporating subservice organization assessments into SOC 1 reports
- What other issues must auditors address in issuing SOC 1 Type 2 attestation reports?
Faculty
Mitchell Evans
Director, Risk Consulting
Barr Assurance & Advisory
Mr. Evans is experienced in the IT Audit and Security world. Prior to joining his firm, he worked at KPMG's IT... | Read More
Mr. Evans is experienced in the IT Audit and Security world. Prior to joining his firm, he worked at KPMG's IT Audit & Assurance practice where he performed numerous IT attestation engagements including Sarbanes Oxley (SOX) and Service Organization Controls (SOC1, SOC2, and SOC3) examinations for both small and large organizations. In the past, he specialized in engagements within the Healthcare, Finance & Banking and Retail industries. He is also a Certified Information System Auditor (CISA).
CloseBrad Thies
Principal, Risk Consulting
Barr Assurance & Advisory
Mr. Thies specializes in helping clients assess, design, and implement processes and controls to meet customer,... | Read More
Mr. Thies specializes in helping clients assess, design, and implement processes and controls to meet customer, regulatory, and compliance requirements. His focus includes governance risk and compliance (GRC), SOC 1, SOC 2, SOC 2 examinations, SSAE 16, HIPAA, FedRAMP, ISO 27001/2, NIST/FISMA, PCI, CPNI, SOX, information security management systems (ISMS), FCC Telco Regulations, GLBA, business process improvement, WebTrust for CAs, IT audit and attestation, and internal audit. He provides a unified approach to compliance, risk consulting, and attestation services focused in the technology and cloud service industries. He is a CPA and a certified information system auditor with extensive experience in the industry.
CloseGreg Ameden, CISA
Director of IT Assurance Services
Hancock Askew & Co.
Mr. Ameden is his firm's Director of IT Assurance and Advisory Services for Hancock Askew and leads the... | Read More
Mr. Ameden is his firm's Director of IT Assurance and Advisory Services for Hancock Askew and leads the firm’s IT-related internal audit, risk advisory, and SOC reporting services. He helps clients identify and evaluate IT risk, implement cost-effective controls and monitoring strategies, improve execution and performance, and provide assurance to their customers and other external parties in a wide array of areas including SSAE 16/SOC examinations, enterprise and IT risk assessments, IT risk management programs, IT internal audit co-sourcing or augmentation, compliance examination readiness assessment and remediation, policies and procedures design and documentation, and design/oversight/execution of controls testing programs (e.g. for Sarbanes-Oxley).
Close