Enterprise GRC Platform
Tyndora for SOC 1 Type II
A SOC 1 report gives your customers' auditors assurance over the controls at your service organization that are relevant to their internal control over financial reporting (ICFR). It is an SSAE 18 attestation performed by a licensed CPA firm — not a certification. Tyndora automates control testing and evidence collection across the examination period.
SOC 1 Compliance Framework
Service Organization Control (SOC) 1 applies to service organizations that affect clients' financial reporting. Companies providing bookkeeping, payroll, tax, or financial services need SOC 1.
SOC 1 Scope & Criteria
- User Entities: Clients who rely on your financial services
- Control Criteria: Your own control objectives, defined by management (SSAE 18 / AT-C 320)
- Scope Focus: Controls affecting clients' financial reporting
- Type II: covers operating effectiveness over a period, typically 6–12 months (vs Type I, a point in time)
Who Needs SOC 1?
Service organizations that impact client financial reporting must obtain SOC 1. Typical examples include payroll processors, accountants, bookkeepers, and tax services.
- ✓ Payroll service providers
- ✓ Accounting and bookkeeping firms
- ✓ Tax preparation and filing services
- ✓ Financial statement preparation services
Explore Typical SOC 1 Control Objectives
SOC 1 has no fixed control catalog — objectives are defined by your management. Click any category to see the kinds of control objectives service organizations commonly include.
These categories and objectives are illustrative examples only. In a SOC 1 examination under SSAE 18 (AT-C 320), the service organization's management defines its own control objectives and the controls that meet them, based on the services it provides that are relevant to user entities' internal control over financial reporting. Your actual objectives will differ from those shown here.
SOC 1 Implementation in Tyndora
From control-objective documentation to testing across the examination period to Type II report delivery.
Control Objectives & SSAE 18 Implementation
A SOC 1 examination is performed under SSAE 18 (AT-C 320). Your management defines the control objectives for the services that affect user entities’ financial reporting; Tyndora maps, documents, and tests the controls that meet them.
- Control-objective mapping for services affecting user-entity ICFR
- Financial process mapping (order-to-cash, procure-to-pay)
- Control design and documentation
- Control testing evidence collection
SOC 1 READINESS
Target Report
Type I first, then Type II
Control Objectives Documented
22 / 32 (69%)
Examination Period
Not yet started — readiness phase
Audit Readiness
58%
CONTROL TESTING PROGRESS
Control Objectives Defined
32
Tested & Effective
18 / 32 (56%)
Evidence Collected
Readiness phase — evidence being staged
Type II Examination Period
A SOC 1 Type II report covers a defined period — typically 6–12 months — of continuous control operation. Tyndora automates testing across that period so evidence is auditor-ready.
- Monthly automated control testing
- Full-period evidence pre-staged for the auditor
- Failed test remediation tracking
- Auditor-ready test documentation
SOC 1 Report & User Entity Communication
The SOC 1 Type II report is delivered to user entities (your clients' auditors) to demonstrate control effectiveness. Tyndora prepares the report for auditor delivery.
SOC 1 Report Contents
- ✓ Management assertion on control effectiveness
- ✓ Detailed control descriptions and testing procedures
- ✓ Full-period testing results and evidence
- ✓ Auditor's opinion on control effectiveness
User Entity Benefits
- ✓ Proof that your controls work effectively
- ✓ Reduced audit scope for their auditors
- ✓ Faster financial statement audits
- ✓ Lower audit costs for clients
See SOC 1 Attestation Ready
Book a discovery and we'll show you control-objective implementation, examination-period testing automation, and SOC 1 report preparation.
Book a discovery