Wipfli logo

SOC Examinations

Get transparent and thorough SOC examinations

System and Organization Controls (SOC) examinations allow clients to project confidence and provide independent assurance to current customers, prospects, and their financial statement auditors that processes and controls are sound.

Wipfli’s experienced auditors work collaboratively with clients to thoroughly complete the various types of SOC examinations.

Our SOC services

SOC for service organizations

These internal controls reports provide valuable information that users of outsourced services need to assess and respond to the risks over services provided by service organizations.

  • SOC 1:  We work with you to evaluate and document your internal controls over financial reporting.
  • SOC 2:  Secure a report on trust services criteria relevant to one or more of the following principles: security, availability, processing integrity, confidentiality and privacy.
    • SOC 2 for HITRUST is Our team helps service organizations that desire to use the SOC 2 reporting framework to leverage both the SOC 2 Trust Services Principles and the HITRUST Common Security Framework (CSF). 
  • SOC 3:  We can help examine and produce a general use report on your trust services criteria relevant to one or more of the following principles: security, availability, processing integrity, confidentiality and privacy.

SOC for cybersecurity

Evaluate and document your cybersecurity risk management program and related controls based on the AICPA cybersecurity reporting framework.

SOC for supply chain

We can help entities that produce or distribute products complete a SOC for supply chain report that describes their supply chain risk management efforts.

SOC exams for service organizations
Learn what the different types of SOC audits are, why your service org might need one and what the benefits are
Download white paper
SOC exams for user entities
Everything you need to know about SOC audits, from when to ask a service provider for one to how to read an SOC report
Download white paper
Featured Insight

Top 3 SOC report exceptions and how they impact your auditor opinion

These are the three common categories of SOC report exceptions we see, plus how they impact your SOC auditor’s final opinion.