Licensed CPA Firm · SSAE 18 · AICPA

SOC 1 Audit
under SSAE 18

We evaluate the internal controls relevant to financial reporting (ICFR) at service organizations. We demonstrate the reliability of your processes when they affect the financial statements of your clients in the U.S. and Latin America.

Accounting BPO Fintech Financial SaaS Payroll Processors ISAE 3402
SOC 1 Report — SSAE 18 ICFR Audit
️ AICPA Member
CPA Licensed Firm
SSAE 18 · AT-C Section 320
USA & LATAM
Equivalent to ISAE 3402
Report Types

SOC 1 Type I vs SOC 1 Type II

Understanding the difference helps you choose the right assessment based on the maturity of your controls and the requirements of your clients and auditors.

Swipe to see the full table
Criteria
SOC 1 Type I Design
SOC 1 Type II Effectiveness
Main Focus
Assesses whether controls are properly designed and implemented.
Assesses the design and verifies the operating effectiveness of controls.
Time DimensionPerformed as of a specific date or point in time (e.g., "As of December 31").Covers a continuous period, typically between 6 and 12 months of operation.
Type of EvidenceDemonstrates that controls exist and are ready to mitigate financial risks.Provides solid evidence (through sampling) that controls operated without interruption.
Ideal Use CaseCompanies being audited for the first time or that have just implemented structural changes.Companies with mature processes whose clients and auditors require the highest level of annual assurance.
Estimated Timeline1 to 1.5 months from kickoff to report issuance.Observation period + 1.5 to 2.5 months for execution and issuance.
Demand LevelEntry point — useful for demonstrating that controls exist.Most requested ⭐ Popular among corporate clients and auditors.
Industries We Serve

What types of companies need a SOC 1 report?

Organizations that process, store, or impact their clients' financial information are the primary candidates for a SOC 1 report under SSAE 18.

Swipe to see the full table
Company TypeService ProvidedHow It Impacts Financial ProcessesWhy It Needs SOC 1
Accounting BPOOutsourced accountingProcesses clients' accounting records and financial statementsEnsures financial reliability
Payroll processorsPayroll calculation and disbursementDirectly affects the client's expenses and recordsAccuracy and control in payroll
SaaS companies / accounting ERPCloud-based accounting platformsManage financial data, balance sheets, and reportsSecure, reliable software
Clearing banksProcess financial transactionsIntermediate transactions recorded in accounting booksProcess integrity and accuracy
E-invoicing providersInvoice issuance and validationAffects tax and accounting informationProper invoicing controls
Funds / Trust companiesManaging third-party investmentsControl resources that impact financial statementsCertification of proper management
Financial outsourcingAccounts payable / receivableAffects the client's cash flow and balance sheetsTransparency in financial processes
Data centers hosting ERPsHosting financial systemsTheir uptime affects accounting operationsValidated technology controls
Fintech companiesPayments, loans, and creditHandle financial data and monetary flowsBuilds trust with regulators and banks
Payroll software / HR techPayroll automationAffects labor costs and financial recordsAccuracy, privacy, and control
Frequently Asked Questions

Everything you need to know about SOC 1

A SOC 1 audit is an attestation report under the AICPA's SSAE 18 standard (AT-C Section 320). It evaluates a service organization's internal controls over financial reporting (ICFR) and demonstrates the reliability of its processes when they impact its clients' financial statements.
SOC 1 Type I evaluates the design and implementation of controls as of a specific date. SOC 1 Type II also evaluates operating effectiveness over a 6 to 12 month period — it's the most requested by corporate clients and external auditors.
A SOC 1 Type I can be completed in 1 to 1.5 months from kickoff. A SOC 1 Type II requires the observation period (6 to 12 months) plus an additional 1.5 to 2.5 months for execution and report issuance. Reports are valid for one year.
Only a registered CPA firm with an active license from a State Board of Accountancy can issue a valid SOC 1 report under SSAE 18, in compliance with AICPA standards. Next Assurance meets all of these requirements.
Yes. SOC 1 under SSAE 18 is recognized in the U.S. and internationally. Its content is substantially equivalent to the IAASB's ISAE 3402. Next Assurance can issue dual-use SOC 1 + ISAE 3402 reports for clients with international requirements.
Policies and procedures, control matrices, transaction samples, reconciliations, system reports, access controls and segregation of duties, and evidence of control monitoring and operation over at least 6 months (Type II).

Need a SOC 1 report?

Our team reviews your service structure and recommends the most appropriate type and scope — at no cost.