SOC 1
BetaControls over financial reporting — SSAE 18 / AT-C 320. Type I design review or Type II operating effectiveness.
Before you start — what to have ready for SOC 1
Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.
Decide your scope first
This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.
- Which systems, services and locations are in scope — write this down before you answer anything.
- Who owns each area, so an answer about it is somebody’s to give.
- The period the evidence should cover, where the framework opines on a period rather than a moment.
Gather these documents
What SOC 1 is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.
- Description of the system and control objectives relevant to financial reporting
- Control activities documentation for each control objective
- Access control and segregation-of-duties evidence
- Change management records for financially significant systems
- Evidence covering the observation period
Have the right people
Who needs to be involved, and what changes if it is only you.
- Someone who can find the documents — usually whoever owns the control day to day.
- A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
- One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
- A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.
Prepare the files
Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Financial-controls evidence can contain transaction data and staff identities. Remove real transaction records and mask personal details — the control descriptions and their operation are what is assessed.
- Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
- A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
- The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
- Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
- A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.
Know what you will get
So the result is what you expected when you started.
- You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
- You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
- Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
- A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
What is SOC 1?
A SOC 1 report (SSAE 18 / AT-C Section 320) examines your internal controls over financial reporting (ICFR). It's typically driven by customer and contract demand when your service affects your customers' financial statements — payment processors, payroll providers, fund administrators, data-centre operators, and SaaS finance platforms are common examples. It is rarely a statutory requirement; your customers' auditors usually ask for it.
Your CPA firm produces the report. This platform prepares you for the engagement: identifying in-scope process families, assessing control design, referencing evidence, and producing an auditor-ready package.
Who needs SOC 1?
Type I vs Type II
- ✓Controls are suitably designed at a specific date
- ✓No operating effectiveness testing
- ✓Typically a 60-90 day engagement
- ✓Lower cost — auditor reviews documentation only
Best for: A first SOC 1 examination, accelerating a pending contract, demonstrating design intent.
- ✓Reviews operating effectiveness over the agreed period
- ✓Auditor samples actual transactions
- ✓Includes tests of controls and their results
- ✓Covers the system of record for the full period
Best for: Renewing customers, enterprise sales, regulated industries, financial-sector suppliers.
In-scope process families
SOC 1 is process-family based — you only test controls relevant to the financial processes your service performs. Select the families that apply in the Scope Wizard.
SSAE 18 (superseded SSAE 16 in 2017) splits the examination into AT-C 320 (SOC 1) and AT-C 205 (SOC 2). The report is produced by a licensed CPA. This platform performs pre-engagement readiness work — it does not replace the CPA audit.