Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 1 audit checklist — SOC 1 Audit Checklist: The Essential 2026 Readiness Guide

SOC 1 Audit Checklist: The Essential 2026 Readiness Guide

A SOC 1 audit checklist is what a service organisation works through before the service auditor arrives, and it looks nothing like a SOC 2 one. There are no published criteria to tick off. Instead there are acknowledgements management must be able to give, a description it must write to eight required elements, control objectives it must specify and defend, evidence it must have kept from the first day of the period, and an assertion and a representation letter it must be able to sign. This SOC 1 audit checklist is organised on those obligations, in the order they arise, with the traps at each step.

What this guide covers

SOC 1 audit checklist explained
A SOC 1 audit checklist follows management’s own obligations under AT-C 320, not a published list of criteria.

SOC 1 audit checklist: before the engagement

The first block of the SOC 1 audit checklist is the acceptance stage. Both AT-C section 320 and ISAE 3402 stop the auditor accepting the engagement unless management can give a set of acknowledgements. Confirm each, with the evidence behind it, before the engagement letter is signed.

  • The scope and the description will be useful to user entities and their auditors — the services they rely on are inside it, not drawn around them.
  • Management accepts responsibility for the description and the assertion, including their completeness, accuracy and method of presentation.
  • Management has, or will have by the report date, a reasonable basis for the assertion — its own monitoring and testing, not the auditor’s work.
  • Management has selected the criteria and will state them in the assertion.
  • Management has specified the control objectives and will name any law, regulation or outside party that specified them.
  • Management has identified the risks to the objectives and designed, implemented and documented the controls.
  • Management will provide the written assertion with the description, and both will go to user entities.
  • Management will give the auditor access to records, agreements, people and any further information requested.

An item that cannot be confirmed is not a finding; it is the absence of an engagement. Our SOC 1 report guide explains what each acknowledgement leads to in the finished document.

SOC 1 audit checklist: scope, type and period

Decision Check Trap
Scope Every service that touches user entities’ financial reporting is in; exclusions are listed with reasons and communicated A boundary drawn for convenience that the auditor will not accept
Type Type 2 unless user entities can control the service themselves or the first period cannot be covered in time Offering a Type 1 to a customer whose auditor needs Type 2
Period Chosen from a survey of user entities’ year ends; covers a substantial portion of them Picking the organisation’s own fiscal year and discovering the gap at year end
Subservice organisations Every provider tested for dependency; carve-out or inclusive decided and recorded for each Treating a hosting provider as a vendor when the ITGC objectives depend on it
Standard AT-C 320, ISAE 3402 or both, matching where user entities are audited A US-only report for a European customer base, or the reverse

The type and period decision is the one that costs most when it is wrong, because a Type 2 period cannot be reconstructed after it has passed; the SOC 1 Type 2 vs Type 1 guide covers the constraints.

SOC 1 audit checklist: control objectives and controls

  • Objectives adopted for every class of transactions and every ITGC domain the applications depend on — logical access, access administration, change, infrastructure, operations, transmission, backup, physical.
  • Every objective tested for the four attributes: relevant to user entities’ financial-statement assertions, objective, measurable, complete as a set. Rewrites recorded. The control objectives guide has the worked examples.
  • Under every objective, the risks that threaten it, including fraud risks; under every risk, at least one control.
  • Every control described with its five elements: frequency, responsible role, activity, information source, action on exception.
  • Key controls designated, so testing and evidence concentrate where a failure would defeat the objective.
  • Complementary user entity controls identified for every objective that depends on the customer, linked to the objective, worded so a user auditor can test them.
  • Complementary subservice organisation controls identified for every objective that depends on a carved-out provider, and the provider’s own report confirmed to cover them.
  • Segregation of duties checked for every role against the conflict pairs, with compensating controls documented where separation is impossible.

SOC 1 audit checklist: the description

The description block of the SOC 1 audit checklist is the longest, because the description is management’s document and the auditor reads it against the criteria. Before it goes out, every one of the following is present and true.

  • Services provided and classes of transactions processed.
  • Procedures by which transactions are initiated, authorised, recorded, processed, corrected and reported, with the role by title and the system at each step.
  • Information used in the procedures — records, files, tables, reports — and how errors in it are corrected.
  • Significant events other than transactions: conversions, fee and rate changes, valuations, period-end procedures.
  • How reports for user entities are produced, checked and delivered, with the key report list.
  • Subservice organisations, the method used for each, and the monitoring controls over them.
  • Control objectives and controls, with CUECs and CSOCs.
  • Control environment, risk assessment, information and communication, and monitoring, as they relate to the services.
  • For Type 2: relevant changes to the system during the period, drawn from a change log kept through the year, not reconstructed at the end.
  • Nothing omitted, nothing distorted; every frequency stated; every “independent” true; the scope sentence identical to the assertion’s.
  • Every control in the description confirmed to be in operation, by observation or inspection, with the evidence logged.

SOC 1 audit checklist: evidence and operating effectiveness

This is the section of the SOC 1 audit checklist a first-year programme fails, and it fails on day one rather than at fieldwork.

  • Evidence retention switched on for every control from the first day of the period, with the retention location and owner recorded.
  • Every report or extract used inside a control — the access listing, the suspense report, the job log — shown to be complete and accurate, because a control that relies on an unreliable report is not a reliable control.
  • Populations for testing drawn from the system where the event happens, not from the ticketing tool, and reconciled: leavers from HR, changes from the deployment log, accounts from the directory.
  • Management’s own tests of key controls performed at interim and after period end, with every sample item recorded so the auditor could reperform it.
  • Quarterly attestations from every control owner: operated as described, exceptions declared, performer changes declared.
  • Every deviation, whoever found it, recorded, evaluated for cause and classified — acceptable within the expected rate, needing more testing, or showing the control did not operate.
  • Manual controls performed by people with recorded competence and delegated authority; a handover performed by someone without either is a deviation.
  • Deficiencies tracked to remediation, with the compensating control relied on meanwhile and the remediated control tested before closure.

SOC 1 audit checklist: fieldwork

  • A named coordinator who logs every auditor request with an owner and a due date, quality-checks evidence before it goes, and arranges walkthroughs with the person who performs the control.
  • Populations and listings provided with source, query, parameters, extraction time and record count.
  • Deviations the auditor finds recorded in the same register as the ones management found, the same day.
  • Decisions on internal audit — direct assistance, work used, or neither — made at planning and confirmed in writing where the auditor requires it.
  • Requests the organisation cannot meet escalated the same day, because a refusal can limit the scope and change the opinion.

SOC 1 audit checklist: assertion, representations and issuance

  • The assertion lists every criterion for the description, the design and, for Type 2, operating effectiveness; an omitted criterion can cause the auditor to disclaim.
  • The scope sentence in the assertion, the description, the engagement letter and the auditor’s report is identical.
  • The assertion mirrors the opinion: if an objective was not achieved, the assertion says so.
  • Subsequent events reviewed up to the report date and disclosed where a reader would need to know.
  • The representation letter prepared against the union of the AT-C 320 and ISAE 3402 lists — non-compliance, fraud, uncorrected deviations, design deficiencies, controls not operating as described, subsequent events, regulatory examinations — with evidence behind each line before anyone signs.
  • The draft report reviewed: opinion elements, period, CUEC and subservice statements, every exception reconciled to the deviation register, any modification understood.
  • Other information, if any, headed as not covered by the opinion and consistent with the description.
  • Distribution logged; prospects under non-disclosure with a note that they are not intended users; bridge-letter dates fixed for the gap to customers’ year ends.

From SOC 1 audit checklist to programme

A checklist gets a service organisation through one examination. A programme gets it through every one after that at lower cost, because the change log, the quarterly attestations, the evidence list and the deviation register run all year and the description is refreshed rather than rewritten. The SOC 1 Toolkit turns every line above into a working document: the preconditions checklist, the scoping and subservice decision memos, the description templates for all eight elements, the objective library with its reasonableness review, the evidence and request list, the deviation register, the quarterly attestation, both assertions, the representation-letter checklist, the draft-report review and the annual re-examination calendar.

That is 87 documents, each citing the AT-C 320 and ISAE 3402 paragraphs it answers. If this SOC 1 audit checklist has more unticked boxes than you expected, the SOC 1 Toolkit is the fastest way to close them.

Further reading in this series: SSAE 18 explained, ISAE 3402 explained for the international reading of every line above, and SOC 1 audit cost.

Frequently asked questions

How long does SOC 1 audit readiness take?

It depends on how much of the checklist already exists. The binding constraint is the Type 2 period: evidence must run from its first day, so the calendar is set by when retention, attestations and management testing can start, not by how fast the description can be written. The AICPA’s SOC 1 resources describe the engagement management is preparing for.

Does the auditor provide a SOC 1 audit checklist?

The auditor will provide a request list during fieldwork and may offer a readiness assessment beforehand. Neither replaces management’s own reasonable basis for its assertion, and the auditor cannot design or operate the controls it will later examine.

Which SOC 1 audit failure cannot be fixed afterwards?

Evidence that does not exist for part of the period. A control that operated but left no record for three months cannot be concluded on for those months, and no amount of description rewriting fixes it.

Is a SOC 1 audit checklist different from a SOC 2 one?

Substantially. A SOC 2 checklist works through published criteria. A SOC 1 checklist works through management’s own obligations under AT-C 320: the acknowledgements, the description elements, the objectives it specified, the assertion and the representations. Our SOC 1 vs SOC 2 guide explains why.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.