Description
The SOC 1 Toolkit is built on what management actually has to produce
A SOC 1 report has three parts, and management writes two of them. The service auditor examines management’s description of the system and management’s assertion; it does not write either. A first engagement turns on whether that description exists, and a folder of policies is not one.
The SOC 1 Toolkit is organised on the service organisation’s own obligations under AT-C section 320 (SSAE No. 18, as amended) and ISAE 3402: 87 editable templates, 63 Word documents and 24 Excel workbooks, across 9 sections. Every document carries a Requirements-addressed table naming the paragraphs it answers, and the crosswalk workbook lists all 82 identifiers — 41 from AT-C 320, 39 from ISAE 3402 — against the document that answers each.
The SOC 1 Toolkit’s description of the system, section by section
The description criteria require eight elements, plus the changes during the period for a type 2 report, plus the rule that nothing relevant is omitted or distorted. The SOC 1 Toolkit gives you a master template with every element as a headed section.
A separate drafting template covers each element: services and classes of transactions; the transaction-processing narrative from initiation to reporting; the information the procedures use; significant events other than transactions; report preparation; subservice organisations and the carve-out or inclusive method; the control environment and the other COSO components; and the changes-during-the-period section built from a change log kept through the year.
A drafting standard sets the writing rules a user auditor needs — role by title, frequency stated, action on exception named — and a self-assessment tests the finished description against every criterion before the auditor sees it.
19 control objectives, 76 risks and 77 controls, written to be testable
The commonest reason a SOC 1 examination goes wrong is an objective a user auditor cannot conclude on. The SOC 1 Toolkit’s objective library carries 11 business-process objectives and 8 IT general control objectives, each written to the four attributes the AICPA’s management guidance names — relevant to user entities’ financial-statement assertions, objective, measurable and complete — and each tied to the assertions it serves.
Under every objective sit the risks that threaten it, 76 in all with the fraud-relevant ones flagged, and 77 illustrative controls that each state the five things a user auditor looks for: frequency, responsible role, activity, information source and action on exception. Tailoring notes cover 7 types of service organisation, from payroll processors and fund administrators to claims administrators, payment processors, loan servicers, hosted financial applications and data centres. A reasonableness review with worked rewrites catches the objectives that fail.
CUECs, CSOCs and the dependencies a report must state
A control objective that depends on something a user entity or a subservice organisation does is not achieved by the service organisation alone, and a report that leaves the dependency out claims a control the organisation does not operate. The SOC 1 Toolkit ships a complementary user entity controls register with 10 worked CUECs and a drafting guide that tests whether a contractual responsibility is really a CUEC; a complementary subservice organisation controls register with 8 worked CSOCs; the dependency test that decides whether a provider is a subservice organisation or a vendor; the carve-out versus inclusive decision memo; and the agreement a subservice organisation signs to be included.
ISAE 3402 has no term for complementary subservice organisation controls. The SOC 1 Toolkit says so, and its description wording introduces the concept for an ISAE reader rather than assuming it.
Assertions, representations and the bridge letter in the SOC 1 Toolkit
The SOC 1 Toolkit gives you the written assertion for a type 1 report, for a type 2 report and for the inclusive method with the subservice organisation’s own assertion, each in the structure both standards illustrate, with every criterion listed and a consistency check that catches a scope sentence that differs between the assertion and the description.
The representation-letter preparation checklist lists every representation the auditor will ask management to sign — the union of the AT-C 320 and ISAE 3402 lists — with the evidence behind each and the date rule. Subsequent events, the unaudited Other Information section, the draft-report review with the response to a modified opinion, report issuance and distribution, and the bridge letter that covers the gap to a user entity’s year end are each a document.
Operating effectiveness you can show, not assert
A type 2 assertion needs a reasonable basis management built itself; the auditor’s work is not it. The SOC 1 Toolkit carries the management testing plan, sampling guidance stated as the organisation’s chosen approach rather than as a rule of either standard, a test workpaper seeded with all 77 controls, an evidence-retention and request list with an information-produced-by-the-entity sheet, the population-completeness checklist, a deviation register classified the way AT-C 320 classifies deviations, a remediation tracker, the monitoring procedure and a quarterly control-owner attestation, so that the year-end assertion is built from four quarters of specific confirmations.
The 16 control policies and procedures in the pack are the ITGC and transaction-process controls a SOC 1 examination tests — logical access, provisioning, access review, privileged access, change management, program development, computer operations, backup, incidents, physical security, data transmission, client onboarding and authorisation, reconciliation and output review, IPE reliability, and competence of control performers — plus a segregation-of-duties matrix with 20 conflict pairs. They are written for internal control over financial reporting, not as a general security policy set.
For user entities: reading the report you were sent
The SOC 1 Toolkit is the only pack in the catalogue with a section for the other side of the table. 6 documents cover a user entity’s own reliance: the report review checklist structured on what the user auditor must consider, the CUEC mapping workbook, the SOC report inventory and coverage-gap tracker, the bridge letter request, the vendor report evaluation memo, and the carve-out follow-up tracker. If your SOX 404 programme relies on a payroll, benefits, custody or hosting provider’s report, this is the half of the pack you will use first.
Written against the primary texts, and dated
The SOC 1 Toolkit was written against AT-C section 320 in the AICPA’s codification as amended through SSAE No. 22, ISAE 3402 as issued by the IAASB in December 2009, the AICPA’s management-side guidance for SOC 1 engagements, and the 2013 COSO framework, with ASAE 3402 (December 2022) checked for paragraph alignment. Every document states its sources and the date of the position. Where the two standards differ in a way that changes what management must do, the difference is stated: the representation lists, the implementation test, the missing CSOC concept, the “authorised” step in the transaction flow.
AT-C 320, ISAE 3402 and the AICPA guidance are cited by paragraph with the intent paraphrased. No text from any of them is reproduced; you need your own copy of each.
Where the SOC 1 Toolkit sits beside the rest of the catalogue
The SOC 2 Toolkit is the information security policy set for an examination under the Trust Services Criteria; the SOC 1 Toolkit does not repeat it. The SOX Toolkit is the user entity’s own ICFR programme, and the SOC 1 Toolkit’s user-entity section is where the two meet. The COSO Toolkit carries the framework the description’s control-environment section maps to. The TPRM Toolkit covers the wider third-party programme in which a vendor’s SOC 1 report is one piece of evidence.
Honest about the boundaries
- The SOC 1 Toolkit does not contain the service auditor’s report. That is the auditor’s document.
- It does not make an organisation certified. Nobody is certified under AT-C 320 or ISAE 3402; the report is an opinion on specified matters for a specified period.
- The objectives and controls are illustrative starting points. Your description states the controls you operate, and the pack’s tools exist to make sure it does.
- CSAE 3416 is mapped at topic level only; confirm paragraph references against the CPA Canada Handbook.
- The standards themselves are not included.
What you get in the SOC 1 Toolkit
| Section | Documents | What it holds |
|---|---|---|
| 00 Programme and Governance | 9 | Implementation guide, charter, roles, type and period memo, preconditions, auditor selection, scope change, plan, readiness workbook |
| 01 Scope and Boundary | 7 | System scoping, subservice organisation inventory and method, CSOC register, inclusive-method agreement, user-entity register, distribution policy, glossary |
| 02 System Description | 13 | Master template, eight section templates, transaction flow workbook, changes during the period, self-assessment, implementation evidence log, drafting standard |
| 03 Control Objectives | 11 | Objectives register and library, risk mapping, control activities matrix, design evaluation, key controls, CUEC register and guide, reasonableness review, RACI, specified objectives |
| 04 Control Policies and Procedures | 16 | Logical access, provisioning, access review, privileged access, change, development, operations, backup, incidents, physical, transmission, SoD matrix, onboarding, reconciliation, IPE, competence |
| 05 Operating Effectiveness | 10 | Testing plan, sampling, workpaper, evidence and requests, population completeness, deviation register, remediation tracker, monitoring, quarterly attestation, fraud escalation |
| 06 Assertion and Reporting | 12 | Type 1, type 2 and inclusive assertions, representation checklist, subsequent events, other information, draft report review, bridge letter, deficiency log, issuance, transition plan, annual calendar |
| 07 User Entity Reliance | 6 | Report review checklist, CUEC mapping, report inventory, bridge letter request, evaluation memo, carve-out tracker |
| 08 Crosswalks | 3 | AT-C 320 to ISAE 3402 / ASAE 3402 / CSAE 3416, ITGC to SOX / ISO 27001 / SOC 2, COSO principles |
00 Programme and Governance
- SOC 1 Implementation Guide
- SOC 1 Programme Charter
- Roles and Responsibilities in a SOC 1 Engagement
- Report Type and Period Selection Memo
- Engagement Preconditions Checklist
- Service Auditor Selection and Engagement Terms Checklist
- Scope Change Control Procedure
- SOC 1 Programme Plan and Timeline (Excel)
- SOC 1 Readiness Assessment Workbook (Excel)
01 Scope and Boundary
- System Scoping and Boundary Definition
- Subservice Organisation Inventory and Method Decision Memo
- Complementary Subservice Organisation Controls Register (Excel)
- Inclusive Method Subservice Organisation Agreement
- User Entity Population and Report Distribution Register (Excel)
- Restricted-Use and Report Distribution Policy
- Glossary of SOC 1 and ISAE 3402 Terms
02 System Description
- Management’s Description of the System – Master Template
- Description Section – Services and Classes of Transactions
- Description Section – Transaction Processing Procedures
- Transaction Flow Narrative and Flowchart Workbook (Excel)
- Description Section – Information Used in the Procedures
- Description Section – Significant Events Other Than Transactions
- Description Section – Report Preparation for User Entities
- Description Section – Subservice Organisations
- Description Section – Control Environment and COSO Components
- Description Section – Changes to the System During the Period
- Description Completeness and Fair Presentation Self-Assessment
- System Implementation Evidence Log (Excel)
- Description Drafting Standard and Style Guide
03 Control Objectives
- Control Objectives Register (Excel)
- Control Objective Library
- Risk-to-Control-Objective Mapping Workbook (Excel)
- Control Activities Matrix (Excel)
- Control Design Evaluation Worksheet (Excel)
- Key Control Identification Memo
- Complementary User Entity Controls Register (Excel)
- CUEC Drafting Guide
- Control Objective Reasonableness Review
- Control Ownership and RACI Workbook (Excel)
- Control Objectives Specified by Another Party Procedure
04 Control Policies and Procedures
- Logical Access Management Policy
- User Access Provisioning and Removal Procedure
- Periodic Access Review Procedure
- Privileged Access Management Procedure
- Change Management Policy and Procedure
- Program Development and Implementation Procedure
- Computer Operations and Job Scheduling Procedure
- Backup and Recovery Procedure
- Incident and Problem Management Procedure
- Physical and Environmental Security Policy
- Data Transmission and Interface Controls Procedure
- Segregation of Duties Policy and Conflict Matrix (Excel)
- Client Onboarding and Transaction Authorisation Procedure
- Reconciliation and Output Review Procedure
- Information Produced by the Entity Reliability Standard
- Competence and Authority of Control Performers Standard
05 Operating Effectiveness
- Management Control Testing Plan
- Sampling Guidance for Management Testing
- Test of Controls Workpaper (Excel)
- Evidence Retention and Request List (Excel)
- Population Completeness Checklist
- Deviation and Exception Register (Excel)
- Remediation and Compensating Control Tracker (Excel)
- Monitoring Activities Procedure
- Quarterly Control Owner Attestation
- Fraud and Deviation Escalation Procedure
06 Assertion and Reporting
- Management’s Assertion – Type 1
- Management’s Assertion – Type 2
- Management’s Assertion – Inclusive Method Variant
- Management Representation Letter Preparation Checklist
- Subsequent Events Procedure and Memo
- Other Information Section Guidance
- Draft Report Review Checklist
- Bridge Letter Template
- Deficiency Communication Log (Excel)
- Report Issuance and Distribution Procedure
- Type 1 to Type 2 Transition Plan
- Annual Re-examination Cycle Calendar
07 User Entity Reliance
- SOC 1 Report Review Checklist for User Entities
- CUEC Mapping Workbook for User Entities (Excel)
- SOC Report Inventory and Coverage Gap Tracker (Excel)
- Bridge Letter Request Template
- Vendor SOC 1 Report Evaluation Memo
- Subservice Organisation and Carve-out Follow-up Tracker (Excel)
08 Crosswalks
- AT-C 320 to ISAE 3402, CSAE 3416 and ASAE 3402 Crosswalk (Excel)
- ITGC to SOX, ISO 27001 and SOC 2 Mapping (Excel)
- Control Environment to COSO 2013 Principles Mapping (Excel)
ISO 45001 Assessment Tool - Ultimate Solution 




































Reviews
There are no reviews yet