SCRM Supplier Compliance & Risk Management

Home

SOC 2 · Trust Services Criteria · type I and II

Your provider’s report also states what you must do yourself.

SOC 2 is the customary assurance report for providers in the Anglo-Saxon world. For you as a customer it is an audit report to read and assess – not a seal.

A SOC 2 report is produced by an audit firm and assesses a provider’s controls against the Trust Services Criteria. Type I looks at design at a point in time, type II adds operating effectiveness across a period, usually six to twelve months.

Two elements decide its value for you: how sub-service organisations are handled, either included or expressly carved out, and the complementary user entity controls. A report with many carve-outs covers considerably less than the cover suggests.

What to check in the report

  • Type and audit period – a type I says nothing about effectiveness over time.
  • Which criteria were examined: security alone, or availability, confidentiality and privacy too.
  • How sub-service organisations were treated: included or carved out.
  • Exceptions identified and their impact.
  • The list of controls that sit with the customer.

What the customer must do with it

Obtain
Request the report, not merely confirmation that one exists.
Read
Assess period, scope and exceptions and record the outcome.
Implement
Run the complementary user entity controls as your own tasks.
Close gaps
Assess carved-out sub-service organisations separately.
Renew
Reports cover a period – request the next before it lapses.

How SCRM covers it

Report with period

Type, audit period and criteria as fields rather than a filename.

Customer controls as tasks

What sits with you gets an owner and a date.

Carved-out parties

A separate entry in the dependency graph, so the gap stays visible.

Renewal on a cycle

The next report is requested before the current one ages out.

Frequently asked

Is SOC 2 comparable to ISO 27001?

Both concern information security but differ fundamentally: ISO 27001 certifies a management system, SOC 2 is an audit report on controls. Many providers hold both.

Does SOC 2 satisfy ISO 27001 A.5.19?

It is a strong building block but does not replace your own assessment. The evidence is that you reviewed the report and acted on it.

What does “carve-out” mean?

The sub-service organisation was excluded from the examination. You must then assess it yourself – frequently the overlooked part.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required