After your first SOC 2 report: setting up the annual audit cycle

IT-audit8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

The first SOC 2 report takes most organizations the most work: setting up controls, writing a system description, getting used to the auditor's questions. Once the report is delivered, a quiet moment often follows. The team that worked towards the audit for months returns to its regular work. That is exactly where things go wrong. SOC 2 works as an annual cycle, and the choices you make right after the first report determine how much effort year two will take.

Why a cycle is needed

A SOC 2 Type 2 report makes statements about a closed observation period. The day after that period ends, the report starts to age. Customers who rely on the report for their own vendor management want continuous coverage: their auditors and regulators check whether a report is available for each financial year. A report whose period ended eighteen months ago raises the same question in every security review: what has happened since?

That is why almost all service organizations work with a fixed annual cycle: a Type 2 report every year, with observation periods that connect.

Making observation periods connect

The common approach is simple: the new observation period starts on the day after the previous one ends. If your first period ended on 30 September, the next one runs from 1 October to 30 September of the following year. This creates a closed chain of reports without months nobody reported on.

Two practical choices come into play. The first is length. A first report often covers a shorter period, six months for example, because the organization needed the report quickly. From the second report onwards, twelve months is the norm. Customers and their auditors get the most out of that, and it saves work over time: one audit per year instead of two short rounds.

The second choice is the end date. It pays to pick it deliberately. Many service organizations set the period end a few months before the moment customers need the report, for example around their financial year-end. There is always time between the end of the observation period and the final report: the auditor has to perform the last test procedures, discuss findings and finalize the report. Choose the end date badly and the report will arrive too late every single year for the moment customers ask for it.

For the months between the period end and the delivery of the new report there is the bridge letter: a short statement by the service organization itself that the controls have not materially changed since then and that no relevant incidents occurred. Useful to have ready, but it remains a management statement, not an auditor's opinion.

What changes in year two

The second audit resembles the first, with a few real differences. The period is usually longer, so the auditor tests operating effectiveness over twelve months and draws samples from the entire year. Controls that run monthly or quarterly must therefore demonstrably have run in the quiet months too. With a first report, a shaky start is sometimes absorbed by starting the observation period later. That escape does not exist in year two.

The auditor also looks more closely at what has changed. New services, a migration to different infrastructure, an acquired team or a changed access management process: anything that touches the system description must be updated in it and can lead to new or modified controls. Findings from the first report come back as well. An exception that appeared in last year's report is something the auditor wants to see resolved this year, or at least demonstrably being addressed.

The common mistakes after the first report

The biggest pitfall is slackening right after delivery. Evidence that was neatly recorded during the audit project stops in October and is hastily reconstructed the following August. Reviews that were supposed to happen monthly turn out to have been skipped for months. In a Type 2 audit over the full year this is immediately visible: the samples land exactly in the months when nobody was minding the controls.

A second pattern is the departure of the internal driver. In many organizations the first project leans on one person who knows everything and keeps everything. If that person leaves without a handover, year two starts with a search for passwords, folders and agreements from the previous project. So assign control ownership to roles and teams, not to an individual.

The third mistake is not reporting changes. Organizations keep building: new features, new subprocessors, a different hosting provider. Whoever only mentions this at the next audit surprises the auditor and delays themselves, especially when the change touches the scope of the report. A short message to your auditor when material changes occur prevents that.

Keeping the cycle light

The difference between a heavy and a light annual cycle is continuity. A few habits make the difference. Collect evidence at the moment a control runs, not afterwards: store minutes, tickets, exports and review records immediately in a fixed place. Schedule the internal control moments for the whole year, with an owner per control. Do your own interim check halfway through the period, so deviations can still be fixed within the period instead of ending up as exceptions in the report. And maintain the system description as a living document instead of starting on it in the last week before the audit every year.

This is also where tooling proves its value. In our audit platform you link evidence to controls continuously, see per control when the next execution is due and build the audit file throughout the year. The audit then becomes a check of what is already there.

Setting up an annual cycle or preparing your second report? We guide service organizations through SOC 2 and ISAE 3402 projects, from first report to ongoing annual cycle. Feel free to contact us.

Frequently asked questions

Does a SOC 2 audit have to be repeated every year?+

There is no legal obligation, but in practice there is a commercial one. A SOC 2 Type 2 report covers a closed observation period. Once that period recedes into the past, its value to customers declines and security reviews start raising questions again. Almost all service organizations therefore opt for an annual cycle with consecutive periods.

Can there be a gap between two observation periods?+

It is possible, but unwise. A gap means there are months no report says anything about, and customers notice. The common approach is to start the new period on the day after the previous one ends.

Is the audit in year two lighter than in year one?+

The audit itself is not: the auditor again tests design, implementation and operating effectiveness over the full period, often twelve months where the first report sometimes covered a shorter period. The preparation can be much lighter, provided evidence has been collected throughout the year instead of reconstructed just before the audit.

What covers the time between the period end and the new report?+

A bridge letter (gap letter): a short statement by the service organization itself that the controls have not materially changed since the end of the last observation period and that no relevant incidents occurred. It is not an auditor product and no substitute for a report, but customers often ask for one in the intervening months.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us