Sharing Your SOC 1 During RFP

August 31, 2015 Lauren Edmonds

Can I share my SOC 1 with a prospect while we are going through an RFP process?

Yes, distribution of the report is not restricted; however the authorized use or reliance on the report is restricted to specified users. These specified users include the customers (user entities) and their financial statement auditors (user auditors) that used the in-scope system or service as of the report date (for a Type 1 report) or during the review period (Type 2). A prospective user may not place any reliance on the SOC 1 report relevant to their Internal Controls over Financial Reporting.

About the Author

Lauren Edmonds

Lauren is a Principal at Schellman with over 10 years of attestation and compliance experience. Lauren has evaluated risks and controls for a number of industries including financial services, manufacturing, marketing, distribution and service-based organizations.

More Content by Lauren Edmonds
Previous Article
Disaster Recovery Controls Within SOC 1 Test of Controls Matrix
Disaster Recovery Controls Within SOC 1 Test of Controls Matrix

Can I have disaster recovery controls within my SOC 1 test of controls matrix?

Next Article
Formal Risk Assessment Before Our SOC 1?
Formal Risk Assessment Before Our SOC 1?

Do we have to go through a formal risk assessment before our SOC 1?