What if I don't want any IT General Controls in my SOC report?
What if I don't want any IT General Controls in my SOC report?
A SOC report must include a complete set of control objectives relevant to internal controls over financial reporting (SOC 1) or to the applicable trust services criteria (SOC 2). Exclusion of relevant ITGC controls may result in a qualification for fairness of presentation and or control design. This would need to be discussed during the planning activities with the service auditor to determine the overall impact to the SOC report.