4018 - Understanding System and Organization Controls (SOC)
Course Description
If your organization outsources services and processes, you need to understand the System and Organization Controls (SOC) reports third-party vendors submit. In this course, you’ll learn how to use these reports to support service auditing, vendor-risk management, regulatory compliance and procurement. You’ll interpret current SOC reporting standards, examine key components of the reporting lifecycle, and create a comprehensive checklist to ensure compliance. You’ll come away with strategies to avoid common issues and findings encountered during the completion of a SOC report.
This is a complementary course to the SCS Internal Audit certificate program.
Within 4-6 weeks of successfully completing this course, you will receive your micro-credential indicating achievement of the outlined learning outcomes and competencies/skills. Micro-credentials are tamper proof, verifiable, blockchain-based and 100% digital. They can be shared on social media, including LinkedIn and Facebook, embedded in websites or downloaded as PDFs.
Learning Outcomes
By the end of this micro course, you'll be able to:
- Examine the connection between various assurance engagement standards and guidelines pertaining to SOC reporting
- Explain the specific responsibilities of management of the service organization and the service auditor
- Analyze the service organization’s processes and how to evaluate the suitability of the design and operating effectiveness of the service organization’s controls
- Identify the criteria that are used to evaluate the design and operating effectiveness of controls at a service organization
- Analyze testing results and exceptions
- Evaluate the elements of the Service Auditor's Report
- Develop strategies to avoid common issues and findings encountered during the completion of a SOC report
Competencies/skills developed in this micro course include:
- Guidance Knowledge
- SOC Reporting Lifecycle Management
- Relying Parties Requirements Analysis
- Risk Assessment