Attestation · International

SOC 1, without the spreadsheets.

Give customers’ financial auditors the report they need about you.

What is SOC 1?

A SOC 1 report covers controls at a service organisation that are relevant to its customers’ internal control over financial reporting. If your service touches billing, payroll, payments or financial data, your customers’ auditors will likely ask for one.

Who needs it

  • Payroll, billing, payments and fintech providers
  • SaaS vendors whose customers are SOX-regulated public companies
  • Service organisations processing transactions that land in a customer’s financial statements

What SOC 1 looks at

Control objectives

Objectives you define around the transactions and data that matter to customers’ financial statements.

IT general controls

Access, change management and operations controls over the systems that process financial data.

Complementary user entity controls

The controls your customers must operate for yours to be effective.

How Beviso gets you there

  • IT general controls with automated evidence for access and change management
  • Shared controls with SOC 2 and SOX so evidence is collected once
  • Auditor portal for sampling across the Type II period

6 SOC 1 controls, ready on day one

These controls are loaded when you enable SOC 1, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

ITGC.1

Logical Access to Applications and Data

Access to applications and data is restricted to authorized individuals.

Evidence from

  • Okta
  • GitHub
  • AWS
  • Microsoft Azure
  • Google Workspace
  • Salesforce

ITGC.2

Change Management Controls

Changes to applications and systems follow a formal, documented process.

Evidence from

  • GitHub
  • GitLab
  • Jira
  • ServiceNow
  • Azure DevOps

ITGC.3

Computer Operations — Job Scheduling and Monitoring

Automated and manual jobs are scheduled and monitored for completion and errors.

Evidence from

  • Datadog
  • PagerDuty
  • Splunk
  • Grafana

ITGC.4

Incident Management

Incidents are logged, investigated, and resolved following documented procedures.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira

ITGC.5

Audit Logging and Monitoring

Audit logs are generated, retained, and reviewed for security events.

Evidence from

  • Datadog
  • AWS
  • Splunk
  • HashiCorp Vault
  • Salesforce

ITGC.6

User Provisioning and Deprovisioning

User accounts are created and deactivated following formal request and approval processes.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • GitHub
  • AWS
  • Rippling

SOC 1 questions

SOC 1 or SOC 2?
SOC 1 is about financial reporting; SOC 2 is about security and the other Trust Services Criteria. Some service organisations need both, and much of the underlying access and change evidence is the same.

Start your SOC 1 programme today.

Free while Beviso is in beta. No credit card required.

Get started free