Report on Controls
A Report on Controls is a document produced by an independent CPA firm that describes an organization's controls and the auditor's findings about them. In the SOC 2 context, it is the deliverable that results from an attestation examination, not a certificate. It tells readers what controls were examined and whether they were suitably designed, and in some cases whether they operated effectively over a defined time period.
A Report on Controls is the deliverable of an attestation engagement performed by a licensed CPA firm under the AICPA SSAE 18 standard, in which a service auditor reports on a service organization's system and the controls relevant to the applicable Trust Services Criteria. A SOC 2 Type I report addresses the suitability of the design of controls at a specified point in time, while a SOC 2 Type II report addresses both design suitability and operating effectiveness over a defined review period whose length is set by scoping decisions rather than fixed by the standard. The report attests only to the controls and the period or point in time covered and does not constitute a certification, nor does it guarantee the absence of security breaches; its assurance is bounded by the defined scope, the selected criteria (Security is required as the Common Criteria, with Availability, Processing Integrity, Confidentiality, and Privacy optional), and the professional judgment of the service auditor. This should be distinguished from an ISO/IEC 27001 certificate, which is issued by an accredited certification body against a management system standard rather than produced as an attestation report, and from related SOC 1 and SOC 3 report types, which serve different purposes and audiences.
Why it matters
For most service organizations, a Report on Controls is the primary evidence they can hand to customers and prospects to demonstrate the state of their control environment. Rather than asking each customer to conduct its own audit, a service organization can commission a single attestation examination by a licensed CPA firm and share the resulting report under appropriate confidentiality arrangements. This makes the report a central artifact in vendor due diligence and third-party risk management, particularly for SaaS providers and other organizations that process data on behalf of their customers.
Understanding what the report is, and what it is not, matters because its assurance is bounded. A SOC 2 report attests only to the controls described and the point in time or review period covered; it does not guarantee that no security breach will occur, nor does it function as a certification. Readers who treat the report as a blanket seal of security misread its scope. A Type I report speaks only to whether controls were suitably designed at a specified date, while a Type II report additionally addresses whether those controls operated effectively over a defined period, so the type and the period covered materially change what a reader can conclude.
Because the report reflects the selected Trust Services Criteria and the professional judgment of the service auditor, two reports are rarely directly comparable without examining their scope. A report that covers only the required Security (Common Criteria) category conveys different assurance than one that also addresses Availability, Processing Integrity, Confidentiality, or Privacy. Reading the scope, the period, and the auditor's opinion carefully is essential to using the report responsibly in a compliance or procurement decision.
Who it's relevant to
Inside Report on Controls
Common questions
Answers to the questions practitioners most commonly ask about Report on Controls.