Service Auditor
A service auditor is the licensed CPA firm that examines a service organization's controls and issues a SOC report on the results. This is the independent party that performs the assessment, rather than the company being assessed.
A service auditor is a licensed CPA firm that performs attestation engagements over a service organization's controls under the applicable AICPA standard, including SOC 1, SOC 2, and SOC 3 examinations. In a SOC 2 engagement, the service auditor evaluates the controls relevant to the selected Trust Services Criteria and issues an attestation report (either Type I, assessing suitability of design at a point in time, or Type II, assessing design and operating effectiveness over a defined review period). The service auditor is distinct from the service organization's management, which is responsible for the description of the system and the controls being examined; the resulting output is a report rather than a certification, and it attests only to the controls and period covered.
Why it matters
The service auditor is the independent party whose examination gives a SOC report its credibility. Because the auditor must be a licensed CPA firm performing the engagement under the applicable AICPA attestation standard, the report reflects an assessment conducted by a party distinct from the service organization's own management. This independence is what allows customers, prospects, and other stakeholders to place reliance on the results rather than depending solely on the service organization's self-assertions about its controls.
Understanding who the service auditor is also clarifies what a SOC engagement can and cannot deliver. The service auditor evaluates controls relevant to the selected Trust Services Criteria and issues an attestation report, not a certification. That report attests only to the controls and the period covered, so it does not guarantee that the service organization is free from breaches or that controls performed as intended outside the examined scope. Distinguishing the service auditor's role from that of management, who owns the description of the system and the controls, helps readers interpret the report's boundaries correctly.
The distinction also matters when comparing SOC engagements to ISO/IEC 27001, where the assessing party is an accredited certification body rather than a CPA firm, and the outcome is a certificate against a management system standard rather than an attestation report. Recognizing that a SOC report comes from a service auditor, and an ISO 27001 certificate comes from a certification body, prevents readers from treating the two frameworks or their outputs as interchangeable.
Who it's relevant to
Inside Service Auditor
Common questions
Answers to the questions practitioners most commonly ask about Service Auditor.