This course provides a comprehensive overview of SOC 2 reports, focusing on their structure, purpose, and how to interpret and apply them in a compliance or risk management context. Participants will learn about the five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy), the difference between Type I and Type II reports, and the key components of a SOC 2 report including the system description, management assertion, and testing results. The course also covers common pitfalls in relying on SOC 2 reports and best practices for evaluating scope, subservice providers, and complementary user controls. Designed for auditors, compliance professionals, and vendor risk reviewers, this session equips attendees to effectively analyze and apply SOC 2 reports in real-world scenarios. This event may be a rebroadcast of a live event and the instructor will be available to answer your questions during the event. This course qualifies for Yellowbook.
Learning Objectives
After attending this presentation, you will be able to...
- Identify the scope and key requirements of the AICPA NOCLAR ethics interpretations.
- Recall the auditor's requirements with respect to NOCLAR communication
- Recognize how Yellow Book addresses NOCLAR communications
Major Topics
The major topics that will be covered in this course include:
- Participants will review the scope of the interpretations
- The responsibilities of members in public practice and members in business
- Considerations involving confidentiality, communication, documentation, withdrawal, and further action in the public interest. Related requirements under SAS No. 147 and the 2024 Yellow Book, including how auditors must handle communications related to NOCLAR.