Scrutineer.ai

Scrutineer · By framework

SOC 1 compliance software for SSAE 18 reports and Type 2 audits

A SOC 1 has no standard criteria. Your management writes the control objectives and a CPA firm tests what you wrote, which is why a downloaded checklist never quite fits.

Scrutineer holds the objectives, the controls sitting under them and the evidence for every month of the period, so the description of the system matches what actually ran.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOC 1 compliance software

The trigger is your customer financial audit, not your security program

A SOC 1 exists for one reason: your service touches something that ends up in your customers financial statements. Payroll, claims processing, billing and receivables, loan servicing, fund administration, custody and transfer agency work all qualify. Under AU-C 402 a user auditor has to understand controls at any service organization relevant to internal control over financial reporting, and a SOC 1 is how they get that understanding without auditing you themselves. If nobody is relying on you for a number in a financial statement, you probably need a SOC 2 instead. Scrutineer pins that question first, because building the wrong report is a full year lost.

Nobody hands you the control objectives, and that is the hard part

SOC 2 gives you the Trust Services Criteria and you map to them. SOC 1 gives you nothing. Management writes the control objectives, tied to the risks your processing creates for the user entities, and the service auditor tests what you wrote. Write them too narrowly and you get a clean opinion that your customers auditors still cannot rely on, which is the worst possible outcome because it costs the full fee and buys nothing. Scrutineer keeps each objective next to the controls that support it and the evidence that proves the control ran, so a gap in coverage is visible before fieldwork, not after.

A Type 2 covers a period, so the evidence has to exist for the whole period

A Type 1 describes design at a point in time. A Type 2 tests operating effectiveness across a stated period, commonly six to twelve months, and that changes what evidence means. A screenshot taken the week before fieldwork does not show that quarterly access reviews happened in month two. Scrutineer pulls proof from your identity, ticketing and cloud systems on a schedule and timestamps it, so a sample drawn from any month in the window has something behind it. It also tracks the gap between your period end and each customer fiscal year end, which is what a bridge letter is meant to cover.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Settles whether your service is actually ICFR relevant, so you scope a SOC 1 rather than defaulting to a SOC 2 your customers did not ask for
  • Holds management written control objectives with the controls and evidence mapped under each one, instead of in a spreadsheet nobody updates
  • Timestamps evidence across the full Type 2 period, so a sample from month two has proof behind it rather than a screenshot from last week
  • Tracks complementary user entity controls so the CUEC list in your description reflects what you genuinely depend on customers to do
  • Records subservice organizations and whether each is carved out or included, and flags when a carved out provider SOC report has lapsed
  • Reuses the same evidence base for SOC 2, ISO 27001 and SOX Section 404, because the IT general controls underneath them overlap heavily
  • Keeps the description of the system aligned with what changed during the period, which is where most exceptions actually originate
  • Flags the window between your report period end and each customer year end, so bridge letters go out before the request arrives
  • Answers the control questionnaires and CUEC confirmations that user auditors send during their own busy season
SOC 1 COMPLIANCE SOFTWARE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Report reference

What your customer actually asked for, who writes the criteria, and who is allowed to read it

Most comparisons of SOC reports line up SOC 1, SOC 2 and SOC 3 as though they were three tiers of the same thing. They are not. The distinction that decides your project is who writes the criteria: for SOC 2 the AICPA does, and you map to a fixed list. For SOC 1 your own management does, and a clean opinion on badly written objectives is worth nothing to the auditor who asked. Find the row that matches the request you received, then read the last column, because that is where the money is lost.

What you were asked for Who writes the criteria What it actually covers Who may read it Where it goes wrong
A SOC 1 Type 2 report Your management writes the control objectives. The AICPA publishes no criteria list for SOC 1. Design and operating effectiveness of controls relevant to customers financial reporting, tested across a stated period of commonly six to twelve months Restricted use: your management, your user entities, and their financial statement auditors Objectives written too narrowly. You get a clean opinion, pay the full fee, and the user auditor still cannot place reliance on it under AU-C 402.
A SOC 1 Type 1 report Your management, same as a Type 2 Suitability of design and implementation at a single point in time. No testing of whether controls actually operated. Restricted use, same audience Treated as a cheaper substitute. It is a reasonable first year step, but a user auditor relying on your controls generally cannot use a Type 1, and no bridge letter is available for one.
A SOC 2 report The AICPA, through the Trust Services Criteria: security, plus any of availability, processing integrity, confidentiality and privacy Security and operational commitments. Not financial reporting. Restricted use, though widely shared under NDA with prospects and vendor risk teams Sent to a customer external auditor who asked for financial reporting assurance. A SOC 2 does not answer AU-C 402 no matter how thorough it is.
A SOC 3 report The AICPA Trust Services Criteria, same as SOC 2 A short general use summary of a SOC 2 Type 2 examination, without the detailed tests and results General use. You may publish it on your website. Asking for a public SOC 1. There is no SOC 3 equivalent for SOC 1, so a publishable financial controls report simply does not exist.
SSAE 18 certification, or SSAE 16 certification Nobody. The request is malformed and the honest reply is a correction. SSAE 18 is the standard that created AT-C 320, the section a SOC 1 is performed under. SSAE 16 was its predecessor and was superseded in 2017. Not applicable Answering yes. There is no SOC 1 certificate and nobody is SSAE certified. Claiming otherwise in a security questionnaire is a misstatement a diligent buyer will catch.
An ISAE 3402 report Your management writes the objectives, exactly as in SOC 1 The international equivalent of SOC 1, issued under IAASB standards, commonly requested by European and Asian auditors Restricted use, scoped by the reporting framework Commissioning a second, separate examination. A CPA firm can usually issue a combined SOC 1 and ISAE 3402 report from one set of fieldwork, so paying twice is avoidable.
A bridge letter, or gap letter Your management writes and signs it. The service auditor does not. An assertion that nothing material changed between your report period end and the customer year end, typically covering no more than three months The same audience as the report it bridges Assuming it carries audit weight. It is unaudited management representation, only available for a Type 2, and some user auditors decline it entirely or refuse long gaps.
Assurance over a subservice organization you carved out Your management identifies the complementary subservice organization controls it expects The description names the subservice organization and the controls expected of it. Those controls are named, not tested. The same audience as your report Reading CSOCs as tested coverage. They are a disclosure, not an assertion, and your customer still has to obtain the subservice organization own SOC report to close the chain.

Reflects the standards in force as at August 2026. A SOC 1 is performed under AT-C section 320, created by SSAE 18, layered on AT-C 105 and AT-C 205 as revised by SSAE 21, with the SSAE 23 quality management amendments applying to engagements beginning on or after December 15, 2025. SSAE 21 did not replace SSAE 18 for SOC 1, contrary to a good deal of published guidance. Scrutineer prepares and maintains control evidence. It does not perform examinations, and no software vendor can issue a SOC 1 opinion.

Good questions

Questions about SOC 1 compliance software

A SOC 1 report is a CPA firm examination of the controls at a service organization that are likely to be relevant to its customers internal control over financial reporting. It is performed under AT-C section 320, the section created by SSAE 18. The report contains management description of the system, management assertion, and the service auditor opinion and, in a Type 2, the tests performed and their results.
SOC 1 compliance is loose shorthand, because there is nothing to be compliant with in the usual sense. There is no rule book and no pass mark. What exists is an annual examination in which your management states its control objectives and asserts the controls were suitably designed and, for a Type 2, operating effectively across a period. A CPA firm then issues an opinion on that assertion.
Service organizations whose processing affects their customers financial statements. In practice that means payroll processors, claims administrators, billing and receivables services, loan and mortgage servicers, fund administrators, transfer agents, benefit plan recordkeepers, and increasingly any SaaS platform that calculates revenue, holds funds or produces the numbers a customer books. The request almost always comes from a customer external auditor rather than from the customer procurement team.
SOC 1 covers controls relevant to financial reporting and its control objectives are written by your management. SOC 2 covers security and related commitments and its criteria are fixed by the AICPA Trust Services Criteria. The practical test is who is asking: a customer financial statement auditor wants a SOC 1, a customer security or vendor risk team wants a SOC 2. Many companies genuinely need both.
A SOC 1 Type 2 reports on both the suitability of design and the operating effectiveness of controls across a stated period, usually six to twelve months. The service auditor tests samples drawn from that period and publishes the tests and results, including any exceptions. It is the report a user auditor normally needs, because reliance requires evidence that controls actually operated, not just that they were designed.
A Type 1 covers the design and implementation of controls at a single point in time. A Type 2 covers design plus operating effectiveness over a period. A Type 1 is faster and cheaper and is a reasonable first year step, but a user auditor relying on your controls under AU-C 402 usually cannot use one. Most organizations do a Type 1 once, then move to an annual Type 2.
Yes, and a lot of published guidance gets this wrong. SSAE 21 revised AT-C 205 and added direct examinations at AT-C 206, but it did not touch AT-C 320, the SOC 1 section that SSAE 18 created. A 2026 SOC 1 is performed under AT-C 320 layered on AT-C 105 and AT-C 205 as revised. SSAE 23 quality management amendments apply to engagements beginning on or after December 15, 2025.
No. Nobody is SOC 1 certified, SSAE 18 certified or SSAE 16 certified, and no body issues such a certificate. The deliverable is an attestation report containing a licensed CPA firm opinion on management assertion. Any vendor claiming SOC 1 certification is describing something that does not exist. SSAE 16, the predecessor standard people still cite, was superseded in 2017.
They are statements of what your controls are meant to achieve for the user entities, written by your management rather than selected from a list. A typical objective reads like controls provide reasonable assurance that transactions are recorded completely and accurately in the period in which they occur. The AICPA does not publish a set for SOC 1, which is why two service organizations in the same industry can have quite different reports.
Not in the way people expect. Because management writes the control objectives, there is no authoritative checklist that fits every service organization. What generalizes is the underlying layer: IT general controls over access, change management, and operations, plus the process controls specific to what you do. Anything marketed as the SOC 1 checklist is really a starting inventory of IT general controls, which is useful but is not the report.
Most Type 2 periods run six to twelve months, with twelve becoming standard once a program is established. The period matters to your customers: a user auditor wants coverage that overlaps their financial year, so the choice of period end is a commercial decision as much as an audit one. Shorter first year periods are common and normally acceptable, provided the gap afterwards is bridged.
Published figures vary widely and depend heavily on scope and auditor tier, so treat any single number carefully. Linford and Company, an audit firm, reported in February 2026 that SOC examinations typically run from 20,000 to 150,000 dollars with a median near 30,000, and that large firm engagements start in the low six figures. Confirm with quotes from firms that match your size, and price readiness separately.
A bridge letter, also called a gap letter, is a statement from your management that nothing material changed between the end of your report period and a customer year end. It typically covers no more than three months. It matters that it is unaudited: your management signs it, not the service auditor, and some user auditors will not accept one at all.
CUECs are controls your report assumes the customer performs. If your objectives can only be met when the customer reviews an output report, approves a change or manages its own user accounts, that expectation has to be disclosed. Customers frequently ignore the CUEC list, then discover during their own audit that they inherited work. An honest, short CUEC list is worth more commercially than a long defensive one.
When you rely on a subservice organization such as a cloud host or payment processor, you either carve it out or include it. Carve-out is far more common: the description names the service and the complementary subservice organization controls you expect, but those controls are not tested in your report. Your customer then has to obtain the subservice organization own SOC report to close the loop.
No. SOC 3 exists only for SOC 2, as a short general use summary you can publish. SOC 1 reports are restricted use, intended for your management, your user entities and their financial statement auditors, so there is no public version. If a prospect asks for a SOC 1 they can post publicly, the honest answer is that no such report exists.
ISAE 3402 is the international equivalent of SOC 1, issued under IAASB standards, and customers with European or Asian auditors often ask for it by name. A CPA firm can frequently issue a combined SOC 1 and ISAE 3402 report from one set of fieldwork. Commissioning two separate examinations for the same controls duplicates the work and the fee.
No. Scrutineer holds your control objectives, controls and dated evidence and shows where coverage is thin before fieldwork starts. The examination is performed by an independent licensed CPA firm and the opinion is theirs. No software can issue a SOC 1 report, and we are explicit about that line rather than implying a subscription closes the obligation.

Keep reading

Guides that go deeper on service organization reporting

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification