

SOC 1 is a leading framework for managing internal controls over financial reporting (ICFR) in service organisations. It is especially relevant for financial, payroll, SaaS, and BPO providers whose systems impact client financial statements. SOC 1 reports are performed under SSAE 18 (AT-C 320) or ISAE 3402, and are intended for user entities and their financial auditors. This guide breaks the journey into seven structured steps, aligned with best practice from ISO and Annex SL, while tailored to SOC 1’s audit-driven environment.
Each step includes actionable guidance, real-world examples, common risks, and practical support from AvISO and ISOvA to simplify and accelerate your compliance journey.

(SOC 1 scoping and readiness)
What this step covers
How to
Example A payroll provider includes payroll processing, adjustments, reporting, and year-end outputs in scope, but excludes HR advisory services handled by partners.
Risks if overlooked
How AvISO and ISOvA help

(Governance and accountability)
What this step covers
How to
Example A CFO signs the SOC 1 policy set and assigns owners for payroll, IT, HR, and incident response.
Risks if overlooked
How AvISO and ISOvA help

(Risk assessment and compliance planning)
What this step covers
How to
Example A payments platform identifies third-party hosting risks, user access gaps, and fraud scenarios in its SOC 1 risk register.
Risks if overlooked
How AvISO and ISOvA help

(Policy development and control design)
What this step covers
How to
Example An accounting firm documents 25 policies and 80+ supporting records, stored and version-controlled using ISOvA.
Risks if overlooked
How AvISO and ISOvA help

(Control execution and monitoring)
What this step covers
How to
Example A payroll firm automates audit log reviews and escalates incidents into a documented corrective action process.
Risks if overlooked
How AvISO and ISOvA help

(Audit readiness and internal review)
What this step covers
How to
Example A SaaS company runs a pre-audit simulation with AvISO, identifying two documentation gaps and one expired access token.
Risks if overlooked
How AvISO and ISOvA help
Need help with our how-to guide, have a question, or want to know more about how we can help you gain certification? Get in touch.
Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk