Assurance & SOC firms
SOC delivery support for your assurance practice
Agreed evidence, testing and documentation support for SOC 1 and SOC 2 engagements led by your firm.
Keep engagement leadership and reviewer authority with your practice. Add defined delivery capacity around the control areas, reporting period and evidence needs you agree with us.
For the firm leading the engagement
Make evidence work reviewable
A control description, a system export and a screenshot often tell different parts of the same story. We help organise those records against the firm's agreed control matrix, identifying which evidence relates to which control, period and procedure. Mapping is a preparation activity; it does not establish that a control operated effectively.
For SOC 1 work, the scope follows the firm's identified controls relevant to user entities' financial reporting. For SOC 2 work, evidence is organised around the criteria and system boundaries the firm has selected. We do not treat the two engagements as interchangeable or reuse a conclusion without considering its context.
Documentation support can include request tracking, control-to-evidence references, testing records and open-item lists. Agree the templates and review checkpoints so a busy period does not produce working files that the engagement team must reconstruct later.
AuditPartners does not issue SOC reports. It is not a CPA firm or a certification body and does not issue audit opinions or certificates. The responsible firm keeps engagement responsibility, judgment, review and report issuance; certification decisions stay with the responsible body.
Assurance & SOC firmsTesting under your instructions
From control mapping to a reviewed file
Begin with an agreed assignment, not an open-ended evidence collection exercise. Your team sets the methodology, testing approach and required review, while our professionals carry out the defined delivery work.
Align requests to controls
Confirm the control descriptions, owners, reporting period and evidence expected for each procedure. Track received records against the request list and raise unclear ownership, missing periods or changed control descriptions with the engagement team.
Prepare populations and selected samples
Assist with reconciling agreed populations, documenting extraction criteria and assembling evidence for selected items. The firm determines sampling and evaluates population suitability. Limitations in an export or gaps in the period are recorded for a reviewer, not silently excluded.
Perform the assigned testing
Follow the agreed instructions and document the evidence inspected, observed result and questions requiring follow-up. Distinguish a missing record from an identified deviation. Any additional procedure or change in testing scope is agreed with the firm before it is carried out.
Review before handoff
A professional checks the preparation, cross-references and exception record before your reviewer receives it. Where agreed, RiskAssist™ supports evidence intake, control mapping, consistency checks and draft analysis, operated by our professionals with human review. It does not decide the reporting implications of an exception.
Technical work and delivery capacity
Bring specialists into defined control areas
Agree IT and security specialist support for access administration, privileged access, change management, system operations or cloud controls in scope. The assignment should identify what needs technical interpretation, which records are available and who on the firm's team will review the work.
Specialists can help explain the relationship between a policy, a configuration and an operating record. They document limitations and questions for the engagement team rather than extending the system boundary or accepting a management explanation on the firm's behalf.
Delivery personnel, qualifications, location and availability are agreed per engagement. Tools, AI assistance, evidence access and confidentiality are subject to the applicable agreement. Co-delivery, white-label presentation, client protection and confidentiality are offered subject to the applicable agreement for each engagement.
For a first assignment, select a control area with a clear reviewer and an agreed evidence set. Review the preparation and escalation process together before deciding whether to add more control areas or support another reporting period.
A separate path for enterprises
Preparing your organisation for a SOC 2 auditor?
SOC 2 readiness is different from delivery support for an assurance firm. An organisation preparing for an auditor may need to clarify control ownership, identify missing records and understand whether its evidence covers the intended systems and period. That work is scoped separately from the auditor's engagement.
An agreed readiness assessment can produce a gap list, evidence requests and practical next steps for management. Management owns the controls and remediation. Readiness work is not a SOC examination, does not result in a SOC report and cannot guarantee the future auditor's conclusions.
Implementation help and independent audit work are agreed separately. Discuss existing advisers and the intended auditor before work starts so independence and conflicts can be evaluated rather than assumed.
Explore readiness and gap assessmentsDiscuss enterprise readinessAgree the next assignment with your practice
Bring your control areas, reporting period and review requirements. We can discuss a bounded pilot under your firm's methodology.