SOC 1 Compliance Checklist
Assess and document your organization's internal controls for SOC 1 compliance.
Organization Name
*
Contact Person (Full Name)
*
First Name
Last Name
Email Address
*
example@example.com
Assessment Date
*
-
Month
-
Day
Year
Date
Department/Business Unit
*
Role of Assessor
*
Type of SOC 1 Assessment
*
Type I
Type II
Other
Internal Controls Assessment
*
Rows
Yes
No
Not Applicable
Access to financial systems is restricted to authorized personnel.
1
2
3
User access is reviewed and updated regularly.
4
5
6
Segregation of duties is enforced for financial processes.
7
8
9
System changes are documented and approved before implementation.
10
11
12
Backups of financial data are performed regularly.
13
14
15
Incident response procedures are documented and tested.
16
17
18
Physical access to sensitive areas is controlled.
19
20
21
Vendor management processes are in place for outsourced services.
22
23
24
Rate your overall confidence in your organization's current SOC 1 control environment.
*
Low
1
2
3
4
High
5
1 is Low, 5 is High
Please provide any comments, explanations, or planned improvements related to your SOC 1 controls.
Assessor's Signature
*
Submit Checklist
Submit Checklist
Should be Empty: