ACC 645 Module 2 SOC Report Assignment Example

Reviewed by Portia Lambrick, MBA

This ACC 645 Module 2 SOC Report Assignment sample examines an attestation engagement on a service organization's controls and how other auditors rely on it. Prepared for SNHU ACC 645 (ACC-645), the advanced auditing course in the MS Accounting program, it answers Module Two's assignment on SSAE 18 and service organization reporting. A composite Nasdaq-listed payroll and HR software company near Pittsburgh processes payroll for about 9,000 employers, whose auditors need assurance about its controls. The assignment explains why a SOC 1 Type 2 report fits, sets out the control objectives and period, handles two subservice organizations, lists complementary user entity controls, evaluates an access removal exception and shows how a customer's auditor uses the report.

CourseACC 645 Advanced Auditing
ModuleModule 2
Paper typegraduate assignment on service organization control reports
LengthAbout 1,020 words, 6 pages
FormatAPA 7 student paper
SchoolSouthern New Hampshire University
ProgramMS Accounting
UpdatedOctober 2026

Free sample paper for ACC 645 Module 2

1

SOC 1 Type 2 Engagement for the Payroll Processing Platform

[Student Name]

Southern New Hampshire University

ACC 645: Advanced Auditing

Module Two Assignment

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title names the report type and system.
2

SOC 1 Type 2 Engagement for the Payroll Processing Platform

Introduction

The company processes payroll for about 9,000 employers: it calculates gross pay, withholdings and employer taxes, moves funds, files federal, state and local payroll tax returns and remits the taxes. For those employers, payroll expense and tax liabilities are material, and their auditors need evidence about controls they cannot test themselves. This assignment plans the service auditor's SOC 1 Type 2 engagement under SSAE 18 (American Institute of Certified Public Accountants, 2016) and explains how a customer's auditor would use the report.

What this page is doingThe engagement and its users are identified.
3

Choosing the Report

SOC 1 reports address controls at a service organization that are likely to be relevant to user entities' internal control over financial reporting. Payroll calculation, tax filing and fund remittance are exactly that. A SOC 2 report would address security, availability, processing integrity, confidentiality or privacy under the Trust Services Criteria, which matters to customers concerned about employee data, and the company issues one separately for its HR software. A Type 2 report, covering both design and operating effectiveness over a period, is needed because user auditors want to rely on the controls across their fiscal year, not at a single date.

What this page is doingSOC 1 Type 2 fits the users' need.
4

System, Period and Control Objectives

The report covers the payroll processing system for the twelve months ended September 30, 2025, a period that overlaps most customers' fiscal years. Management's description includes the following control objectives.

Control objectives in the description

NumberControl objective
1Payroll input received from customers is authorized and recorded completely and accurately
2Gross pay, withholdings and employer taxes are calculated accurately using current rates
3Payroll funds are collected and disbursed completely, accurately and on time
4Tax returns are filed and taxes remitted accurately and on time
5Logical access to programs and data is restricted to authorized individuals
6Program changes are authorized, tested and approved before implementation
What this page is doingThe scope is defined.
5

Subservice Organizations

Two other organizations perform functions within the system: a cloud provider hosts the platform, and a data vendor supplies updated tax tables for about 7,000 jurisdictions. The company uses the carve-out method, so the description identifies the services each provides and the controls the company expects them to have, but the service auditor does not test their controls. The company monitors them by reviewing their own SOC reports annually and by testing a sample of tax table updates against published rates each quarter. User auditors who need assurance about the cloud host must obtain its SOC 1 report themselves.

What this page is doingThe carve-out method is used.
6

Complementary User Entity Controls

Several control objectives can be achieved only if customers do their part. The description lists five complementary user entity controls: customers authorize payroll changes before submitting them, review payroll registers before approval, restrict access to the platform to authorized staff, review tax filings provided by the company and reconcile payroll bank accounts monthly. A user auditor must test these at its own client; if a customer does not review its registers, the company's controls over input do not by themselves prevent errors.

What this page is doingCustomers' responsibilities are listed.
7

Testing and an Exception

The service auditor tested each control over the period, using sample sizes based on frequency: 40 for daily or per-event controls, 25 for weekly and all four quarters for quarterly reviews. One exception arose under objective 5. For 2 of 40 terminated employees sampled, access was removed six and nine days after termination, against a policy of three days. Neither account was used after termination, according to system logs. The quarterly access review, also a control under objective 5, identified and removed both accounts within 45 days.

Under the attestation standards, the opinion addresses whether controls were suitably designed and operated effectively to achieve each control objective. Because the quarterly review operated effectively and logs showed no use, the service auditor concluded that objective 5 was achieved. The exception is described in the tests and results section with management's response, and the opinion is unmodified. Had the review also failed, the opinion would have been qualified for objective 5.

What this page is doingThe access objective is evaluated.
8

Structure of the Report and Use Restrictions

The finished report has five parts: the service auditor's opinion; management's written assertion that the description is fairly presented and the controls were suitably designed and operated effectively; management's description of the system; the service auditor's description of tests of controls and results, including the exception; and optional other information from management, such as its response and remediation plans, which the opinion does not cover. Because a SOC 1 report is meant for customers and their auditors, who understand how it fits into a financial statement audit, its use is restricted to those parties. It cannot be posted on the company's website as marketing material. Customers who want a general-use document can be pointed to the SOC 3 report the company obtains for its HR platform. The service auditor must be independent of the company, and, because the company is also a public audit client of a different office of the same firm, the firm confirmed that the attestation team had no role in the financial statement audit and that the engagement was preapproved by the audit committee.

What this page is doingThe deliverable is described.
9

Use by User Auditors

A user auditor auditing a calendar-year customer would apply PCAOB AS 2601 (Public Company Accounting Oversight Board, 2016) or its AICPA equivalent. It would evaluate the report's period and scope, the service auditor's competence and independence, the description of tests and results, including the access exception, and the complementary user entity controls at its client. Because the report ends September 30, the user auditor would obtain a bridge letter from the company stating whether controls changed from October through December, and would perform additional procedures if they had, for example on the year-end tax rate updates. Arens et al. (2020) note that a SOC report reduces but does not eliminate the user auditor's work, since the user auditor remains responsible for its opinion.

What this page is doingReliance is planned.
10

Conclusion

A SOC 1 Type 2 report allows thousands of customer auditors to rely on one set of tests, reducing duplicated work for both the company and its customers. Its usefulness depends on clear control objectives, honest treatment of exceptions and customers performing their own complementary controls.

What this page is doingThe report's value is summarized.
11

References

American Institute of Certified Public Accountants. (2016). Attestation standards: Clarification and recodification (Statement on Standards for Attestation Engagements No. 18). Author.

Arens, A. A., Elder, R. J., Beasley, M. S., & Hogan, C. E. (2020). Auditing and assurance services (17th ed.). Pearson.

Public Company Accounting Oversight Board. (2016). Consideration of an entity's use of a service organization (AS 2601). Author.

What the ACC 645 Module 2 instructions ask for

The Module Two assignment in ACC 645 usually asks you to plan, evaluate or use a service organization control report. Plan to explain the difference between SOC 1, SOC 2 and SOC 3 reports and between Type 1 and Type 2, identify the system, the control objectives or criteria and the period, decide how to treat subservice organizations under the inclusive or carve-out method, and list complementary user entity controls. Many versions include exceptions found in testing and ask whether they lead to a modified opinion, and some ask how a user auditor would rely on the report under PCAOB AS 2601 or the AICPA's equivalent. Cite SSAE 18 and the attestation standards specifically, since this is an attestation engagement, not an audit.

How this ACC 645 Module 2 soc report assignment example is built

The paper explains that the company's customers need assurance over controls relevant to their financial reporting, payroll expense, withholdings and tax liabilities, so a SOC 1 Type 2 report covering October 1, 2024 to September 30, 2025 is the right product; a SOC 2 would serve customers concerned with security and privacy of employee data. It lists six control objectives, carves out the cloud host and a tax-table vendor and names five complementary user entity controls. Testing found that 2 of 40 terminated employees kept access for more than three days, but a quarterly access review removed them, so the access objective was achieved and the opinion is unmodified.

Where the ACC 645 Module 2 rubric puts the points

Rubrics for the SOC report assignment typically score selection of the right report type, the description of the system and control objectives, treatment of subservice organizations and user entity controls, evaluation of exceptions, the opinion, guidance for user auditors and use of the attestation standards. Top papers explain why a SOC 1 rather than a SOC 2 answers financial reporting needs, describe what the carve-out method leaves out, evaluate exceptions against the control objective rather than the individual control and explain the bridge letter. Common deductions include applying audit standards to an attestation engagement, ignoring complementary user entity controls, treating any exception as requiring a qualified opinion and overlooking the gap between the report period and customers' year ends.

ACC 645 Module 2 help: the mistakes that cost points

SOC report papers most often slip by evaluating exceptions control by control, when the opinion addresses whether each control objective was achieved, so compensating controls within the same objective matter. A second weak spot is the carve-out method, where students forget that the user auditor must then obtain evidence about the subservice organization separately. If your assignment involves a SOC 2, the structure is the same but the criteria are the Trust Services Criteria for security, availability, processing integrity, confidentiality or privacy. Map each exception to its control objective before deciding on the opinion; it prevents an unnecessary qualification.

Get ACC 645 Module 2 written to your instructions

Send the ACC 645 Module 2 assignment and the service organization facts. The paper will choose the right report, frame the system and control objectives, evaluate exceptions for the opinion and explain how user auditors rely on it with the standards cited. Turnaround is two days, and the first is on us. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

More ACC 645 papers and related MS Accounting samples

ACC 645 Module 2 questions, answered

Where can I find a free ACC 645 Module 2 SOC Report sample?

This page includes a full ACC 645 Module 2 assignment on a SOC 1 Type 2 report for a payroll processor.

What is the difference between SOC 1 and SOC 2 reports?

A SOC 1 report addresses controls relevant to user entities' internal control over financial reporting; a SOC 2 report addresses controls relevant to security, availability, processing integrity, confidentiality or privacy.

What is the difference between a Type 1 and a Type 2 report?

A Type 1 report covers the fairness of the description and the suitability of control design at a point in time; a Type 2 adds the operating effectiveness of controls over a period.

What is the carve-out method?

A way of presenting a subservice organization in which its controls are excluded from the description and testing, with the report identifying the services it provides and the controls expected of it.

What are complementary user entity controls?

Controls the service organization assumes its customers will implement, such as reviewing payroll registers, which are necessary for the control objectives to be achieved.