At RubinBrown, our team of professionals understand the value that System and Organization Controls (SOC) reports bring to both service organizations and user entities in today's marketplace to reduce third-party risk.
At RubinBrown, our team of professionals understand the value that System and Organization Controls (SOC) reports bring to both service organizations and user entities in today's marketplace to reduce third-party risk.
It is becoming increasingly common for businesses to outsource aspects of their operations to a trusted third party. At RubinBrown, our team of consultants understands the value that System and Organization Controls (SOC) reports bring to both service organizations and the user entities that rely on them. We help organizations navigate the requirements of SOC 1®, SOC 2®, SOC 3® and related examinations, reducing third party risk and easing audit fatigue along the way.
If an error in your systems could misstate your customers' financial statements, you likely need a SOC 1. SOC 1 reports address controls at a service organization that are relevant to a user entity's internal control over financial reporting (ICFR).
If your customers are asking whether they can trust you to securely handle their data, you likely need a SOC 2. SOC 2 reports address the security, availability, processing integrity, confidentiality, and/or privacy of the systems a service organization uses to process user data, and are generally restricted to parties with sufficient knowledge of the organization and the services it provides.
SOC 3 reports cover the same trust services criteria as a SOC 2 (security, availability, processing integrity, confidentiality, and/or privacy), but are written for general use, so you can share them publicly, for example on your website or in marketing materials, without restriction.
SOC for Supply Chain examinations report on the controls within a manufacturing, production, or distribution system, communicating to stakeholders how an organization identifies, prevents, and responds to risks across its supply chain.
Many organizations need to report against more than one framework at once. A SOC 2+ engagement layers additional criteria onto your SOC 2 examination, commonly the Cloud Controls Matrix, HITRUST, HIPAA, ISO 27001, or NIST 800-53, so you can satisfy multiple stakeholders through a single, unified reporting effort instead of repeating the process framework by framework.
Audrey Katcher, CPA, CISA, CITP, CGMA
Partner | audrey.katcher@rubinbrown.com
Audrey has more than 30 years of IT audit and service organization control experience. She oversees RubinBrown's Information Technology Risk Services practice, including third party assurance, cyber attest, SOC services, and emerging services such as AI Governance and Risk Assessments. Audrey has been a contributing author of the American Institute of Certified Public Accountants (AICPA) SOC 2 Guide since its first release and serves as a signing partner for SOC 1 and SOC 2 engagements. She is a member of the AICPA's SOC 2 Working Group, served on the AICPA Board of Examiners, and sits on the International Board of Directors for Baker Tilly International Ltd.
Rob Rudloff, CISSP, ISSMP, CCSP, PMP
Partner | rob.rudloff@rubinbrown.com
Rob has more than 25 years of information security and cybersecurity experience across security reviews, mitigation, strategy, and architecture development. He is a Certified Information Systems Security Professional, Information Systems Security Management Professional, Certified Cloud Security Professional, and Project Management Professional.
Christine Figge, CPA, CGMA
Partner | christine.figge@rubinbrown.com
Christine has more than 20 years of public accounting and consulting experience. She brings a unique perspective to the SOC process, having used SOC reports as an auditor, assisted management in developing their system description and control identification, and performed the attestation services required to issue SOC reports for clients. Christine is a contributing author to the AICPA’s SOC for Service Organizations toolkit. She serves as a signing partner at RubinBrown and provides quality review services to CPA firms around the country for SOC 1, SOC 2 and SOC 3 engagements.
Katelyn Rattner, CISA
Partner | katelyn.rattner@rubinbrown.com
Katelyn Rattner has more than 13 years in public accounting, specializing in technology compliance and advisory services. She serves as a trusted advisor to both public and private sector clients, partnering with executive leadership to navigate complex regulatory environments, strengthen internal controls, and align technology strategies with broader business objectives.