In layman’s terms, can someone explain SOC vs SOX and any other major forms of reporting. Just started at a big 4 and it’s always mentioned in conversation as if I had ever learned about it :/

likefunny
Posting as :
works at
You are currently posting as works at

SOX is a law that requires that public companies (companies traded on the stock market) be audited by an external entity (e.g., a big four firm, any other audit firm) every year to ensure that the company’s financial statements are accurate. In a SOX audit, there is the financial statement audit (done by the assurance team) and the IT audit (done by the IT team). Both teams work together. The goal is to obtain reasonable assurance that whatever the company reported to the public on their financial statements was accurate.

SOC is a report that is published by an organization that provides services to other companies. For example, UltiPro is a HR and payroll application that is a cloud based application (it can be accessed over the web). A company can buy UltiPro to use in their organization. However, since UltiPro is cloud based, the application is hosted by UltiPro, therefore the company that buys the application cannot host it on their own servers. In order to ensure that UltiPro has proper controls/security in place to protect the company’s data, they go through a SOC audit. A third party auditor (e.g., a big four or other audit firm) will audit the applications controls. After the auditor reviews the controls, they publish a report to give an opinion on the security controls in place. This report can then be reviewed by every company that buys the software to ensure that their data is protected and safe.

I’m not sure what your experience is but hopefully this makes sense. SOC takes a little bit of background/research to grasp its importance. There’s also multiple types of SOC reports but I won’t get into that.

likehelpful

SOX refers to Sarbanes Oxley, which is legislation that details the requirements for all U.S. public companies.

SOC is System and Organization Controls which is AICPA speak for the reports produced from an audit.

likehelpful

To add on:

When people say SOX they're usually referring to either internal or external audits (of controls over financial reporting).

When people refer to SOC, they mean the attestation/report (that we read or produce) for companies who perform business to business services (I.e. service organizations)

likehelpful

A SOC can also refer to a Security Operations Center

likefunny

I doubt this person is confused as to the difference between a Security Operations Center and Sarbanes Oxley.

likefunny

A SOC report is issued by an independent auditor. A SOC report is typically used to demonstrate to clients and investors that your key business processes / services have suitable controls designed and operating effectively.

like

SOX is utilized by the CIA for enhanced interrogation

likefunny

Google is going to be your friend.

like

Goodness this was all so incredibly helpful. I know as a new hire I really look for mentoring so if anyone has any advice or insight they’d like to share, feel free to message me! Always looking to learn - thank you all again so much

like

One more thing I didn't see touched on- SOC and SOX clients both mostly involve controls testing so the work can be similar. SOC testing will be all IT controls (since the purpose is to attest to the system as a service is being operated effectively), while SOX will have both IT and business process controls (since the purpose is to attest the financial statements are not materially misstated). The IT controls in SOX and SOC should be similar enough someone could be on both types of engagements, especially at a staff level.

like

SOC is NOT all IT controls. This is an all too common misconception with SOC reports.

like

Related Posts

I was on a partner/manager call today and they were discussing the “high” turnover at the senior and experienced associate level. What was shocking is that while ours is about double normal, evidently we are 3 out of 4 in turnover meaning 2 of the Big 4 are even higher.

like

How would switching to big 4 tech consulting at 2 YOE look for mba applications? Would it hurt? Looking to matriculate 2023 or 2024 but don't want this move to hurt me if I do it.

It’s now been about a month since I cold applied to all big 4 firms for upcoming winter internships. I’ve tried reaching out to some of the recruiters in the area I applied for but no response. Is this white flag territory or is there still hope? And if it’s the ladder is there anything I can do to speed up the process or is it just a waiting game.

like

Partners, At IBM we have Band 8, 9, 10 (AP). If the three banded people were to apply for an opportunity in BIG 4, what levels will they typically be slotted?

like

At some Big 4 companies there is a Partner / Principal group that has equity and are part owners of the business and an equivalent Managing Director group that does not have equity and are essentially employees.

How does it work at McKinsey / Bain ? Do those same distinctions exist across partner types, owner vs non owner?

like

Are there any law firms out there with better comp than Big 4 tax and won’t work you more than 50 hours a week?

What are the average age brackets at Big 4 to be a Con, Senior Con, Manager, Senior Manager, Director, Partner? Keen for people’s perspectives.

like

hi everyone ,

I currently work as intern in one of the big 4, now I got an opportunity In deloitte with a package of 7.6l lpa (6l fixed, 1l joining ,bonus & 60k variable) for the same job role. it is through cmpus placement & recruiting us as freshers. I do have another 3 yrs of experience but it was for other role. considering the experience that i have ,is there any chance for me to negotiate in the salary?
please advise

Anyone can give insight in B4 Risk in Houston/Dallas market?

like

Experienced hires who have recently joined Big 4, how rough has the transition been?

like

Hey there, just got a mail from a recruiter at Bain to discuss a potential specialist consultant opportunity. Any tips on what the interview process might be like , indicative comp and WLB? I have 7 years experience in the releavnt field (Acc & Big 4) so will be joining laterally.
TIA

like

Hi ,
I am having 5.5 years of experience in software testing.

My current CTC:7.26lpa
Offer in hand: 1( Big 4 Company)
Offered CTC:12LPA

Can I try for other opportunities or can I join on this company?

What is the current salary for 5.5 years experience?

like

What happens if you don’t join due to better package from other big 4 after excepting the offer

exit opportunities for someone who got a good gpa from a well known school and a cpa who thought they would be doing something cool while building a foundation for a fruitful career but got stuck on state/federal claims and related government work instead? or is a full restart needed?

S1 at B4 now but looking to do something more traditional (?) that will provide opportunity in finance/accounting and not something ‘risk’ oriented that will pigeonhole me.

like

Anyone else with big 4 experience looking to find a rewarding career path with an undergrad degree in accounting? What career options are out there without having to go back to school?

like

Differences in FDD at accounting firms (big 4, rsm, GT, etc) vs non-accounting firms (HL, A&M, FTI)?

like

Boutique or big 4?

I'm currently an ops manager at a big 4 in London and received an offer from a small boutique firm with 25-30% pay rise.

I'm also in the process with Accenture but I feel like I'm not sure if I'd jump just for the money but also change in environment.
What type of things would you be asking yourself if you were in my shoes and debating to jump ship?

like

How do people get interview call from Accenture Strategy & Consulting? I am an MBA from tier 2, 5 YoE post MBA in Financial Risk. Currently working with a Big 4.

like

Is it worth to move to a Value Engineering and GTM role in a product based company from Deals Strategy and Value creation role in a Big 4? In the last one year, I only learnt Power Bi and Alteryx but no functional or domain knowledge. Offshore setup doesn't allow us to get full idea about what's happening in the front end. Please guys I need your thoughts on this.

likesmart

More Posts

Can we keep the Bosch company laptop with us permanently?

like

IEP, 504, and those without internet will return in-person next week while rest of students remain remote. Regular Ed teachers may have students (mild Learning Disabled kiddos) in their room while teaching. They are saying it’s a liability issue if they have one student in the room with them, even though teaching other via Zoom. Thoughts? Anyone else experiencing this?

like

Can anyone ask for offer revision after offer acceptance in zscaler?

Transitioning from line of business familiarity (understanding financial statements) to... real(?) Finance (bonds and cap markets and other debt sales) any advice on books or resources to learn really from step 0?

like

Does American Airlines have any status partnerships with hotels or rental cars, etc? (Eg. Platinum Marriott will get you united silver)

like

30 yo gent here... I need to start going on dates with people who travel more ... this going on dates with people in the same city every week has been a big of a struggle. Anyone single!?

like

Anyone in Boston area need an accountability partner. I have always wanted to help people get in shape or at least build self confidence and body positive vibes. Not ready to open a gym yet but I’m open to changing one life at a time. 😊

like

Joining in lti is virtual or we have to go office on that day and how is first week planned. Like some kind of full day induction or what?

like

Rumours of mass defection if the split goes ahead. Who in this bowl is planning to leave? And if you're thinking of staying, what is your rationale?

like

We actively hire global mobility tax, state and local tax, tax reporting advisory, and audit various sr and higher positions across the US at a top 6 public accounting firm. DM please

like

Anyone looking to hire an entry level accountant position with no experience?

It’s been difficult to get a job around here.

What I have:
- Bachelors in Accounting
- Starting Masters in Accounting in January 2023

like

What does a manager in big4/protiviti internal audit consulting do? I’m an experienced bank senior auditor and looking to make the switch to IA advisory. Do managers work on outsourced/co-source IA engagements and are they still preparing work papers?

like

I got offers from PragerM, UHY, and PKF. I think I made my decision but wanted to see if anyone had any insight of them. Would you not choose one for one reason or another? Or is there one that stands out and would jump on immediately? Thanks all.

like

❗️❗️❗️Is there anyone here from Infosys Consulting? Preferably at Principal/ Senior Principal Consultant level. Need urgent help❗️❗️❗️

like

Any Amazon counsel or other FAANG attorneys willing to share how their comp review has worked? I’m really happy with my offer(lower base, really high signing bonus and decent RSUs) and was told their would be yearly comp reviews but wondering how that plays out the first few years...

like

Business analytics or Data analytics ?
Who are payed more ?
They both seem to have the same tech stack
Excel - sql - python/r - tableau/powerbi

like

Does IBM have good onsite opportunities?

like

What in the world is this old spice YouTube thing ?

like

Hello, I'm looking for a referral for financial due diligence/M&A consultant roles in the Netherlands. If anyone can help please let me know. Happy to have a chat

like

How do you sell the benefits of managed money to your clients?

like

Additional Posts in Risk Assurance

How will blockchain impact us in the future?

Is KPMG, EY and PWC considerate about one not wanting to travel and chosing local projects in the IT Assurance practice? Please share your experiences. Thanks!

I lead our SOC practice for a US mid tier cpa/consulting firm. I've been losing a lot of deals due to lower cost / boutique vendors who are partnered with these SOC automation platforms (Vanta, Laika, etc.). Have any of you used these tools for the audit and what has your experience been like? Thanks

like

What’s the difference between Issues vs Findings?

like

Crowe is hiring for quite a few positions across the US (Internal Audit, IT controls and cyber/digital security, Compliance,etc)… I’m a manager and would think some of these niche areas have great opportunity for new folks to excel rather quickly. Great flexibility and mobility policies. I’d be happy to chat if interested and get you directly in touch with the right people internally.

likefunny

Does anyone have any good resources for auditing ESG?

Anyone can give insight in B4 Risk in Houston/Dallas market?

like

How do we go about renaming this bowl to Technology Risk? #ey

likefunny

Anyone can share experience working industry for SOX/IA roles? Is there work life balance, good pay, etc.?

like

Everyone I've met in my 2 years in IT Risk assurance hate it, me included. Who likes it and why? Just curious and to get some motivation!

like

For all you in IT audit what has your salary progression been YOY?

like

I currently work in IT Audit at Deloitte and have a degree in Management Information Systems. I'm looking to transition into a cyber security role either with or outside of the firm. Anyone have experience doing this and have any tips or ideas? Or have any tips on some certifications I could get that would make me more desirable?

like

Deciding between PWC Core Assurance or KPMG Internal Audit for associate role. Would love to hear from people here about what is best.

like

Looking for advice. I have a few offers in negotiations for Senior IT audit role. My main motive is to get out of toxic work culture in B4 consulting and public accounting. Looking for better wlb, better work culture and decent compensation to make good living. Currently in TX making around 110K TC.

1. Children’s Place: Base-110K . Probable bonus of 3-5%. No relocation assistance or sign on bonus. Based in NJ. Location is closer to all my friends and family
(Continued)

like
like

Interviewing around right now. What comp should I ask for M1 roles? IT Audit, NYC

like

Mid year promotions, I found out you need to make your own case for it rather than the firm coming to you. If you think you’re ready make sure you speak up!

Any recommendations on lower mid market IT risk advisors who are good at looking at IT controls for data warehousing? Should we be talking to LMM accounting firms or specialist boutiques?

We're a lower mid market tech company looking for some consulting help to look at our current data warehousing setup and getting recommendations on control remediations

TIA!

like

So I was offered a role in Strategy Consulting in after 2 years in Risk Consulting however, after 2 years I’ve only worked on Internal audit engagements few ad hocs such as updating risk register and the delegation of authority matrix.

Honestly speaking I am doing good and I am up for promotion in October however I am not fully enjoying my time but I fear that the move would not be a good and I can’t hit the ground running which scares me.

Any advice and past experiences in such career shit?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal