There are five audit documents that a SOC 2 / SOC 1 customer needs to e-sign in the Thoropass platform before the final audit report can be issued.
Your documents will typically be sent in two batches: the first two documents are sent at the beginning of the audit, and the final three documents are sent at the end.
Please see an explanation of each document below:
Engagement Letter (EL)
What it is: A formal agreement between the auditing firm and the customer.
Purpose: Outlines the scope of the audit, deliverables, and terms of the engagement.
Why it's required: Ensures mutual understanding of the audit process and legal agreement.
Control Design Questionnaire (CDQ)
What it is: A list of questions sent to customers about their control environment.
Purpose: Confirms and validates how customer controls are designed.
Why it's required: Helps auditors understand the customer’s processes for control evaluation.
Representation Letter
What it is: A letter from the customer confirming that all provided information is accurate.
Purpose: Serves as a final declaration of the accuracy of data submitted during the audit.
Why it's required: Required for compliance with audit standards.
Management Assertion
What it is: A document signed by management asserting that the controls were in place during the audit.
Purpose: Verifies the accuracy of management's statements on control design and operating effectiveness.
Why it's required: Integral to the audit report and validates the SOC conclusions.
Subsequent Events Questionnaire (SEQ)
What it is: A document confirming whether any major changes occurred after the audit period.
Purpose: Identifies any new events that could impact the validity of the audit.
Why it's required: Ensures the report reflects an accurate control environment up to the report issuance date.
