Skip to content

SOC 2 is an AICPA audit report attesting that a software vendor's controls protect customer data across security and related criteria.

SOC 2

SOC 2 is an AICPA audit report attesting that a software vendor's controls protect customer data across security and related criteria.

SOC 2 is an audit report, defined by the American Institute of Certified Public Accountants (AICPA), that attests to how well a service provider's controls protect customer data across trust criteria such as security, availability, processing integrity, confidentiality, and privacy. An independent auditor examines the vendor's controls and issues the report; it is an attestation of practices, not a government certification.

RIAs, advisors, and family offices care about SOC 2 because they entrust software vendors with sensitive client financial and personal data. A current SOC 2 report is a common due-diligence checkpoint when selecting a platform.

Two report types come up in vendor reviews:

  • Type I — controls are suitably designed at a point in time
  • Type II — controls operated effectively over a review period
  • Bridge letters — cover the gap between report dates

When comparing wealth management software or evaluating vendors, advisors should request the latest SOC 2 Type II report as part of their security review.

Compare: