Skip to main content

SOC 2 Type 1 audit for external auditors

This article is part of the SOC 2 best practices series.

Hyperproof is a robust, all-in-one compliance operations platform that allows organizations to stay on top of all their security assurance and compliance work. With Hyperproof, organizations can identify compliance requirements, implement controls, collect and store proof, automate routine tasks, and much more.

Many organizations prefer to conduct their audits directly in Hyperproof to eliminate the typical back-and-forth between the organization and the auditor. Using Hyperproof also helps organizations greatly reduce the number of times clients are asked for the same evidence by different audit teams.

As an auditor, your role in Hyperproof varies depending on the client’s preferences—some clients may grant an auditor full access to their Hyperproof organization, while others may add an auditor as a contact, meaning that the auditor never actually logs in to the platform.

For auditors who are added to their client’s Hyperproof organization, you will be able to review all documentation the client has uploaded to Hyperproof, as well as communicate with the client right from the platform. Hyperproof keeps historical records with version control, so both you and the client can stay up-to-speed

with the audit in real-time.

Conducting a SOC 2 audit using Hyperproof

Audit kickoff

The internal auditor meets with you, the external auditor, and you provide the Document Request List (DRL).

Review and submission of follow-up actions

When the client and their internal auditor have completed all of the requests in the Document Request List, they submit the results to you for your review.

If all requests have been satisfied, both the internal auditor and you, the external auditor, move on to the next steps.

If requests have not been satisfied, the internal auditor updates the DRL, ensures that linked proof is satisfactory, re-exports the updated audit, and then delivers it to you, the external auditor, for another review.

Producing the SOC 2 Type 1 report

When all audit requests have been satisfied and provided to you, you compile the Type 1 report and provide it to the client.

Did this answer your question?