Files
odyssey/wiki/entities/SOC 2 报告类型.md

44 lines
1.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
tags: [实体, 概念, 合规]
created: 2026-09-16
updated: 2026-09-16
sources: [raw/notes/2026-09-16-what-is-soc-2-compliance.md]
---
# SOC 2 报告类型
> SOC 2 审计报告的两种形态:Type I 评估某一时点的控制设计与实施,Type II 在此基础上考察六个月期间的运行有效性。
## 简介
[[SOC 2]] 报告没有统一模板 —— 报告内容因公司而异,既取决于选用了哪几项 [[Trust Services Criteria]],也取决于选了哪种报告类型。类型之间的差别不在「严格与否」,而在**考察的时间维度**:看快照,还是看一段时间的表现。
## 关键信息
- **类型**:概念(审计报告类型)
- **所属**:[[SOC 2]] 框架(制定者 [[AICPA]])
- **Type I 时间维度**:某一时间点(point in time)
- **Type II 时间维度**:某一时间点 + 之后六个月
- **相关概念**:[[Trust Services Criteria]]
## 详细内容
| 维度 | Type I | Type II |
|------|--------|---------|
| 适用场景 | 首次做 SOC 2 合规审计的组织 | 需要证明持续有效性的组织 |
| 考察对象 | 某一时点已建立的控制 | 同一批控制,外加六个月的运行记录 |
| 评估内容 | 控制是否被**正确设计与实施** | 设计、实施,**以及运行有效性** |
选择建议(本文隐含):先做 Type I 验证控制设计,再过渡到 Type II 证明持续运行 —— 报告最终是「unique to the company and the chosen audit principles」。
## 不同素材中的观点
暂无其他素材讨论报告类型。
## 相关页面
- [[SOC 2]]
- [[Trust Services Criteria]]
- [[SOC 1]]
- [[合规与审计]]