During this presentation, we will discuss the various types of SSAE SOC reports, as well as the corresponding types of audits. This course will help your organization identify critical processes, procedures, and controls that should be included in the scope of your assessment. We will discuss methodologies to implement and maintain an effective control environment compliant with the Sarbanes-Oxley Act (SOX) Section 404 or NIST. Lastly, participants will be educated in the following:
- Identifying 3rd party processes being performed on behalf of clients.
- Identifying SOC requirements based on those 3rd party processes.
- Identifying the process, objectives, and control scope.
- Creating documented policies, procedures, and controls, and
- SSAE report formatting.
Course Key Concepts: SSAE, SOC, Compliance, Security, Audit, CISA.
Learning Objectives
- Recognize the differences SSAE 18 SOC I, SOC II, SOC III, and Type I and II.
- Discover and discuss various audit objectives.
- Explore and discuss policies, procedures, and control to determine the audit scope.
- Identify and discuss the advantages of performing a readiness assessment.
Last updated/reviewed: March 17, 2024
7 Reviews (38 ratings)
Course Complexity: Foundational
No advanced preparation or prerequisites are required for this course.
Education Provider Information
Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA
For more information regarding this course, including complaint and
cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to
Course Questions and Answers1 Question

Wendi FinnOwner
Hi Wendy could you consider a course that would cover more around what to do if exceptions noted by the auditor-approach you would recommend. Also getting SSAE 18 from Sub service providers as some providers may use a number of them/ also if you get a subservice SSAE18 and there are testing exceptions the approach. Finally maybe discuss use of Bridge letters thanks