Expert Knowledge to Your Inbox - SignUp Now!

SOC 1 Reports for Lease Accounting Software: What to Look For

John J. Meedzan

Co-Founder and Managing Partner, iLease Management LLC

Questions this article answers

  • What should I look for in a SOC 1 report for lease accounting software?
  • How does a SOC 1 report mitigate risks in lease accounting?
  • What are the different types of SOC 1 reports?
  • Why is a SOC 1 report important for ASC 842 compliance?
  • What is the role of a SOC 1 report in auditing lease accounting software?

Navigate SOC 1 Reports for Lease Software Selection

Under ASC 842, the accuracy and integrity of lease accounting data come first. That takes a robust control environment, most of all when a company relies on third-party software. Controllers and accounting managers need to know how to review a SOC 1 report.

A System and Organization Controls (SOC) 1 report1 gives independent assurance over the internal controls of a service organization relevant to a user entity's financial reporting. When you evaluate lease accounting software, these reports show how the controls are designed and, in a type 2 report, whether they operated effectively. Those controls affect lease data accuracy, calculations, and financial statement presentation. That includes checking that the software can support ASC 842 controls well.

What Auditors Are Actually Looking For in SOC 1 Reports

Auditors read a SOC 1 report closely to judge how much comfort they can take from the service organization's controls. Those controls, in turn, affect the user entity's financial statements. The auditors' main goal is to obtain sufficient appropriate audit evidence about the completeness and accuracy of the lease data the software processes.

This evidence feeds their view of whether the user entity complies with ASC 842. The focus is lease identification, classification, measurement, and disclosure. Auditors run detailed procedures to confirm that the underlying lease control procedures are properly designed and operate as expected.

"SOC 1 is an examination of controls at a service organization that are likely to be relevant to user entities' internal control over financial reporting."2

When auditors review SOC 1 reports, they focus on several key areas. Each one bears on the user entity's lease accounting processes:

Audit Focus AreaDescriptionRelevance to Lease Accounting
Control ObjectivesAre the stated control objectives comprehensive and directly address financial reporting risks related to lease accounting?Ensure all material aspects of ASC 842 (e.g., ROU asset, lease liability) are covered.
Description of ControlsIs there sufficient detail on how the software processes lease data, calculations, and reporting?Verifies the logic and programming behind ASC 842 computations.
Tests of ControlsWhat specific tests did the service auditor perform, what were the results, and what was the period covered?Provides assurance on the operating effectiveness of controls crucial for accurate lease balances.
Complementary User Entity Controls (CUECs)What controls are expected to be implemented by the user entity to achieve stated control objectives?Highlights the shared responsibility for internal controls between the service organization and the user.
ExceptionsWere there any control exceptions or deviations noted, and how might they impact the user entity's financial statements?Indicates potential weaknesses that require additional audit procedures at the user entity level.

Q: How do auditors test SOC 1 reports for lease accounting software? A: Auditors evaluate the design of the controls the SOC 1 report documents and, in a type 2 report, their operating effectiveness3. They look for how the service organization addresses key ASC 842 requirements.

Examples are lease classification, discount rate application, and recognition of right-of-use (ROU) assets and lease liabilities. This often means reviewing the service auditor's methods and findings against the user entity's own lease portfolio and related risks.

What an Unread SOC 1 Report Leaves Uncovered

Failing to adequately review a SOC 1 report for lease accounting software can introduce significant risks to a company's financial reporting. So can failing to address its findings. The completeness assertion refers to an auditor's objective to verify that the financial statements include all transactions and accounts that should be recorded. In lease accounting, this means making sure every lease and sub-lease is captured.

Here are common risks and failure points:

  • Incomplete Lease Population: A primary risk is that the software or the user entity's processes fail to capture all contracts that meet the definition of a lease. This can lead to understated ROU assets and lease liabilities. When they evaluate compliance, auditors constantly ask, "what are the risks of incomplete lease population?"
  • Improper Calculation of Lease Components: Errors within the software can result in material misstatements. These are errors in discount rate application, lease term determination, or variable payment calculations. This directly affects the accuracy of ROU asset and lease liability balances.
  • Inadequate Data Migration Controls: When a company moves to new software, errors in migrating lease data from legacy systems can lead to inaccuracies. This often requires careful validation beyond the scope of a standard SOC 1 report alone.
  • Lack of Segregation of Duties: If the software's access controls do not properly segregate duties, the risk of fraud or unintentional errors goes up. An example is lease data input vs. approval.
  • Failure to Address CUECs: User entities often overlook their duty to implement the Complementary User Entity Controls (CUECs) that the SOC 1 report identifies. This can negate the effectiveness of the service organization's controls.

⚠️ Risk Alert: A common audit finding is that companies overlook the Complementary User Entity Controls (CUECs) specified in the SOC 1 report. They assume the software alone covers all control requirements for lease accounting compliance.

The ASC 842 Master Glossary defines a right-of-use (ROU) asset as "an asset that represents a lessee's right to use an underlying asset for the lease term."

Inaccurate ROU asset controls can lead to material misstatements on the balance sheet.

Calculation Example: Lease Liability Understatement Risk

Scenario: A 5-year lease is set up in the software with a 3-year term, because nobody validated the lease-term input against the signed lease. The lease liability is measured at commencement as the present value of the lease payments not yet paid (ASC 842-20-30-1). A two-year error in the term understates it, and understates the right-of-use asset by the same amount (ASC 842-20-30-5(a)).

ComponentCorrect ValueIncorrect InputCalculation Impact (5% discount rate, annual payments in arrears)
Annual Lease Payment$10,000$10,000PV of Payments
Actual Lease Term (Years)5N/A$43,295
Incorrect Lease Term (Years)N/A3$27,232
Lease Liability UnderstatementN/AN/A$16,062

Figures are rounded to the dollar; the understatement is the difference of the unrounded present values ($43,294.77 − $27,232.48 = $16,062.29). The 5% here is the lessee's incremental borrowing rate, used because the rate implicit in the lease is not readily determinable (ASC 842-20-30-3). A lessee that is not a public business entity may instead elect a risk-free discount rate, by class of underlying asset (ASC 842-20-30-3).

Key Takeaway: An input control failure can lead to significant financial statement misstatements, even for a seemingly minor data point like lease term. That is why it is crucial to review the specific control activities within a SOC 1 report. Internal control review procedures are crucial for mitigating such risks, as the considerations for an effective internal control framework highlight.

Practical Checklist for SOC 1 Report Review

To understand what a SOC 1 report covers, take a structured approach. This checklist helps controllers and accounting managers review a SOC 1 report for lease accounting software effectively:

Checklist ItemDescriptionAudit Implication
1. Identify Report TypeIs it a Type 1 report (design effectiveness at a point in time) or a Type 2 report (design & operating effectiveness over a period)? For financial reporting, a Type 2 report is generally preferred.Type 2 provides more comfort; Type 1 may require additional user entity testing.
2. Review Control ObjectivesDo the control objectives specifically address key ASC 842 requirements, such as lease identification, measurement, amortization, and disclosure? Ensure they align with your organization's specific ASC 842 disclosure requirements.Inadequate objectives mean controls may not cover critical risks.
3. Evaluate Complementary User Entity Controls (CUECs)Understand your responsibilities. List all CUECs and verify if your organization has implemented and operates these controls effectively. These are crucial for a fully compliant system.Failure to perform CUECs negates the service organization's controls, potentially leading to audit findings.
4. Scrutinize Service Auditor's OpinionRead the opinion carefully. Is it unqualified? Any modified opinions or disclaimers warrant immediate attention and further investigation.A qualified opinion indicates significant control weaknesses or scope limitations.
5. Examine Test Results & ExceptionsReview the "Tests of Controls" section. Note any identified control exceptions, their root causes, and potential impact on your financial statements. Consider their materiality.Exceptions require user entity follow-up and potentially additional substantive audit procedures.
6. Check Service PeriodDoes the report cover the relevant financial reporting period? Gaps in coverage may necessitate interim controls or additional procedures.Ensures controls were effective during your reporting period.
7. Assess Impact on Audit PlanningUse the report findings to inform your own internal controls assessment and your external auditor's planning, particularly for areas like embedded lease discovery and ensuring lease accounting compliance.Helps determine the extent of substantive testing required by external auditors.

✅ Best Practice: Be proactive. Talk with your external auditors about the SOC 1 report and the CUECs you have implemented, to stay aligned and minimize audit surprises.

Testing Beyond the Report You Were Handed

Accounting teams must do more than receive a SOC 1 report. They need to actively validate that the software and internal processes reliably support ASC 842 compliance. This takes a mix of testing, documentation, and continuous monitoring.

An embedded lease is practice shorthand. A larger contract that is not called a lease still contains one if it conveys the right to control the use of an identified asset (ASC 842-10-15-3). Finding these takes diligence.

  1. Reconcile Data: Regularly reconcile lease data from the software to source documents (e.g., lease agreements, amendments). This can include comparing ROU asset balances and lease liabilities to general ledger accounts.
  2. Perform Parallel Testing: For significant changes or new implementations, run key calculations outside the software for a sample of leases. Examples are initial recognition and amortization schedules. Then compare the results.
  3. Validate CUECs: Document the execution of all Complementary User Entity Controls (CUECs) specified in the SOC 1 report. This includes reviewing access controls, data input validations, and approval processes.
  4. Conduct Lease Identification Testing: Periodically review a sample of contracts that are not in your lease accounting software. Confirm they are indeed not leases, or identify any potential embedded leases that were missed. This directly addresses the completeness assertion. For more on this, see the ultimate guide to ASC 842.
  5. Review System-Generated Reports: Verify that reports the software generates (e.g., amortization schedules, journal entries) align with expected ASC 842 outputs. Verify too that they can be traced back to underlying data.

💡 Key Takeaway: The burden of proof for effective controls ultimately rests with the user entity. A SOC 1 report gives assurance about the service provider, but not about your specific implementation or oversight.

FASB ASC 842-10-15-3 sets out the test. A contract is or contains a lease if it conveys the right to control the use of an identified asset for a period of time in exchange for consideration. That calls for robust identification processes.

The Set-It-and-Forget-It Control Failure

A company that ignores the finer points of SOC 1 report review can face significant audit challenges and potential material weaknesses. Common pitfalls often stem from a misunderstanding of shared control responsibilities.

Common MistakeBest PracticeImplications for Audit Findings
1. "Set it and Forget It" MentalityRegularly review the latest SOC 1 report, especially if there are system upgrades or significant changes in your lease portfolio. Ensure the report period aligns with your fiscal year.Outdated reports provide insufficient assurance, leading to increased audit scrutiny and potential control deficiencies.
2. Ignoring CUECsDocument and perform all Complementary User Entity Controls (CUECs) identified in the report. Communicate these responsibilities clearly within your accounting team.Failure to execute CUECs is a common cause of control deficiencies, as the service provider's controls are only effective if CUECs are also implemented.
3. Not Understanding the ScopeClarify what within the software is covered by the SOC 1 report. If certain modules or customizations are excluded, plan for additional internal testing.An incomplete scope means controls for critical processes might not be assessed, leaving financial reporting exposed. For instance, review the PBC list a lease audit typically requires to see what falls outside SOC 1 scope.
4. Focus Only on the Opinion PageRead the entire report, paying close attention to the detailed findings, exceptions, and management responses. The body of the report contains crucial context.Overlooking exceptions or qualifications can lead to auditors identifying undisclosed control weaknesses at your entity.
5. Inadequate Testing of Significant BalancesEven with a strong SOC 1, maintain internal review procedures for high-value leases, complex lease modifications, and critical calculations.Over-reliance on the SOC 1 for material balances without independent verification is a risk, particularly for unusual transactions.

🚨 Critical: Failure to understand and implement CUECs listed in a SOC 1 report is a frequent cause of the control deficiencies auditors identify. It creates a gap in the overall control environment.

Using SOC 1 as a Risk Assessment Tool

Organizations that use SOC 1 report review well show a proactive and integrated approach to internal controls. They do not simply file the report. They actively use it as a foundational risk assessment tool for their lease accounting processes. The result is more efficient audits, fewer audit findings, and confidence in their ASC 842 compliance.

A well-prepared company builds the SOC 1 findings into its overall internal control framework. For example, it might conduct a quarterly review of its lease portfolio against CUEC requirements. That review validates access rights and makes sure all new contracts have been reviewed for embedded leases. Its accounting team runs sample tests on high-dollar leases to verify that the software's calculations align with its lease agreements and ASC 842 principles.

With this continuous monitoring and proactive work on the SOC 1 report's details, auditors can place greater reliance on the company's internal controls. That can reduce the scope and intensity of the substantive testing required.

This approach lets external auditors use the service auditor's work during ASC 842 auditing. That is audit effort, not a promised fee reduction.

The AICPA notes that such a report is used to "understand the controls at the service organization and potentially reduce the amount of substantive testing required."4

Making SOC 1 Review Part of Control Monitoring

Controllers and accounting managers should prioritize a thorough and ongoing review of their lease accounting software's SOC 1 report. The goals are to maintain robust lease accounting compliance and to optimize external audit efforts. This is not a one-time task. It is an integral part of ongoing internal control monitoring.

Related Articles

Sources and further reading

  1. AICPA & CIMA — AICPA System and Organization Controls communications guidelines ↩

  2. AICPA & CIMA — SOC 1® – SOC for Service Organizations: ICFR ↩

  3. AICPA & CIMA — Maintaining high standards for SOC engagements ↩

  4. AICPA & CIMA — Employee benefit plans: SOC 1 reports and service organizations resource center ↩