IT assurance & advisory

Independent SOC 1, SOC 2 and controls assurance services

Forvis Mazars in Malta supports global service organisations operating from Malta with independent assurance over technology, operational and internal control environments. Our services are designed for organisations that need to provide customers, user auditors, business partners, regulators or other stakeholders with credible assurance over the controls supporting their services.

We provide SOC 1 / ISAE 3402, SOC 2 / ISAE 3000-style assurance and related controls assurance services, helping service organisations define the right scope, prepare evidence, test controls and issue reports that support customer due diligence, outsourcing risk management and stakeholder confidence.

SOC 1 and SOC 2 reporting

Report typeBest suited forFocus
SOC 1 / ISAE 3402Service organisations whose services may be relevant to customers’ internal control over financial reportingControls over services, processes and systems that may affect user entities’ financial reporting and their auditors’ work.
SOC 2 / ISAE 3000-style assuranceTechnology, SaaS, outsourcing, managed service, fintech, platform and data-driven service organisationsControls relevant to security, availability, processing integrity, confidentiality and privacy, using recognised criteria such as the AICPA Trust Services Criteria.

A Type 1 report addresses the design of controls at a point in time, while a Type 2 report also addresses operating effectiveness over a defined period. For service organisations with recurring customer assurance requirements, Type 2 reports often provide stronger evidence of sustained control operation.

How we can help

We provide practical support across the assurance reporting lifecycle, including:

  • SOC readiness and gap assessments — identifying gaps in scope, controls, evidence and reporting readiness.
  • SOC 1 / ISAE 3402 reporting — assurance over controls relevant to user entities’ internal control over financial reporting.
  • SOC 2 / ISAE 3000-style assurance — assurance over controls relevant to security, availability, processing integrity, confidentiality and privacy.
  • Type 1 and Type 2 reporting support — from initial control design assessment through operating effectiveness testing.
  • System description and control mapping — helping management prepare clear descriptions of services, systems, boundaries, controls, subservice organisations and complementary user entity controls where relevant.
  • Third-party and outsourcing assurance — supporting service organisations that need to demonstrate control maturity to customers, partners and user auditors.
  • Cybersecurity and information security assurance — assurance over selected technology, security, access, change management, operations, resilience and monitoring controls.

Our approach

Our approach is practical, risk-based and evidence-led. We work with management to understand the services provided, define the reporting boundary, map control objectives or criteria, identify relevant systems and subservice organisations, assess evidence, test controls and prepare clear reporting for intended users.

We combine IT assurance, audit, cybersecurity, internal controls and risk consulting experience to help service organisations produce credible assurance reports while strengthening the underlying control environment.

Need a SOC 1, SOC 2 or related assurance report?

Speak to Forvis Mazars in Malta about independent SOC reporting and controls assurance services for global service organisations operating from Malta.

Contact