A report-reading checklist for European, Australian, and Singapore buyers: opinion, scope, period, exceptions, and local obligations.
Confirm that the report is the right one
Start with the legal entity, service, product version, and dates. Compare them with the proposed contract and architecture. Check whether the report is Type 1, addressing design at a date, or Type 2, also addressing operating effectiveness over a period. Identify which Trust Services Criteria are covered. A Security-only report is not an opinion on every aspect of Availability, Processing Integrity, Confidentiality, or Privacy.
Ask for the complete report through the provider's controlled sharing process. A sales slide, logo, or one-page summary cannot show the system boundary, independent service auditor's opinion, management's assertion, tests, or results. The AICPA offers a report-reading checklist that explicitly directs management to those sections.
Read the opinion and description together
Read the independent CPA's opinion first, including any qualification and its basis. Then read management's assertion and the system description to see what the opinion actually concerns. Identify excluded products, locations, activities, or third-party services. Check whether the report period includes the time relevant to your purchase, and ask what changed after the period ended.
Pay close attention to outsourced components and customer responsibilities. A cloud provider may be treated as a subservice organization, and the SaaS provider may rely on controls the customer must perform. Map these assumptions to your own configuration, identity processes, data flows, and contract. A report that tests the provider's side of shared responsibility does not test yours.
Examine tests, exceptions, and follow-up
For a Type 2 report, inspect the controls, the CPA's tests, and the results. Look beyond a headline opinion: an exception may matter greatly for your service, or it may be limited to a control outside your use. Ask the provider how relevant deviations were investigated and remediated. Check whether any complementary customer controls are realistic for your team and whether you can operate them from day one.
Write a short decision note with the residual questions: what the report covers, what it does not cover, the exceptions relevant to your use, additional evidence requested, and who accepts the remaining risk. This makes the report part of vendor oversight rather than a document filed away after procurement.
Overlay local and contractual duties
For an EU purchase involving personal data, assess controller and processor roles, contractual terms, transfers, and other GDPR duties separately. In Australia, consider whether the entity is covered by the Australian Privacy Principles, including APP 11's reasonable security and retention requirements. In Singapore, consider applicable PDPA protection, transfer, retention, and breach duties. A SOC 2 report may inform each review, but it is not a legal compliance determination in any of these jurisdictions.
If you also request an ISO/IEC 27001 certificate, verify its issuing body, current status, and scope against the service. Keep a single supplier decision record linking the SOC 2 observations, certificate scope, contract, data protection review, and any compensating controls. Revisit it when the provider changes its product, hosting, or subservice organizations.
Put it into practice
- Match the report entity, service, criteria, and period to the planned purchase.
- Read the CPA opinion, management assertion, system description, tests, and results.
- Record subservice dependencies, customer controls, exceptions, and remediation questions.
- Assess EU, Australian, or Singapore privacy and contractual duties separately.
Primary sources
- AICPA & CIMA: key elements of a SOC 2 report and review checklist
- AICPA & CIMA: illustrative SOC 2 report
- European Commission: GDPR application and controller/processor roles
- OAIC: APP 11 security of personal information
- Singapore PDPC: data protection obligations
Normstone resources are general information, not legal advice or an independent assessment.