# SYNTHETIC SOC 2 TYPE 2 REPORT EXCERPT

TRAINING DOCUMENT ONLY. No audit was performed. No auditor, vendor, customer or assurance report is represented. All names, dates, controls, samples, results and opinion language below are invented.

## 1. Cover and scope

Service organisation: Example Text Services Ltd (fictional).
System: Example Business Workspace, hosted text service.
Period: 1 January to 31 March 2026, invented.
Illustrative issue date: 30 April 2026.
Categories represented in this exercise: Security and Confidentiality. No conclusion about other categories is represented.
Excluded products: Example Consumer App and standalone Example Desktop Client.

Annotation: match the service, period and categories to the proposed use. Do not convert this scope into a claim about every company product.

## 2. Mock opinion summary

For this teaching case only, assume the report gives a qualified opinion relating to timely removal of former-user access. No real practitioner has issued this opinion.

Annotation: read the actual opinion in a real report. Do not infer an unmodified or qualified opinion only from an exception count.

## 3. Fictional test table

| Control | Stated design | Invented test | Invented result |
| --- | --- | --- | --- |
| ACCESS-EX-01 | Remove departing users within the fictional policy’s 24-hour limit. | Examine 25 fictional leaver records from the stated period. | Two records show access remaining for 16 days; 23 meet the stated limit. |
| REVIEW-EX-02 | Review privileged workspace membership monthly. | Inspect three invented monthly review records. | Records are present; no exception is stipulated in this example. |

Annotation: the 24-hour limit is this fictional policy, not a universal SOC requirement. Results are not real tests and do not establish any provider’s effectiveness.

## 4. Subservice organisation

Example Cloud Host (fictional) supplies hosting. Its physical data-centre controls are carved out of this specimen’s test scope. The fictional service organisation retains a provider-review responsibility.

Annotation: obtain the relevant actual subservice evidence and understand the report’s treatment. Do not assume this excerpt tested excluded host controls.

## 5. Complementary user entity controls

CUEC-EX-01: customer configures SSO for its workspace.
CUEC-EX-02: customer reviews authorised workspace membership.
CUEC-EX-03: customer applies its approved data-input and retention policy.

Annotation: these are fictional report assumptions, not a statement that an actual buyer has implemented them.

## 6. Subsequent management statement

Invented statement: “We changed the offboarding process after the report period.” No later independent test is included in this specimen.

Annotation: ask for the change date, scope and supporting evidence. Do not describe this management statement as an auditor’s retest.

## Source and scope

Guide: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/

Source check: 21 September 2026. General information, not professional approval or a completed control test.

- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/
