# Annotated synthetic SOC 2 report

The complete specimen includes a scope page, mock qualified opinion, test table, subservice carve-out, customer controls and a subsequent management statement.

All report content is invented for teaching. No audit, real vendor finding, practitioner opinion or confidential report is represented.

Source: https://aona.ai/resources/guides/ai-vendor-soc2-report-review/
Sources checked: 2026-09-21

## Synthetic report, meaningful finding

### TRAINING ONLY

Hosted Business Workspace, Q1 2026

### Mock opinion

Qualified regarding access removal

### Invented sample

2 of 25 removals outside the fictional policy

Note: No audit was performed.

### Customer action

Check SSO and membership review

| Report element | Synthetic finding | Buyer interpretation |
| --- | --- | --- |
| System and period | Hosted Business Workspace; January–March 2026. | Match the intended service and time window. |
| Opinion | Mock qualification about former-user access removal. | Read the actual opinion and the linked finding. |
| Test exception | Two of 25 fictional removals took 16 days against a fictional 24-hour policy. | Assess affected access, cause and evidence of remediation; do not score by count alone. |
| Subservice carve-out | Fictional cloud host’s physical controls are excluded. | Obtain relevant complementary evidence; do not infer these controls were tested here. |
| Customer controls | SSO, membership review and data/retention policy are expected. | Verify the buyer’s actual configuration and responsibilities. |
| After-period statement | Management says offboarding changed; no retest is included. | Separate that statement from an independent examination. |

## Review checklist

- [ ] Match system, period and opinion
  Identify the exact service, covered categories and any qualification before relying on the report.
- [ ] Follow the material finding
  Review the test, exception, management response and actual remediation evidence.
- [ ] Close scope gaps deliberately
  Assess excluded subservice controls and the customer responsibilities relevant to the proposed use.

## Included example files

- synthetic-soc2-report-excerpt.md
- soc2-report-reading-exercise.md
- soc2-report-reading-exercise.csv

## Source references

- AICPA: System and Organization Controls suite: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services (2026-09-21)
- Microsoft: SOC 2 Type 2 overview: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2 (2026-09-21)
- AICPA: Addressing SOC 2 engagement risks: https://www.journalofaccountancy.com/issues/2026/may/aicpa-guides-peer-reviewers-to-address-soc-2-risks/ (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
