SOC 2: What It Is & Why It Matters
SOC 2 is an independent audit report, based on the Trust Services Criteria, that describes how a service organisation controls customer data. It is widely used in vendor due diligence.
In this explainer
- Understand what a SOC 2 report is and who issues it
- Learn the Trust Services Criteria that underpin it
- Distinguish a Type I report from a Type II report
- See why an independent report matters for debtor data
- Know what to ask a vendor and how Merion approaches it
8 min
What it is
SOC 2, short for System and Organization Controls 2, is a reporting framework developed by the American Institute of Certified Public Accountants. Unlike a certification, a SOC 2 report is an independent examination performed by a licensed auditor, who describes a service organisation's controls and gives an opinion on whether they are suitably designed and, in some reports, operating effectively over time.
SOC 2 is most often used by organisations that hold or process customer data on behalf of others. The report is generally shared under confidentiality with prospective and existing customers, who use it to understand how a provider protects the data entrusted to it.
Key principles
SOC 2 is organised around the Trust Services Criteria. Security is always assessed; the others are included where they are relevant to the service:
- Security — protecting systems and data against unauthorised access.
- Availability — whether the service is available for operation and use as agreed.
- Processing integrity — whether processing is complete, accurate, timely and authorised.
- Confidentiality — protecting information designated as confidential.
- Privacy — how personal information is collected, used, retained and disposed of.
A Type I report describes controls at a point in time. A Type II report goes further and tests whether those controls operated effectively across a period, often several months. A Type II report therefore gives stronger evidence than a Type I.
Why it matters for debt recovery
When a creditor hands debtor data to a recovery provider, that data leaves the creditor's direct control. A SOC 2 report gives the creditor an independent, third-party view of how the provider protects it, rather than relying solely on the provider's own assurances. For procurement and risk teams, that independence is the central value of the report.
Because SOC 2 covers areas such as availability and processing integrity as well as security, it can also speak to operational reliability: whether the service stays available and whether the data it processes is handled accurately. For a debtor whose payment or balance must be recorded correctly, processing integrity is not an abstract concern.
What to ask a provider
To make sense of a SOC 2 claim, ask for detail rather than a headline:
- Is your report a Type I or a Type II, and what period does it cover?
- Which Trust Services Criteria are in scope?
- Were any exceptions or deviations noted, and how were they addressed?
- Can we review the report under a confidentiality agreement?
The exceptions section of a SOC 2 report is often the most informative part, because it shows where controls did not operate as intended and how the organisation responded. A report with no detail, or one that cannot be shared, is worth questioning. Our vendor due diligence page explains how we approach these requests.
How Merion approaches it
Merion follows good practice consistent with the SOC 2 Trust Services Criteria: we aim for controls that are designed sensibly, applied consistently and supported by records, so that our handling of customer and debtor data can stand up to independent scrutiny.
This is general information and not a statement that Merion holds any specific SOC 2 report. Audit reports are point-in-time and can change, so please verify a provider's current attestations directly and review any report on its own terms before relying on it.
Key takeaways
- SOC 2 is an independent auditor's report, not a self-issued certificate
- It is built on the Trust Services Criteria, with Security always in scope
- A Type II report tests controls over a period and gives stronger evidence than Type I
- Read the exceptions section and confirm a provider's current report directly
Frequently asked questions
What is the difference between SOC 2 and ISO 27001?
ISO 27001 certifies a management system against a standard, while SOC 2 is an independent auditor's report on a provider's controls against the Trust Services Criteria. They overlap but serve different purposes, and some organisations pursue both.
Should I prefer a Type I or Type II report?
A Type II report tests whether controls operated effectively over a period, so it generally gives stronger assurance than a Type I, which only describes controls at a point in time.
Why are SOC 2 reports shared under confidentiality?
Reports often contain detailed descriptions of a provider's systems and controls. They are usually shared under a confidentiality agreement so that detail is not made public.
Security and compliance you can verify
Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.