EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
EY SOC reporting teams help companies communicate trust and confidence in the internal control environment around the services they provide to customers.
Read more
SOC attestations build confidence among customers, investors and regulators by providing an independent evaluation of controls. SOC 1 reports focus on controls related to financial reporting risks, and SOC 2 reports provide independent attestation on an organization’s internal controls, typically to address third-party vendor risk management and due diligence. Many user organizations and regulators now mandate SOC reports.
ISO certifications are globally recognized and aim to bring consistency, discipline and credibility to an organization’s processes in areas such as cyber security, privacy, artificial intelligence (AI) governance, resilience, quality and sustainability. For example, ISO 27001 (cyber security) covers information security management; ISO 9001 focuses on quality management; ISO 22301 supports business continuity and resilience; ISO 14001 targets environmental sustainability; and ISO 42001 provides a structured framework addressing AI related risks, accountability and oversight. Depending on industry and organizational priorities, companies may also pursue international certifications related to health and safety, energy management, environmental sustainability, business continuity and quality management.
By integrating these ISO certifications with SOC attestation efforts, organizations can efficiently meet regulatory, industry and emerging technology requirements. This approach requires careful overlap of scope, team and timing on the auditor side as well as the auditee side.