SOC 1 Report Reviewer
Reads a SOC 1 report (Type I or II), pulls out the structured details, drafts the reviewer's assessments for confirmation, compares it to last year's review, and fills in a complete 13-tab review workpaper with 70 built-in checks.
- Plugin
- auditshore-soc1-review
- Version
- v1.2.5
- Impact
- High
- Complexity
- Medium–High
How it works
- Input
- The current-year SOC 1 report (PDF), plus last year's review data if this is a repeat engagement
- What it does
- Classifies the auditor's opinion → pulls out every control objective, control, and exception → drafts each judgment as a proposal for the reviewer → maps complementary user-entity controls to the service organization's controls → identifies subservice organizations → fills in the workbook
- What has to hold true
- 70 checks run as live formulas in the workbook — including recomputing period coverage from the report dates — and every one was shown capable of failing before the package shipped. Every judgment stays a proposal until the reviewer confirms it.
- Output
- A completed, ready-to-review 13-tab SOC 1 review workpaper
The part that makes it reproducible
What it's made of
Each step runs on its own, so you can see — and stop at — any stage.
- 1
soc1-extract
Pulls the control objectives, controls, testing exceptions, complementary user-entity controls, subservice organizations, and the auditor's opinion straight out of the PDF.
- 2
soc1-assess
Drafts every judgment call the reviewer has to make — which control objectives matter, which user-entity controls apply, whether the service auditor's testing was adequate — each as a proposal with a confidence level and the source text behind it, so the reviewer confirms instead of starting from a blank grid.
- 3
soc1-diff
Compares this year's report against last year's review — repeat exceptions first, then scope changes and subservice organizations that came or went.
- 4
soc1-review
Fills in Auditshore's standard 13-tab review workbook, where every field names the standard that requires it and 70 checks run as live formulas.
What you'll need to change for your firm
This runs as published, but every audit function documents things its own way. These are the places it assumes a house format:
- Your SOC review workbook, if it differs from the standard 13-tab template
- Your materiality and significance thresholds for reported deviations
- How prior-year review data is stored, for the year-over-year comparison
- Which complementary user-entity controls your client actually relies on
Built for Claude
Install it into Claude Cowork and point it at your files.
- 1Download the skill bundle — everything it needs, including the shared building blocks, is inside.
- 2Add it to Claude Cowork as a plugin (auditshore-soc1-review).
- 3Point it at your own files and run it against one period you already know the answer to.
Free. We'll send the bundle and the setup notes.
Running on ChatGPT Enterprise or Copilot? We port these into your environment.
Want SOC 1 Report Reviewer fitted to your methodology?
We adapt it to your control matrix, your workpaper template, and your thresholds — then hand it over so your team can run it themselves.