SOC 2 for fintech: what a bank partner reviews
A bank partner has to review you, and the 2023 interagency guidance names SOC reports.
SOC 2 for fintech starts with your bank partner’s obligations. In June 2023 the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC) and the Office of the Comptroller of the Currency (OCC) finalized joint guidance on third-party relationships. It says a bank’s use of a third party does not diminish its own responsibility, and that due diligence may include reviewing SOC reports.1
A fintech with a bank partner is that third party. The review is coming either way. A report decides how long it takes.
This page covers what the guidance asks, where a SOC 2 fits in it, and the three cases where a different report is the right one: Processing Integrity, SOC 1 and the Payment Card Industry Data Security Standard (PCI DSS). It is not legal advice about your bank agreement. Ask your partner bank what it needs in writing.
Where a SOC report fits in a bank’s due diligence
The guidance describes a life cycle for every third-party relationship: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination.1 SOC reports appear at two points.
- Due diligence
- A bank evaluates the third party’s risk management and internal controls, and whether those controls face independent testing. It may consider reviewing SOC reports and independent certifications, and whether their scope and results are relevant to the activity the third party will perform.
- The contract
- A contract may set the types and frequency of audit reports the bank is entitled to receive. The guidance gives SOC reports and PCI compliance reports as examples, and the bank may keep a right to audit you itself.
Two consequences follow for your report. Scope has to cover the activity the bank relies on, because the bank reads scope before results. And the report has to stay current, because the contract will ask for it again. How long a SOC 2 report is valid and what a bridge letter can say cover the gap between periods.
The guidance also expects banks to give more comprehensive oversight to relationships that support critical activities. If your product touches the bank’s customers or money directly, expect the deeper version of every step.
When you move money or compute balances
Security is the one category every SOC 2 includes. Processing Integrity is the category that tests whether processing is complete, valid, accurate, timely and authorized.2 A ledger, a payment flow or a balance calculation is exactly that kind of processing.
Whether it belongs in scope depends on what your contracts promise. If they commit you to accurate balances or correct payment processing, the scoping tool will flag Processing Integrity. Polara G.R.C. scopes Security only, fixed rather than a setting. If your bank needs Processing Integrity tested, a firm that runs that scope directly is the right route.
When the buyer really needs SOC 1
SOC 1 and SOC 2 answer different questions. A SOC 1 reports on controls at a service organization that are relevant to its customers’ internal control over financial reporting.3 A SOC 2 reports on security and the other trust services categories.4
The test is where your output ends up. If figures your system produces flow into a customer’s financial statements, their auditors may ask for a SOC 1. If a bank asks for SOC 1 by name, a SOC 2 will not substitute for it. We offer SOC 2, not SOC 1, so in that case we are the wrong vendor, and a CPA firm that performs SOC 1 examinations is the right one.
The PCI DSS boundary
PCI DSS applies to entities that store, process or transmit cardholder data, or that could affect the security of the environment holding it.5 It is a separate standard with its own assessment. A SOC 2 does not cover it, and we do not offer PCI DSS.
The way to keep it small is to never touch card data. A payment processor’s hosted integration can collect card details and send them straight to the processor without passing through your servers, which reduces your PCI obligations.6 Then the processor is a vendor in your SOC 2, carved out like any other, and its own reports sit in your vendor file.
The controls a bank will read closely
Within a Security scope, five areas map most directly onto what the guidance asks a bank to check.
- Production access. Who can read account and transaction data, and the quarterly review that proves the list is right.
- Change management. Code that moves money gets reviewed and approved before it ships, with the record kept.
- Vendor management. Your processor, your banking-as-a-service provider and your cloud host, each with a current report on file.
- Incident response. A notification commitment to the bank that matches your agreement, and a plan that meets it.
- Complementary user entity controls. What the bank must do on its side. How to word CUECs covers it.
If your product is an API the bank’s systems call, the guide for API companies covers change evidence and logs in more detail. The same structure applies to legal tech and agencies, with a different buyer reading it.
Through Polara Labs it is audit-ready starting at about a week of focused work, and a Type 2 adds a 3-month observation window before the audit. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report is optional: $2,000 added later, or $4,000 in total with onboarding, with the engagement fee for the independent partner auditor inside it. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
Do fintech startups need SOC 2?
What does a sponsor bank look for in a SOC report?
SOC 1 or SOC 2 for a fintech?
Does SOC 2 cover PCI DSS?
Should a fintech SOC 2 include Processing Integrity?
Sources
- Interagency Guidance on Third-Party Relationships: Risk Management
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting (SOC 1® Guide)
- SOC 2 Report
- PCI Data Security Standard (PCI DSS)
- Integration security guide
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.