AuditOne LLP Service Offerings
AuditOne LLP offers a comprehensive suite of compliance and attestation services, including:
AICPA Attestation Reports (SOC 1, SOC 2, SOC 3)
AICPA attestation reports include several types of SOC examinations designed to evaluate different aspects of organizational controls. SOC 1 focuses on internal controls over financial reporting (ICFR) and comes in two forms: Type I, which assesses the design of controls at a specific point in time, and Type II, which evaluates both the design and operational effectiveness of those controls over a defined period. SOC 2 addresses controls related to the Trust Services Criteria—security, availability, processing integrity, confidentiality, and privacy. Like SOC 1, it offers Type I reports for control design and Type II reports for ongoing operational effectiveness. SOC 3 is a public-facing version of a SOC 2 audit, often accompanied by a trust seal for marketing and assurance purposes. Together, these reports serve financial, security, and public trust needs, ensuring alignment with stakeholder expectations and regulatory requirements.
ISO/IEC 27001:2022 Reviews (Stage 1, Stage 2, Surveillance, Recertification)
The audit process for ISMS certification begins with Stage 1: the Readiness Assessment, which involves a thorough review of ISMS documentation, a gap analysis to identify areas needing improvement, and recommendations to enhance compliance. Next, Stage 2: the Certification Audit provides a comprehensive evaluation of ISMS implementation, including control testing and compliance verification, followed by a certification decision and guidance on any corrective actions required. After certification, Surveillance Reviews are conducted annually to monitor ongoing ISMS compliance and effectiveness, assess updates, risk management practices, and continual improvement efforts, and provide feedback to maintain certification status. Finally, every three years, a Recertification Audit is performed to fully reassess the ISMS and renew certification.
HIPAA, CCPA, GDPR Privacy Audits
We provide comprehensive privacy audit services tailored to HIPAA, CCPA/CPRA, and GDPR compliance. For HIPAA, we assess risks to electronic protected health information (ePHI), ensure Privacy and Security Rule compliance, review breach response policies, and verify Business Associate Agreements (BAAs). For CCPA/CPRA, we conduct data mapping, evaluate consumer rights mechanisms, review privacy notices, assess data security practices, and audit vendor management. For GDPR, we review Data Protection Impact Assessments (DPIAs), validate lawful processing bases, ensure compliance with data subject rights and cross-border data transfer mechanisms, and assess breach management processes.

This site uses cookies to provide you with a more responsive and personalized service. By using this site you agree to our use of cookies.