ADP SOC 1 Report: Requesting, Bridge Letters, and User Controls

If your company is going through a financial statement audit, your auditor will ask for the ADP SOC 1 report, a confidential document describing the controls ADP uses to process payroll, benefits, and other financial transactions on your behalf. You get it by requesting it through ADP’s client service channels, and in almost every case you want the Type 2 version covering a period that lines up with your fiscal year. Start early. Getting the wrong version, or getting the right one too late, is what turns a routine audit request into a fee overrun.

Type 1 or Type 2

SOC 1 reports come in two versions, and picking the wrong one wastes real time.

A Type 1 report is a snapshot. It confirms that ADP’s controls were properly designed as of a single date. It says nothing about whether those controls actually worked over any stretch of time, so your auditor cannot use it to reduce their own testing.

A Type 2 report covers a defined period, usually twelve months. ADP’s independent auditor samples transactions across that period, tests them against stated control objectives, and documents the results, including any deviations and ADP management’s response. This is the evidence your auditor needs to rely on ADP’s controls and scale back transaction-level testing on your side.

For virtually every annual financial statement audit, request the Type 2. And pay attention to the period it covers. If your fiscal year ends December 31 and the report covers January through September, that leaves a three-month gap your auditor has to close through other means. The closer the report period matches your fiscal year, the less extra work lands on your audit team.

How to Request the Report from ADP

The report is confidential and restricted to ADP clients and their auditors. It is not on ADP’s public website. Distribution runs through ADP’s internal channels.1ADP. Data Security

The standard route is ADP’s client service portal, where compliance documents are available to authorized users. If you can’t find the report there, contact your ADP account representative or the compliance support team directly. When you make the request, specify:

  • That you need the SOC 1 Type 2 report, not the Type 1 and not the SOC 2
  • The reporting period your auditor requires
  • Whether you also need a bridge letter (see below)

ADP will verify your client status before releasing the document. Allow several weeks. If the current report has not been issued yet, or if verification takes longer than expected, a late start pushes back your auditor’s fieldwork. When auditors can’t review the SOC 1 during their planned window, they expand their own substantive testing, and that expanded scope shows up on your invoice.

Bridge Letters When the Periods Don’t Align

ADP issues SOC 1 Type 2 reports on select products and services, generally on an annual cycle, and the report period rarely lines up perfectly with any one client’s fiscal year. To cover the gap between the end of the report period and the date your auditor needs assurance through, ADP produces four bridge letters per year, one for each calendar quarter.1ADP. Data Security

A bridge letter is a management-signed statement from ADP asserting that no significant changes have occurred to the control environment since the last formal report. It is not a substitute for a Type 2 report. Auditors are generally comfortable relying on a bridge letter that covers no more than about three months. Past that, the assurance erodes and your auditor may require additional procedures.

Ask about bridge letter availability when you request the report, not later. If your fiscal year-end falls outside ADP’s report period, you will almost certainly need one.

Complementary User Entity Controls You Have to Perform

This is where most user entities stumble. ADP’s controls are designed on the assumption that your company is performing certain procedures internally. Those procedures are listed in the report as Complementary User Entity Controls, or CUECs. If your team is not performing them, ADP’s controls alone are not enough, and your auditor cannot fully rely on the report no matter how clean the opinion.2AICPA & CIMA. SOC 1 – SOC for Service Organizations: ICFR

Common CUECs for a payroll service organization include:

  • Reviewing and approving payroll registers before ADP processes the final run
  • Reconciling ADP-generated reports to your general ledger
  • Restricting access to the ADP portal to authorized personnel
  • Promptly notifying ADP of terminations and pay rate changes

Your auditor tests these CUECs directly. They will ask for evidence that your team performed each one throughout the year. If you cannot produce it, your auditor loses the ability to rely on the corresponding ADP controls, and testing scope expands.

Handle this before fieldwork. Pull last year’s CUEC list as soon as it is available, assign each control to a specific person, confirm the work is actually happening, and make sure documentation exists. Discovering a gap during the audit is expensive.

What Your Auditor Will Look At

Your auditor does not accept the report at face value. They work through it to decide how much reliance to place on ADP’s controls and how much of their own testing they can scale back.

The Service Auditor’s Opinion

The first thing your auditor reads is the opinion. An unqualified opinion means ADP’s auditor concluded that the system description was fairly presented and the controls operated effectively throughout the report period. That is the outcome you want and the strongest basis for reliance.

A qualified opinion identifies specific control objectives where problems were found. Your auditor will assess whether those areas touch controls relevant to your transactions. If they do, expect additional testing in those areas.

An adverse opinion means the service auditor found material, pervasive problems. Your auditor essentially cannot rely on the report. A disclaimer of opinion, where the service auditor could not gather enough evidence to conclude, creates the same practical result. Both are rare for a service organization of ADP’s size, but the consequences for timeline and cost are real when they happen.

Deviations in the Testing Results

Even with an unqualified opinion, the testing results section often lists individual control deviations. Your auditor examines the nature and frequency. Isolated deviations in peripheral areas are usually not a concern. Recurring deviations in controls that directly affect payroll calculations or benefits processing prompt closer work.

Your auditor also reviews ADP management’s response to each deviation. A deviation paired with a credible remediation plan carries less weight than one where the issue is unacknowledged. Two reports can both carry unqualified opinions and still lead to very different audit workloads depending on where the exceptions fall.

Carved-Out Subservice Organizations

ADP relies on other vendors to deliver parts of its service. Those vendors are called subservice organizations. ADP typically uses the carve-out method, meaning those vendors’ controls are excluded from the SOC 1 report’s scope. The report will name the subservice organization and describe what it does, but the service auditor’s testing does not extend to it.3PCAOB. AI 18: Consideration of an Entity’s Use of a Service Organization: Auditing Interpretations of AS 2601

When your auditor sees this, they decide whether the carved-out organization’s controls matter to your financial reporting. If they do, your auditor has to get comfortable another way, often by obtaining the subservice organization’s own SOC 1 report or by performing direct procedures.

Mistakes That Cost Time and Money

Three problems come up again and again.

The first is timing. Companies request the report too late, discover it does not cover the right period, and scramble for a bridge letter that may or may not satisfy the auditor. Request the report at least two months before fieldwork, and confirm the reporting period lines up with your fiscal year-end before your auditor shows up.

The second is ignoring CUECs. The report lists them plainly, but many companies never assign ownership internally. When the auditor asks for evidence that someone reviewed the payroll register before every pay cycle, the answer is often nothing. Assign each CUEC, build it into recurring processes, and keep the documentation.

The third is treating the report as a checkbox. It contains real information about how ADP handles your financial data. If ADP’s auditor identified deviations in payroll calculation controls and you run payroll for thousands of employees, that finding matters operationally, not just to the auditor. Read the report when you receive it and flag anything that touches the ADP services you actually use.