If your company outsources payroll or HR to ADP, your external auditor will ask for ADP’s SOC reports before signing off on your financial statements. ADP publishes two of them, both audited under standards set by the AICPA: a SOC 1 covering the controls that affect your financial reporting, and a SOC 2 covering security and operational controls. Both are issued as Type 2 reports for select products, both require a nondisclosure agreement to obtain, and both are only useful if the specific ADP product your organization uses is named in the scope.
SOC 1 or SOC 2: Which One Your Auditor Wants
The two reports answer different questions and go to different people inside your company.
The SOC 1 addresses controls over financial reporting. When ADP calculates wages, withholds taxes, and pushes journal entries into your general ledger, those processes flow straight into your financial statements. Your external auditors care about the SOC 1 because it tells them whether ADP’s controls over those processes are designed properly and operating as intended. For most ADP clients at audit time, this is the report that matters.
The SOC 2 covers a broader set of operational controls evaluated against the AICPA’s five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.1AICPA & CIMA. 2017 Trust Services Criteria (With Revised Points of Focus – 2022) IT governance and compliance teams usually review it to check ADP’s data centers, network security, disaster recovery, and data handling. The SOC 2 does not feed the financial statement audit the way the SOC 1 does, but it matters if your organization runs sensitive employee data through ADP’s platform.
Type 1 vs. Type 2
Each report comes in two versions. A Type 1 is a snapshot: it confirms that ADP’s controls were designed correctly on a single date. It cannot tell you whether those controls actually worked over time.
A Type 2 covers a defined period, usually six to twelve months, and tests whether the controls operated effectively throughout that window. For financial statement audits, Type 2 is the version most auditors will accept as sufficient evidence to reduce their own testing. Public companies subject to Sarbanes-Oxley Section 404, which requires management to assess and report on internal controls over financial reporting each year, need the Type 2.2Office of the Law Revision Counsel. 15 U.S. Code 7262 – Management Assessment of Internal Controls
ADP issues SOC 1 Type 2 and SOC 2 Type 2 reports across select products and services.3ADP. Data Security – ADP Each ADP product may have its own report with its own scope. A company using ADP Workforce Now cannot assume a report covering ADP TotalSource applies to them. Verify that the specific product your organization uses is named in the scope section. If it is not, the report will not help your audit.
What Is Actually Inside the Report
ADP SOC reports follow a standardized structure under SSAE 18. Four sections do most of the work.
The Auditor’s Opinion
The Independent Service Auditor’s Report contains the opinion. An unqualified opinion means the auditor found no material exceptions and concluded that ADP’s controls were properly designed and operating effectively throughout the review period. Your auditor can rely on that opinion to narrow their own testing under PCAOB AS 2601, the standard governing how auditors use service organization reports.4PCAOB. AS 2601 – Consideration of an Entity’s Use of a Service Organization
A qualified opinion signals a significant control failure or a limitation on what the auditor could test. Your auditor then has to determine whether the issue affects your financial statements, and that investigation translates into more audit hours.
Management Assertion and System Description
The Management Assertion is ADP’s formal statement that the system description is accurate and complete and that the controls described were implemented as of the specified date.
The System Description walks through the services covered, the technology infrastructure, and the boundaries of the system under review. Read it against the services your organization actually receives. If the described workflow does not match how your company uses the platform, you have a scope alignment problem that will undermine your auditor’s ability to rely on the report.
Control Objectives and Testing Results
The body of the report lists control objectives, such as reasonable assurance that payroll transactions are processed accurately and completely, along with the specific controls ADP uses to meet each one. For a SOC 1, these objectives address risks of financial misstatement directly, including wage calculation, tax withholding and deposit through EFTPS, and quarterly filings like Form 941 and annual wage statements like Form W-2.5Internal Revenue Service. About Form 941, Employer’s Quarterly Federal Tax Return The general ledger interface, which maps summarized payroll to your chart of accounts, is tested here as well.
The testing results show which controls were tested, the sample sizes, and the outcomes. “No exceptions noted” is what you want to see. When exceptions appear, the report describes the failure. A single exception in a low-volume, low-risk control area may not change anything about your audit. Exceptions in high-volume controls like payroll tax deposits or wage calculations will almost certainly trigger additional testing.
Complementary User Entity Controls: The Part Clients Miss
This is the section most client organizations underestimate, and it causes the most audit problems. Complementary User Entity Controls (CUECs) are controls that ADP assumes your organization will perform. ADP’s controls are designed to work only in combination with these client-side controls. Ignore them and the framework falls apart, no matter how clean ADP’s opinion is.
Common CUECs in ADP’s reports include:
- Reviewing the monthly payroll register reconciliation ADP provides.
- Promptly removing terminated employees’ access to the ADP platform.
- Maintaining accurate employee demographic and compensation data.
- Reviewing output reports for reasonableness before posting journal entries.
Your auditor will ask for evidence that your organization performed each relevant CUEC throughout the audit period. “We do that informally” is not an acceptable answer. You need documented, dated evidence of each control’s execution. Without it, your auditor cannot rely on the ADP SOC report and will expand their testing scope.
Employment tax records must be kept for at least four years after the tax becomes due or is paid, whichever is later.6Internal Revenue Service. How Long Should I Keep Records? Public companies subject to SOX face a stricter standard: audit workpapers must be retained for at least five years from the end of the fiscal period in which the audit concluded, and knowingly destroying those records can bring fines and up to ten years in prison.7Office of the Law Revision Counsel. 18 U.S. Code 1520 – Destruction of Corporate Audit Records Retain your CUEC documentation for at least as long as the longer of these requires.
Subservice Organizations and the Carve-Out Gap
ADP relies on third-party vendors for certain functions, such as banks that process tax deposit transactions and cloud providers that host portions of the platform. Under SSAE 18, the SOC report must disclose these subservice organizations and explain how their controls are treated.
Two approaches exist. Under the inclusive method, the subservice organization’s controls are folded into ADP’s report and tested alongside ADP’s. Under the carve-out method, the subservice organization’s controls sit outside the scope of the report. ADP still monitors those vendors, and the monitoring controls are tested, but the subservice organization’s own controls are not.
Most large service organizations, including ADP, use the carve-out method. That creates a gap in the assurance chain. If a critical function like tax deposit processing runs through a carved-out subservice organization, your auditor may need to obtain that vendor’s own SOC report or perform alternative procedures. Check the system description for which subservice organizations are carved out and what functions they perform. If a carved-out entity handles something material to your financial statements, raise it with your auditor early.
How to Get ADP’s SOC Reports
ADP SOC reports are not posted publicly. Access requires a signed nondisclosure agreement between your organization and ADP.3ADP. Data Security – ADP Start by contacting your ADP account representative or sales team. Once the NDA is in place, the reports are delivered electronically through a secure portal or file transfer.
Start early. ADP’s SOC report coverage periods typically run six to twelve months, and a lag always exists between the end of the coverage period and the issue date. If your fiscal year ends December 31 and the SOC report covers a period ending September 30, that three-month gap is something your auditor will need addressed. Request the report early in your audit cycle rather than waiting until your auditor asks. Late delivery is one of the most common causes of year-end audit delays.
Bridge Letters for Coverage Gaps
The SOC report period rarely aligns perfectly with your fiscal year-end. When the report period ends before your fiscal year does, your auditor needs assurance that ADP’s controls kept working during the uncovered months.
The standard solution is a bridge letter, sometimes called a gap letter. This is a written statement from ADP management covering the period between the end of the SOC report and your fiscal year-end. Bridge letters typically cover up to three months. A valid one identifies the SOC report period it extends, states whether any material changes occurred in the control environment during the gap, and includes a disclaimer that the letter does not replace the SOC report.
Note the limitation: the bridge letter comes from ADP management, not from the independent auditor who performed the SOC examination. That auditor has no visibility into whether controls continued working after their testing window closed. A bridge letter provides less assurance than the SOC report itself, and your auditor may require additional procedures if the gap runs longer than a few months or if the bridge letter discloses material changes.
If ADP cannot provide a bridge letter or the gap exceeds three months, your auditor may need to perform their own testing over the gap period.
When Your Auditor Cannot Rely on the Report
Several scenarios can break reliance: a qualified opinion, material exceptions in key controls, missing CUEC documentation on your end, a scope mismatch between the report and the services you actually use, or a gap period that cannot be bridged. When reliance breaks down, your auditor has to treat ADP as a black box and test the outsourced processes independently.
Under PCAOB AS 2601, the auditor’s options at that point include testing your organization’s own controls over ADP’s output (reconciliations, output report reviews, independent recalculations), performing substantive testing on the transactions ADP processed, or in rare cases visiting ADP to test directly.4PCAOB. AS 2601 – Consideration of an Entity’s Use of a Service Organization All of these alternatives cost more than relying on a clean SOC report. For organizations with significant payroll volumes, the additional fees add up quickly.
Treat the SOC report as something your organization actively manages rather than passively receives. Verify product scope alignment before audit season, document every relevant CUEC throughout the year, request the report early, and raise any exceptions or gaps with your auditor before fieldwork begins.