What Is a SOC 1 Bridge Letter and How Does It Work?

A SOC 1 bridge letter is a statement signed by a service organization’s management that covers the period between the end date of its most recent SOC 1 Type 2 audit report and a client’s fiscal year-end. The letter asserts that nothing material has changed in the control environment during that gap, letting the client’s auditors keep relying on the prior audit report for their own year-end work. Most auditors will accept a bridge letter for gaps of up to 90 days.

Why the Gap Exists in the First Place

Service organizations that handle financial data for clients get audited annually by independent CPA firms under the AICPA’s attestation standards, specifically AT-C Section 320 under SSAE 18.1AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center The audit tests whether internal controls over financial reporting are designed properly and operating as intended across the audit period.

The trouble is timing. A SOC 1 Type 2 report might cover a period ending September 30, but many clients close their books on December 31. That leaves a three-month window in which the client has no independent evidence about whether the service organization’s controls stayed intact. The bridge letter fills that window. It’s not an audit and not an independent opinion. It’s a management representation, and auditors weigh it accordingly.

Why Year-End Auditors Care

Public companies subject to the Sarbanes-Oxley Act must report annually on the effectiveness of their internal controls over financial reporting. Section 404 requires both a management assessment and an independent auditor attestation covering the full fiscal year.2SEC.gov. Study of the Sarbanes-Oxley Act of 2002 Section 404 Internal Control Over Financial Reporting Requirements When a company outsources payroll, benefits administration, or transaction processing to a service organization, the controls at that organization become part of the company’s overall control environment. A gap in documentation is a gap in evidence.

Without a bridge letter, the user entity’s auditors have to either test the service organization’s controls themselves for the uncovered period or flag the gap as a control deficiency. If that deficiency rises to a material weakness, management cannot conclude that internal controls are effective, and the auditor’s opinion on internal controls must be adverse.3SEC.gov. Appendix E Background and Basis for Conclusions A bridge letter is often the simplest way to avoid that outcome. Private companies aren’t governed by SOX, but their auditors follow the same professional standards when evaluating service organizations, so the evidentiary gap looks the same either way.

What the Letter Has to Say

A bridge letter needs to be specific enough that an auditor can read it, compare it against the SOC 1 Type 2 report, and confirm the two documents form a continuous chain of evidence. Vague assurances don’t clear that bar. At minimum, the letter should include:

  • The full title of the SOC 1 Type 2 report being extended, the exact dates of the period it covered, and the name of the CPA firm that performed the audit.
  • The precise start and end dates of the gap period, running from the day after the report’s period ended through the client’s fiscal year-end.
  • An explicit statement that management is not aware of any material changes, deficiencies, or issues in the control environment that would alter the conclusions in the original report.1AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center
  • A description of any minor changes made during the gap, with a brief explanation of why they don’t undermine the original report’s findings.
  • The signature, name, and title of an authorized executive, typically the CIO, CTO, or head of compliance.

The no-material-change assertion is the heart of the document. Making it credibly means management actually reviewed monitoring data, incident logs, and system change records for the gap period before signing. An assertion made without that review creates false reliance and is worse than no letter at all.

Who Signs It and How Clients Get It

The service organization’s management drafts and signs the bridge letter. This is one of the most important distinctions between the letter and the SOC 1 report itself. The report is an independent opinion issued by a licensed CPA firm; the bridge letter is a self-representation by the company being evaluated.4AICPA & CIMA. System and Organization Controls: SOC Suite of Services The auditor who performed the original SOC 1 examination does not sign, verify, or endorse it. That’s why auditors give a bridge letter less weight than the report. Management has an incentive to say everything is fine, so a competent user auditor will read the letter alongside other evidence, such as the service organization’s track record of stable controls and the absence of public incidents suggesting otherwise.

Distribution follows the same restricted-use model as the SOC 1 report itself: intended for the service organization, its user entities, and those user entities’ auditors. Most service organizations post the letter through a secure client portal, particularly during the January-through-March busy season when many clients need the same letter at once. Clients usually request the letter through the service organization’s compliance team.

The 90-Day Limit

The 90-day cap isn’t written into any formal auditing standard. It’s an industry convention reflecting a practical judgment: beyond three months, too much can change in a control environment for a management assertion alone to carry meaningful weight. Most user auditors treat it as a firm line. A letter covering four or five months will draw skepticism at best and rejection at worst.

That makes the timing of the SOC 1 report period matter. A service organization running an audit period from January through September puts every December 31 client right at the 90-day threshold. If the report period ends June 30, the gap is six months, and no bridge letter will cover it. Service organizations whose report periods are chronically misaligned with client fiscal years should consider shifting the audit window rather than trying to stretch bridge letters past their useful life.

When Material Changes Happen During the Gap

A bridge letter only works when the control environment genuinely hasn’t changed. If the service organization migrated to a new platform, restructured its IT function, experienced a security incident, or made significant changes to the processes described in the SOC 1 report, the standard no-material-change assertion becomes misleading. Signing that assertion anyway isn’t just unhelpful; it exposes the service organization to liability and puts the client’s auditors in a bad spot.

The honest approach is to disclose the changes in the letter, describe what happened, and explain what compensating controls or monitoring were put in place during the transition. Some changes are benign, such as upgrading a firewall appliance or adding a redundant backup, and a clear explanation will satisfy most auditors. Other changes are large enough that no bridge letter will suffice. A complete system migration during the gap period, for example, means the controls tested in the original audit may no longer exist. In that scenario the service organization should arrange for interim testing or an updated SOC 1 engagement rather than paper over the gap.

What Happens Without One

When a bridge letter is unavailable or covers too long a period to be accepted, the user entity’s auditors still need evidence of control effectiveness for the full fiscal year. Their options are none of them cheap or convenient:

  • Test the controls directly. The user entity sends internal auditors or engages external auditors to visit the service organization and test whether controls operated effectively during the uncovered period.
  • Build monitoring controls at the user entity. Reconciliation procedures and exception reporting around the outsourced process can provide evidence of control effectiveness independent of the service organization’s own controls.
  • Obtain an agreed-upon procedures report. The service organization engages its auditor to perform specific, limited testing for the gap period and issue a report on the results. Narrower than a full SOC 1, but it’s independent evidence rather than a management assertion.

The monitoring-controls approach is often the most practical for organizations that face recurring gap-period issues, because once those controls exist they produce evidence year-round regardless of when the SOC 1 report period falls.

Bridge Letters Only Work with Type 2 Reports

A SOC 1 Type 1 report evaluates whether controls are designed properly as of a single date. A Type 2 report tests whether those controls actually operated effectively over a period, typically six to twelve months.1AICPA & CIMA. Employee Benefit Plans: SOC 1 Reports and Service Organizations Resource Center Bridge letters exist to extend the coverage of a Type 2 report, because that’s the only kind that provides evidence about operating effectiveness over time. A Type 1 report is a snapshot; there’s no period of operating effectiveness to bridge forward. A bridge letter attached to a Type 1 report adds no meaningful value.

Aligning the Audit Period to Reduce the Gap

The simplest way to avoid bridge-letter headaches is to align the SOC 1 report period with the fiscal year-ends of most of your clients. Report periods generally don’t run through the calendar year-end because user entities and their auditors want the report in hand while performing interim testing during the fourth quarter. A service organization with mostly calendar-year clients might run its audit period from October through September, so reports land in November or December and the gap stays well inside the 90-day threshold for everyone.

When clients have varied fiscal year-ends, no single report period eliminates every gap. Building bridge letters into the annual compliance calendar keeps the process clean. Prepare the letter promptly after the SOC 1 report is issued, post it to the client portal, and tell clients it’s available. Organizations that get dinged for missing bridge letters are usually the ones treating them as ad hoc requests rather than scheduled deliverables.