Statewide System and Organization Controls (SOC) Report Guidance and Monitoring - 000-0801-26

Description

Departments may engage with third-party service organizations (TPSOs) to perform various activities, such as accounting, payroll, security, hosting applications or data, cloud services call centers customer service, marketing, or payment processing. The Office of Internal Audit Services (OIAS) provides guidance for managing and evaluating TPSOs’ controls through the State of Michigan Financial Management Guide and consultative services. OIAS has provided templates for the departments to use and annually requests departments to submit their TPSOs’ inventory listings, risk assessments, SOC reports, and SOC reports’ review for only financial TPSOs which are material to the State of Michigan Annual Comprehensive Financial Report audit. As of June 8, 2026, the State had approximately 560 externally hosted applications.

Audit Objectives

  • To assess the sufficiency of the State’s oversight efforts on TPSOs.

Timing

Estimated Release Date: Early 2027


← Back to all work in progress