← All posts
SOC 2 management representation letterSOC 2 representation letterSOC 2 audit documents

SOC 2 Management Representation Letter: What to Check Before Signing

Review the SOC 2 management representation letter against your scope, period, system description, exceptions, and later events before management signs it.

Review each statement in the CPA firm's representation letter against the engagement facts and the records behind it.
Review each statement in the CPA firm's representation letter against the engagement facts and the records behind it.

A SOC 2 management representation letter is a signed letter from the responsible party to the service auditor. It gives written representations requested for the examination. If your CPA firm sends a draft, treat each sentence as a claim to check against your actual system, period, records, and known exceptions. Ask the firm to resolve anything you cannot support before management signs.

The AICPA’s Type 2 illustrative letter says AT-C section 205 requires the service auditor to request written representations from the responsible party in a letter addressed to the auditor. That example is available to AICPA members. Your CPA firm should provide the wording for your engagement.

Which management document are you reviewing?

Three management documents can appear near the end of SOC 2 work. They answer different questions, so give each one its own review and approval.

Document Reader What management is saying
Management assertion Readers of the SOC 2 report The system description and controls meet the stated claims for the covered date or period.
Management representation letter The service auditor Management makes the written representations the CPA firm requests for its examination.
Bridge letter A buyer or other report user Management reports on a gap after an existing SOC 2 report period.

The AICPA’s illustrative SOC 2 report includes the management assertion and the independent service auditor’s report. See our management assertion guide for the claims that go into the report. A bridge letter addresses later months for a report user and does not extend the CPA firm’s opinion. Neither document substitutes for a representation letter requested by the auditor.

What should you check before signing a SOC 2 representation letter?

Start with the CPA firm’s draft, then make a small review sheet with one row per statement. Record the source, the person who checked it, the date checked, and any open question for the firm. At a small startup, the founder may sign while an engineer, security owner, or operations lead supplies the facts behind a specific statement.

Check Compare with Question for the reviewer
Entity, service, and scope Engagement terms and final system description Does the letter name the same company and bounded system?
Report type and dates Agreed Type 1 date or Type 2 period Does the claim cover the right time, with no future days?
Criteria and controls Final description, scoped controls, and assertion Do the stated criteria and control claims match the report draft?
Information supplied to the auditor Request list, responses, and source records Did we provide the relevant records and explain gaps?
Exceptions and changes Test results, incidents, changes, and remediation Would an unqualified sentence hide a known fact?
Events after the period Incident, system, vendor, and governance records since period end Could a later event affect the description or the auditor’s work?
Signer and letter date Current authority record and CPA firm’s instructions Can this person stand behind the statements on the agreed date?

The exact representations vary by engagement. This sheet helps management review the firm’s letter; it is not a substitute for the firm’s requested text. For a Type 2 period, use complete audit populations and the evidence packet to check what happened across the period. A few screenshots from fieldwork cannot answer a claim about the whole period.

For example, suppose the draft says management disclosed all relevant security incidents. Your incident owner should review the incident register, the supporting source records, and the disclosures already sent to the auditor. If an incident was omitted, give the CPA firm the facts and discuss the wording. Do not treat a clean sentence as a reason to erase the incident.

How do you resolve a sentence you cannot support?

Mark the sentence open and tell the CPA firm exactly what conflicts with it. Share the underlying record and ask how the firm wants to handle the fact in its work and the final letter. The auditor may ask for more evidence, change the requested wording, or address the issue elsewhere in the examination. The CPA firm makes that call; FileGRC and this checklist do not decide whether evidence is sufficient.

Keep the review trail. If a system changed during the covered period, record when it changed, which controls and description text it affected, and what the firm received. If a control did not operate, record the missed work and any remediation. A signer should see these facts before approving the exact final text.

When should the letter be signed and stored?

Review a draft early enough to find mismatches, but finish the letter after the covered date or period. AT-C section 205, paragraph .55 says written representations should be dated as of the practitioner’s report date. Coordinate the signing time with your CPA firm so the settled letter carries that date; do not backdate a signature. Confirm the final signer, signature method, and delivery channel with the firm. Keep a fixed copy of the signed letter and a record of the actual signing time; restrict access according to your engagement and company rules.

The SOC 2 audit readiness checklist helps settle the scope, description, records, and exceptions before fieldwork ends. It cannot preapprove a future representation letter. If a material fact changes between draft review and signing, reopen the review.

Keep the management review in FileGRC

FileGRC is a Git-native GRC workspace for SOC 2 work. JSON holds structured records, Markdown holds long-form work, and Git supplies the change history. Its Audit Documents can hold an engagement-specific representation letter linked to the named Audit, with approval tied to the reviewed revision. Keep the final signed copy and actual signature evidence with the engagement’s restricted records.

Starter records are proposals, not compliance claims. FileGRC does not replace the systems that produce access, incident, change, or other evidence. Management owns the letter and the independent CPA firm performs the examination. The workspace can show which text was reviewed and how it changed; it cannot make an unsupported statement true.

Open source · MIT

Run your SOC 2 program as files in Git.

Keep policies, controls, work, and evidence indexes in a repository your team and agents can inspect. Add optional hosted email and Slack reminders to keep work moving.

Frequently asked questions

What is a SOC 2 management representation letter?

It is a letter from the responsible party to the service auditor containing written representations for the SOC 2 examination. The CPA firm requests it under AT-C section 205. Management should review the engagement-specific wording and support for every statement before signing.

Is the representation letter part of the SOC 2 report?

The representation letter is addressed to the service auditor. It is separate from management's assertion, which appears with the SOC 2 report. Ask your CPA firm which final documents it will include in the report and which it will keep with the engagement record.

Who signs the SOC 2 representation letter?

The responsible party's authorized management signs the letter. Confirm the signer and exact wording with the CPA firm. The signer should understand the scoped system, covered date or period, known exceptions, and statements in the letter.

When should management sign the representation letter?

Review a draft during fieldwork, then coordinate signing with the CPA firm so the settled letter is dated as of the service auditor's report date, as AT-C section 205 requires. Do not sign a statement about a period that has not ended or backdate a signature.

What if a statement in the CPA firm's draft is wrong?

Tell the CPA firm what is wrong and provide the underlying facts before signing. Resolve a scope, date, incident, exception, or subsequent-event mismatch in the source records and the letter. Do not silently delete a requested representation or sign a statement you cannot support.

Can FileGRC write or approve the letter for management?

No. FileGRC can keep an engagement-specific Document, its Markdown text, approval record, and Git change history together. Management owns the statements and signature, and the CPA firm directs the examination and final letter wording.