From Findings to Fixes: Addressing Common SOC 2 Control Failures
See what membership includes, hear from members, and explore what Colorado's CPA community offers.
Students, emerging professionals, practicing CPAs, independent accountants — see all paths to membership in one view.
Your onboarding checklist, Connect setup guide, and member ambassador introductions — all in one place.
Browse 1,000+ live and on-demand courses, your CPE calendar, free Surgent library, and your transcript.
Accounting & auditing, tax, members in industry, or technology — CPE and resources for your practice.
Career Center, LeadFit leadership programs, Coaching Collaborative, and career development resources.
Member events calendar, networking events, and signature COCPA events — all in one view with easy filtering.
Find your group — tax, technology, industry, emerging professionals, DEI, and more. Join the conversations.
Preferred partners, member savings program, Verifyle, and other benefits included with your membership.
Meet this year's Everyday Heroes and Women to Watch. See past honorees and nominate a peer for recognition.
Speak for COCPA, write for NewsAccount, share a member milestone, or contribute to the profession's story.
Serve on a committee, join the board, mentor emerging professionals, or support the Educational Foundation.
The issues we're monitoring, the legislation we're shaping, and how COCPA advocates on behalf of Colorado CPAs.
Supporting students, aspiring CPAs, and the future of the profession — including the Educational Foundation and scholarships.
Support CPA-PAC, connect with legislators, and help build champions for the profession in Colorado.
COCPA administers the AICPA Peer Review program for firms in Colorado, New Mexico, and Washington — ensuring quality in accounting and attestation services.
Information technology and software continue to expand rapidly, with much of that growth driven by service organizations – companies that provide specialized services to businesses once performed internally.
For CPAs, this shift has increased reliance on outsourced service providers for data analytics, cloud hosting, and information security. It has also heightened responsibility for safeguarding company and client data.
If your organization relies on service organizations, obtaining and reviewing their System and Organization Controls (SOC) 2 report can provide insight into their control environment and any areas of concern. If you are a service organization, clients likely expect you to undergo a SOC 2 examination.
In the spring 2026 issue of NewsAccount, now available digitally, Esteban Rosas, CPA, CITP, senior manager with K Financial Audit and Advisory in Louisville, explores five control failures often found in service organizations’ SOC 2 reports:
Fortunately, Rosas asserts, most of these issues are straightforward to correct with structure, ownership, and repeatable processes. Check out the article, “From Findings to Fixes: Addressing Common SOC 2 Control Failures,” on page 26 of the spring issue for practical solutions to address these failures.
Looking for an opportunity to connect with your COCPA colleagues to discuss technology, its impact on the accounting profession, and future trends? Learn more about the COCPA Technology Users Group.
COCPA members can earn free CPE credit for NewsAccount readership. Take advantage of the opportunity to earn free CPE while staying on top of the latest news from the profession. Click here to learn more and register.