Hard1 markMultiple Choice
Area III: SOC EngagementsSOC EngagementScope

CPA · Question 82 · Area III: SOC Engagements

An auditor is reviewing the 'System Boundaries' in a SOC 2® engagement. The client has excluded their 'Customer Support Chatbot' from the system description. The chatbot collects customer names and account numbers. Is this exclusion appropriate?

Answer options:

A.

Yes, chatbots are not IT systems.

B.

Yes, if the chatbot is hosted by a third party.

C.

No, because all software must be included.

D.

No, because the chatbot processes sensitive data (PII) relevant to the system's objectives.

How to approach this question

Does it touch the data? If yes, it's in scope.

Full Answer

D.No, because the chatbot processes sensitive data (PII) relevant to the system's objectives.✓ Correct
D
The system description must include all components (infrastructure, software, people, data, procedures) that are necessary to achieve the service commitments and system requirements. Since the chatbot handles sensitive customer data, excluding it would misrepresent the system's risk profile.

Common mistakes

Thinking third-party tools are automatically out of scope (they are subservice orgs).

Practice the full CPA ISC Practice Exam 3

82 questions · hints · full answers · grading

More questions from this exam