Responsible Contact Person(s): Mike Jones, Chief Information Officer
Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025...
Responsible Contact Person(s): Mike Jones, Chief Information Officer
Corrective Action Planned: Language has been added to the Conduent contract renewal for option years 1 and 2 to require the SOC 1 Type II. The renewal is in the process of being reviewed and executed to go into effect July 1, 2025.
Language added to contract renewal: Contractor Internal Controls Reports
The Contractor shall provide the Department, at a minimum; annual, unredacted reports from its independent external auditor on the effectiveness of the Contractor’s internal controls conducted in accordance with the AICPA Statement on Standards for Attestation Engagements. If the reports disclose deficiencies in internal controls, the Contractor shall include management’s corrective action plans to remediate the deficiency. The Contractor shall provide the following reports:
· SOC 1 Type 2 Report that reports on the controls at the service organization which are relevant to the user entities’ internal control over financial reporting
· SOC 2 Type 2 Report covering all five Trust Services Criteria (Security, Availability, Processing Integrity, Privacy and Confidentiality)
The contractor shall provide the Department with these internal control reports within 30 days of the report’s issue date. Reports shall cover a period of 12 months beginning from the end date of the prior audit period with the first report covering a period of 12 months from the execution date of this contract. The contractor shall provide unredacted SOC 1 Type 2 and/or SOC 2 Type 2 reports as described above for any subservice organizations which provide a service to the Contractor that may impact the Department’s financial, program operations, or data security as determined by the Department.
Estimated Completion Date: 7/1/2026