When you outsource direct mail, you’re not simply sending over some text and asking someone to print and put it in an envelope for you. Depending on the campaign, your mailing partner could be handling names, addresses, account details, financial information, customer communications and other sensitive data.
That makes the security controls behind your mailing operation just as important as the print quality or postage costs.
As such, you may have heard a prospective supplier mention SOC 1, SOC 2, or perhaps both, but what do these reports actually mean? And which one matters when you’re choosing a direct mail or transactional mail provider?
The short answer is that SOC 1 and SOC 2 look at different things: SOC 1 at financial reporting-relevant controls, while SOC 2 examines controls relating to security, with options for availability, processing integrity, confidentiality and privacy.
If your business is sending financial, transactional or highly sensitive communications, you’ll need to understand the difference. So, give this guide a read, and if you’re still unclear, call our team at 0800 612 1972, and we’ll help you figure out which you need.
What is a SOC report?
SOC stands for System and Organisation Controls. SOC reports are independent assurance reports designed to provide confidence in a service provider’s controls.
SOC reports are particularly relevant when a business outsources an important data-related process to a third party. Rather than every client having to carry out its own detailed assessment of the provider’s controls, a SOC report provides independent assurance about the areas covered by the examination.
Importantly, SOC 1 and SOC 2 are not interchangeable, and neither should simply be treated as a generic “security certificate”. While the reports can overlap in some of the controls they examine, they’re designed for different purposes. Some organisations will have both, especially when they provide services that have both financial-reporting and data-security implications.
So, the scope of the report matters. Let’s get into that:
SOC 1: Financial Reporting is the Focus
A SOC 1 report examines the service provider controls that are relevant to its client’s internal control over financial reporting. So, if you’re wondering if you need this – can your service impact the financial statements of your clients?
Payroll processing is a straightforward example: if a provider’s processes result in incorrect payroll calculations, that affects the financial records of its client (and possibly a whole lot more than just the records)
The same principle can apply to transactional mail. Consider a company sending invoices, statements, payment reminders or other financially significant communications. The accuracy and control of the processes behind those communications will be important to the client’s financial reporting.
A SOC 1 report gives organisations and their auditors information about the controls surrounding those processes.
SOC 2: Looking at Security and Data Controls
A SOC 2 report has a different, broader focus. It evaluates controls against the AICPA’s Trust Services Criteria. These can cover five areas:
- Security – protecting systems and information against unauthorised access and other threats
- Availability – ensuring systems and services are available as agreed
- Processing integrity – ensuring processing is complete, accurate, timely and authorised
- Confidentiality – protecting confidential information from unauthorised disclosure
- Privacy – addressing how personal information is collected, used, retained and disclosed
Security is the required criterion for a SOC 2 examination, while the other criteria can be included depending on the organisation and the scope of the report.
For direct mail, this is specifically important. A mailing campaign can involve large volumes of personal data moving through several stages: data transfer, processing, personalisation, print production, fulfilment, sorting and dispatch. A SOC 2 report covering a couple of criteria provides assurance around the controls that protect the systems and information involved.
In other words, SOC 2 is more directly concerned with the security and handling of data than SOC 1.
What Does SOC Mean for a Direct Mail Provider?
The important question isn’t simply whether a provider has a SOC 1 or SOC 2 report. It’s what that report covers and whether it relates to the services and data you’re outsourcing.
For example, a provider handling marketing mail will be processing names, addresses and customer preferences. A provider producing statements, invoices or other transactional communications may also be handling information connected to the client’s financial reporting processes.
So, it’s not simply a case of SOC 2 being “better” than SOC 1 because it’s more comprehensive. They provide assurance about different areas.
For a direct mail provider, the right question is therefore: does the scope of the report give you assurance about the particular services, systems and data you’re entrusting to them?
In some cases, a provider may have both SOC 1 and SOC 2 reports because its services involve both financial reporting and information security considerations.
SOC Type 1 vs Type 2: Another Distinction Worth Understanding
There is another piece of SOC terminology that’s easy to confuse with SOC 1 and SOC 2: Type 1 and Type 2 don’t describe different areas of security – they describe the period and depth of the examination.
A Type 1 report assesses whether controls are suitably designed as of a particular date.
A Type 2 report assesses the controls’ design and tests their operating effectiveness over a defined period. In other words, it provides evidence that the controls didn’t simply exist on paper on one particular day, but operated as intended during the period under review.
This is important when evaluating a mailing partner, because data security doesn’t only need to work on audit day. It needs to work when files are transferred on a Monday morning, when production volumes increase, when staff change, when systems are updated and when unexpected problems occur.
A Type 2 report therefore gives customers a whole different level of insight into the consistency of a provider’s controls.
Why SOC Matters When Outsourcing Customer Mail
Direct mail is sometimes treated as a physical process: print something, stick it in an envelope and send it off. However, modern mailing operations are much more connected than that.
A typical campaign can involve data transfer, validation, cleansing, segmentation, variable-data printing, production, quality checks, fulfilment, postal sortation and reporting. And the more that data moves through that process, the more important it becomes to understand how it’s protected at each stage.
Particularly for organisations operating in sectors such as financial services, healthcare, utilities, telecommunications, education and the public sector, where customer communications can contain sensitive or commercially important information.
Also, you can’t just ask: “Is your mailing company SOC certified?” There’s actually no generic SOC 1 or SOC 2 certification. Instead, SOC 1 and SOC 2 are attestation reports, and the useful information is in the scope, controls, testing and auditor’s opinion contained within the report.
So, a better question is: “What does your SOC report cover, and does that scope match the service and data we’re outsourcing?”
What Should You Look for when Assessing a Mailing Partner?
Start by checking the scope. Does the report actually cover the systems and services your organisation will be using? A provider may have multiple services, platforms or operating environments, and the report may not automatically cover all of them, so you’ve got to check.
Next, look at the report period. A Type 2 report provides more meaningful assurance about how controls have operated over time than a point-in-time assessment, so if you rely on robust security, that’s the one to go for.
It is also worth understanding which Trust Services Criteria are included in a SOC 2 report. Security is mandatory, but availability, processing integrity, confidentiality and privacy aren’t automatically all included. The scope should therefore be checked rather than assumed.
And finally, consider the SOC report alongside the provider’s wider security framework. Our GDPR compliance checklist blog will help you figure this out.
Choosing a Direct Mail Partner with Confidence
When customer data is part of the mailing process, the right provider should be able to explain not just what security standards they work to, but how those controls operate in practice.
At bakergoodchild, data security sets the foundation of our approach to managing direct and transactional mail, from secure data handling and processing through to print, fulfilment and dispatch.
If you’re reviewing your current mailing processes or assessing a new direct mail partner, our team will be happy to discuss the practical considerations and help you understand what to look for. Just give us a call at 0800 612 1972 or complete our contact form, and we’ll get it all figured out.




