Est.

SOC 2 Observation vs Exception vs Finding Distinctions

Learn why conflating SOC 2's three tiers ruins deal decisions.

Senior Writer · · 10 min read
Cover illustration for “SOC 2 Observation vs Exception vs Finding Distinctions”
SOC 2 scoping, readiness and Type I vs Type II · October 2, 2026 · 10 min read · 2,208 words

A procurement analyst sees “three exceptions noted” in a vendor’s SOC 2 report and shuts down the deal without realizing the report had an unqualified opinion all along. After a management letter notes outdated documentation, a vendor’s security lead spends a week preparing formal remediation for an issue the auditor never called a failed control. The root cause is the same in both cases: treating “observation,” “exception,” and “finding” as though they all mean one thing. But they do not: each term belongs to its own tier in SOC 2 reporting, so conflating them distorts the auditor’s conclusion.

SOC 2 grades nothing as passed or failed, and unlike some compliance frameworks it awards no certificate. Instead the auditor attests in a report, choosing among four possible opinions: a disclaimer of opinion, an adverse finding, a qualified one, or an unqualified one. Every term and every tier in this piece exists to feed that opinion. Get these terms wrong and you may either fret needlessly over matters that never shaped the opinion, or shrug at ones that did.

Some of the confusion comes from outside SOC 2 entirely. Practitioners who cut their teeth on ISO 27001 bring a graded nonconformity scale with them: observations, opportunities for improvement, minor nonconformities, major nonconformities. SOC 2 has no equivalent ladder of severity. Importing that mental model into a SOC 2 conversation leads people to assume a rank-ordered scale exists here too, when the actual structure runs on a different logic altogether, one this piece lays out next.

The four-level hierarchy that structures every SOC 2 Type II result

Sorting out "observation," "exception," and "finding" requires bringing in a fourth term first: deviation. It is the smallest piece of failure in the entire system, and every level above it is made up of deviations.

A deviation happens when one sampled item doesn't pass what the auditor is testing. For instance, if a policy mandates that recent employees complete mandatory cybersecurity instruction by a specific deadline after joining, yet the reviewer discovers someone who finished slightly behind schedule. That single case is a deviation. On its own, it won't appear in the auditor's final conclusion. Instead, it becomes foundational input for assessments further along the process.

An exception records, in formal documented terms, how the auditor responds when at least one deviation is identified. An exception may arise from a lone deviation, or it may capture a recurring issue seen in multiple deviations taken from a single sample. When material, exceptions are included in reporting and may change the opinion.

An audit finding is a wider category than a single exception. The auditor may flag multiple exceptions within a finding, or simply note other risks and weaknesses that never become formal. A finding does not always equal an exception. Such observations may surface in management letters or separate correspondence rather than within the SOC 2 report.

At the lowest level is what auditors may call an observation or management letter comment. It points to a possible process change or design concern that never became a formal exception. With no exception, it stays outside the opinion section.

| Term | Appears in the report? | Can affect the opinion? | |---|---|---| | Deviation | No, it's the underlying evidence | No, on its own | | Exception | Yes, in the test results section | Yes, if material or pervasive | | Finding | Sometimes, or in a separate letter | Only if it includes an exception | | Observation | Rarely, usually a separate communication | No |

Deviations turn into exceptions, and exceptions can become findings. Observations stay off to the side, apart from the formal report. Keep that structure in mind, because each section that follows comes back to it.

Diagram: SOC 2's Four-Tier Hierarchy: From Deviation to Opinion. Visualizes: Visualize the four-tier hierarchy that structures every SOC 2 Type II result, showing how each level feeds upward into the auditor's final opinion.

Why exceptions surface in Type II audits

Exceptions show up almost exclusively within Type II reports, and that traces back to the focus of a Type II engagement. A Type II asks whether controls operated effectively over a whole stretch of time, not just whether they were in place on a single date. Covering control operation across a stated period, often three, six, or nine months and sometimes twelve, the CPA firm draws a sample from every relevant event in that window.

Longer periods mean there are more opportunities for a miss. A skipped access review during the 4th month within a 12-month period is recorded as an exception, even if all the remaining monthly reviews were completed without issue. Because Type I is limited to control design at a single point in time, it may surface a design flaw, but most exceptions stem from operating-effectiveness breakdowns reportable only through a Type II engagement.

The AICPA taxonomy recognizes a trio of exceptions, each needing its own fix.

A design deficiency occurs when a necessary control is absent or was not constructed to achieve its intended goal from the start, representing a foundational flaw instead of a temporary malfunction. A company lacking an MFA policy on production accounts faces a structural flaw, not a temporary error.

When an organization’s Section III narrative gives an inaccurate or incomplete account of its systems and services, it has a system description misstatement. For example, once the company has moved to AWS, still portraying the environment months later as internally hosted infrastructure would misstate the system description even when the related controls operate properly.

A control has an operating effectiveness deficiency when it is well designed but fails to operate consistently throughout the observation period. This category includes quarterly access reviews recorded on paper when they occurred only two of four times.

No list here claims to cover everything. Treat them as examples of the issues auditors turn up when they dig.

Where each term appears inside the report

Understanding the hierarchy only matters if you can locate each part on the page. Four required components make up a SOC 2 report, with a voluntary addition possible: an auditor's opinion paired alongside management's assertion, plus the system description and a table detailing criteria together with corresponding controls, tests, and results. That optional fifth section holds unaudited material that management decided to include.

Begin with the opinion, because that is the first place a reader looks. When the opinion is qualified, Section I is where it should appear, not tucked into the testing summary. In the usual formulation, the auditor concludes that control design and operation pass muster, while excluding the significant impact of the issues laid out under Basis for Qualified Opinion. The wording signals a named, substantive exception that keeps the opinion from being clean.

Next, turn to the test results area in Section IV under AICPA’s format, where exceptions are recorded. For every line, the control being checked is linked with the relevant Trust Services Criterion such as CC6.8, the auditor’s work is summarized, the observed issue is stated in plain factual terms, and counts are shown for the testable population alongside the sample size: the full set of testable items compared with the subset chosen by the auditor.

The report presents findings and observations in separate ways. Those observations, along with any management letter comments, typically sit outside the report's formal sections. Instead, the auditor sends them in separate communications, outside what is attested. When the opinion is unqualified, that doesn't mean the report has no issues. The test results may still list exceptions individually even though the overall opinion is unqualified, so anyone who reads only the opinion page and skips Section IV misses the real substance.

Whenever an exception surfaces, the group typically has an opportunity to reply. That reply from management, usually found under Section V, should identify what caused the problem, the fix that was applied, and when it will be resolved.

Exception, Finding, and Observation Distinctions in the Audit Opinion

What a result gets called goes beyond mere style. It drives whether the opinion comes back modified, and that in turn decides whether a buyer can rely on the report, unchanged, for a sourcing call.

Lead with what is on the line. A qualified opinion is issued when the auditor judges that exceptions, taken singly or aggregated, would prevent the entity from meeting Trust Services Criteria requirements for any of its service commitments. That is the line in the sand, and everything underneath it comes down to how near a given result gets to crossing it.

When exceptions show up on their own, they typically end up documented during testing yet leave the opinion unchanged. Only when deficiencies are widespread or individually significant does the auditor shift to issuing a qualified opinion. Even within that category, some flaws matter more than others. Flaws in how a control was built typically outweigh execution errors, because a missing design reveals a structural gap while a single slip during twelve months is merely an operational lapse.

Such remarks and any management letter points bear no weight on the opinion. By definition they exist beyond the attested document, leaving them no way to reach the opinion section.

Findings fall somewhere in between. A finding may include exceptions, sometimes more than one, and when that's the case it can shape the opinion indirectly by way of those exceptions. But a finding that merely flags room to improve a process, and carries no exception, has no way to move the opinion in either direction.

Treating such vocabulary as exact invites fair criticism, since auditors apply these words loosely and separate practices may describe an identical root issue in conflicting ways. Relying purely on such labels therefore carries genuine risk. To correct this, regard the opinion portion as definitive regardless of terminology used elsewhere in the document, verify that opinion firsthand against the table of test results, and require management replies to identify the exact control and criterion at stake rather than depending on the auditor's chosen phrasing.

Another ambiguity deserves separate treatment: whether an exception is equivalent to a "control deficiency". An exception records evidence that the control fell short of its intended function. A deficiency points to a flaw built into or affecting the control, whether as designed or as performed, and that flaw usually leads to the exception. Calling them the same collapses the useful difference between cause and symptom during remediation rather than mere documentation.

How buyers and vendors read these terms differently

The same entry in a report carries one meaning for you and another for the party across the table.

When a buyer reviews vendor risk, what matters is whether an exception points to real security weakness at the vendor or merely to a recordkeeping issue corrected quickly. A clean opinion may still knock a vendor out of a stringent review if it includes multiple access-control exceptions, despite no formal qualification from the auditor. A vendor looks safer when its attestations are up to date, unqualified, and light on findings; expired reports, numerous findings, or any qualified opinion increase its risk score and invite closer review.

For the vendor being reviewed, observations are usually the simplest outcome to explain to a customer, because they never became part of the formal report and do not carry opinion weight. Still, that doesn't mean the vendor can set it aside internally. An unresolved observation may be written up as an exception during a later audit, after the same issue recurs often enough that the auditor no longer views it as an isolated note.

A qualified opinion demands an entirely separate response from a report packed with exceptions under an unqualified opinion, because this material finding requires deliberate, formal explanations to existing customers and prospects evaluating the vendor.

Management response quality has turned into its own signal that buyers watch closely. Buyers now read Section V as carefully as the opinion itself, because a strong response names the root cause, lays out the corrective action, and attaches a specific timeline, while a vague response does the opposite of reassure: it makes the underlying exception look worse than it might actually be.

Responding to each tier correctly: from management letter to qualified opinion

Match the remedy to the tier, not to how severe the label feels in everyday conversation. For an observation, make an internal record of the issue and outline the fix so it is closed ahead of the upcoming audit round, without issuing a formal statement to customers. Treat a finding with no exception just as lightly, keeping it on the improvement list rather than turning it into an emergency. When a control issue involves ineffective operation, for example, the quarterly review was skipped, the management response should identify the fix, assign responsibility, and give enough detail to show a Section V buyer what changed. Fixing a design deficiency takes more than a quick patch, since the control rebuilt has to start over entirely when the original design never satisfied the criteria. A qualified opinion demands those same steps plus reaching out proactively and directly to each client or potential buyer viewing that report, grounding the message in the specific issues cited within the Basis section that explains the Qualified Opinion instead of offering vague comfort. Aligning the response with the appropriate tier distinguishes a company that truly grasps its own audit from another merely panicking over the harshest term on the page.

Sources

  1. What are SOC 2 exceptions? Types, causes, and how to fix them
  2. SOC 2 Exceptions and Qualified Opinions Explained
  3. SOC 2 Report Example: A Detailed Section-by-Section Breakdown
  4. SOC 2 Observation Period Explained: Audit Readiness

More in SOC 2 scoping, readiness and Type I vs Type II