Skip to content

Evidence request lists

AICPA SOC 3

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Assertion

SOC3-MGMT-ASSERT
Management Assertion

Management asserts that controls were effective to meet applicable Trust Services Criteria.

Artefacts an auditor will ask for
  • Management's written assertion
  • System description supporting the assertion
Where this commonly fails
  • Assertion absent or unsupported by description

Common Criteria

SOC3-CHANGE-MGT
Change Management

Changes to infrastructure and applications follow authorized, tested, approved processes.

Artefacts an auditor will ask for
  • Change tickets with approvals
  • Testing/UAT evidence
  • Segregation of dev/test/prod
Where this commonly fails
  • Emergency changes unapproved
  • No change testing
SOC3-COMMS
Communication

Communicate commitments, requirements, and responsibilities to internal and external parties.

Artefacts an auditor will ask for
  • Internal/external communication of security commitments
  • Customer-facing commitments
  • Information flow records
Where this commonly fails
  • Commitments not communicated to users
SOC3-CONTROL-ENV
Control Environment

Governance, integrity, ethics, board oversight, and accountability establish the control environment.

Artefacts an auditor will ask for
  • Governance/org structure
  • Integrity and ethical values
  • Board/management oversight
Where this commonly fails
  • No defined control environment
  • Oversight not evidenced
SOC3-INCIDENT-MGT
Incident Response

Identify, respond to, communicate, and recover from security incidents impacting Trust Services commitments.

Artefacts an auditor will ask for
  • Incident response plan
  • Incident register
  • Post-incident reviews
Where this commonly fails
  • No IR process
  • Incidents not logged
SOC3-LOGICAL-ACCESS
Logical Access

Access provisioning, authentication, authorization, and review controls protect system resources.

Artefacts an auditor will ask for
  • Access provisioning/deprovisioning
  • MFA configuration
  • Periodic access reviews
Where this commonly fails
  • Stale/orphaned access
  • No access reviews
SOC3-MONITORING
Monitoring Controls

Ongoing monitoring activities detect control deficiencies and trigger remediation.

Artefacts an auditor will ask for
  • Ongoing control monitoring
  • Deficiency identification and tracking
  • Control activity selection
Where this commonly fails
  • No monitoring of controls
SOC3-RISK-ASSESS
Risk Assessment Process

Service organization identifies and evaluates risks impacting Trust Services Criteria objectives.

Artefacts an auditor will ask for
  • Risk assessment process
  • Fraud-risk consideration
  • Risk responses
Where this commonly fails
  • No documented risk assessment
SOC3-VENDOR
Vendor and Subservice Management

Manage third-party risks through due diligence, contracts, and ongoing monitoring of subservice organizations.

Artefacts an auditor will ask for
  • Subservice organization controls
  • Carve-out vs inclusive method
  • Vendor monitoring
Where this commonly fails
  • Subservice org controls not addressed
SOC3-VULN-MGT
Vulnerability Management

Identify, prioritize, and remediate vulnerabilities through scanning, patching, and threat intelligence.

Artefacts an auditor will ask for
  • Vulnerability scan reports
  • Patch management records
  • Remediation SLAs
Where this commonly fails
  • Unpatched known vulnerabilities

Confidentiality

SOC3-DATA-PROTECT
Data Protection

Encryption in transit and at rest with key management protects confidential and personal data.

Artefacts an auditor will ask for
  • Encryption at rest/in transit
  • Access controls on data
  • Data retention/disposal
Where this commonly fails
  • Sensitive data unencrypted

Criteria

SOC3-TSC
Trust Services Criteria Coverage

SOC 3 uses Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Artefacts an auditor will ask for
  • Which TSC categories are in scope
  • Mapping of controls to criteria
Where this commonly fails
  • Scope/criteria mismatch with report

Distribution

SOC3-MARKETING-USE
Marketing and Distribution

SOC 3 reports may be freely distributed and used in marketing materials with appropriate logo guidelines.

Artefacts an auditor will ask for
  • SOC 3 seal/logo usage policy
  • General-use distribution records
Where this commonly fails
  • Misuse of SOC 3 seal
  • Report presented as SOC 2

Report Purpose

SOC3-PURPOSE
General Use Trust Services Report

SOC 3 reports provide general-use assurance on Trust Services Criteria suitable for unrestricted distribution.

Artefacts an auditor will ask for
  • General-use designation
  • Distribution to broad audience
Where this commonly fails
  • Confused with SOC 2 restricted-use report

Reporting

SOC3-AUDITOR-OPINION
Auditor Opinion

Service auditor opinion confirms whether controls operated effectively to meet TSC during the period.

Artefacts an auditor will ask for
  • Independent service auditor's report (CPA firm)
  • Opinion type (unqualified preferred)
  • Auditor independence documentation
Where this commonly fails
  • No independent CPA opinion
  • Qualified opinion not remediated

Scope

SOC3-BOUNDARY
System Boundary

Define infrastructure, software, people, procedures, and data within the SOC 3 reporting scope.

Artefacts an auditor will ask for
  • System description
  • System boundary diagram
  • In-scope components and locations
Where this commonly fails
  • Ambiguous or overstated system boundary
SOC3-PERIOD
Reporting Period

SOC 3 covers a defined examination period typically aligning with calendar or fiscal year quarters.

Artefacts an auditor will ask for
  • Defined examination period (Type 2)
  • Coverage with no gaps
Where this commonly fails
  • Reporting-period gaps
  • Point-in-time only where Type 2 expected

TSC Availability

SOC3-AVAILABILITY
Availability Criteria

Availability criteria address system uptime commitments, capacity, monitoring, backup, and recovery.

Artefacts an auditor will ask for
  • Availability commitments/SLAs
  • Capacity and performance monitoring
  • BCP/DR plans and test results
Where this commonly fails
  • Availability criterion in scope but not operating
  • No capacity monitoring

TSC Confidentiality

SOC3-CONFID
Confidentiality

Confidentiality criteria address protection of information designated confidential through retention, disposal, and access.

Artefacts an auditor will ask for
  • Confidential information identification
  • Handling and disposal procedures
  • Encryption of confidential data
Where this commonly fails
  • Confidentiality criterion needed but out of scope

TSC PI

SOC3-PROC-INTEG
Processing Integrity

Processing integrity criteria address completeness, accuracy, timeliness, and authorization of system processing.

Artefacts an auditor will ask for
  • Processing completeness/accuracy controls
  • Input/output validation
  • Error handling
Where this commonly fails
  • Processing integrity criterion not tested

TSC Privacy

SOC3-PRIVACY
Privacy Criteria

Privacy criteria cover notice, choice, collection, use, retention, disclosure, quality, monitoring, and access for personal information.

Artefacts an auditor will ask for
  • Privacy notice
  • Consent/choice records
  • PII collection-use-retention-disposal controls
Where this commonly fails
  • Privacy criterion needed but out of scope

TSC Security

SOC3-SECURITY
Common Criteria Security

Common Criteria 1 to 9 establish baseline security covering control environment, communication, risk, monitoring, and operations.

Artefacts an auditor will ask for
  • Common Criteria control set (mandatory)
  • Security policies and controls
Where this commonly fails
  • Security category (mandatory) has gaps
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AICPA SOC 3 framework page.