AICPA SOC 3
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Assertion
Management asserts that controls were effective to meet applicable Trust Services Criteria.
- Management's written assertion
- System description supporting the assertion
- Assertion absent or unsupported by description
Common Criteria
Changes to infrastructure and applications follow authorized, tested, approved processes.
- Change tickets with approvals
- Testing/UAT evidence
- Segregation of dev/test/prod
- Emergency changes unapproved
- No change testing
Communicate commitments, requirements, and responsibilities to internal and external parties.
- Internal/external communication of security commitments
- Customer-facing commitments
- Information flow records
- Commitments not communicated to users
Governance, integrity, ethics, board oversight, and accountability establish the control environment.
- Governance/org structure
- Integrity and ethical values
- Board/management oversight
- No defined control environment
- Oversight not evidenced
Identify, respond to, communicate, and recover from security incidents impacting Trust Services commitments.
- Incident response plan
- Incident register
- Post-incident reviews
- No IR process
- Incidents not logged
Access provisioning, authentication, authorization, and review controls protect system resources.
- Access provisioning/deprovisioning
- MFA configuration
- Periodic access reviews
- Stale/orphaned access
- No access reviews
Ongoing monitoring activities detect control deficiencies and trigger remediation.
- Ongoing control monitoring
- Deficiency identification and tracking
- Control activity selection
- No monitoring of controls
Service organization identifies and evaluates risks impacting Trust Services Criteria objectives.
- Risk assessment process
- Fraud-risk consideration
- Risk responses
- No documented risk assessment
Manage third-party risks through due diligence, contracts, and ongoing monitoring of subservice organizations.
- Subservice organization controls
- Carve-out vs inclusive method
- Vendor monitoring
- Subservice org controls not addressed
Identify, prioritize, and remediate vulnerabilities through scanning, patching, and threat intelligence.
- Vulnerability scan reports
- Patch management records
- Remediation SLAs
- Unpatched known vulnerabilities
Confidentiality
Encryption in transit and at rest with key management protects confidential and personal data.
- Encryption at rest/in transit
- Access controls on data
- Data retention/disposal
- Sensitive data unencrypted
Criteria
SOC 3 uses Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- Which TSC categories are in scope
- Mapping of controls to criteria
- Scope/criteria mismatch with report
Distribution
SOC 3 reports may be freely distributed and used in marketing materials with appropriate logo guidelines.
- SOC 3 seal/logo usage policy
- General-use distribution records
- Misuse of SOC 3 seal
- Report presented as SOC 2
Report Purpose
SOC 3 reports provide general-use assurance on Trust Services Criteria suitable for unrestricted distribution.
- General-use designation
- Distribution to broad audience
- Confused with SOC 2 restricted-use report
Reporting
Service auditor opinion confirms whether controls operated effectively to meet TSC during the period.
- Independent service auditor's report (CPA firm)
- Opinion type (unqualified preferred)
- Auditor independence documentation
- No independent CPA opinion
- Qualified opinion not remediated
Scope
Define infrastructure, software, people, procedures, and data within the SOC 3 reporting scope.
- System description
- System boundary diagram
- In-scope components and locations
- Ambiguous or overstated system boundary
SOC 3 covers a defined examination period typically aligning with calendar or fiscal year quarters.
- Defined examination period (Type 2)
- Coverage with no gaps
- Reporting-period gaps
- Point-in-time only where Type 2 expected
TSC Availability
Availability criteria address system uptime commitments, capacity, monitoring, backup, and recovery.
- Availability commitments/SLAs
- Capacity and performance monitoring
- BCP/DR plans and test results
- Availability criterion in scope but not operating
- No capacity monitoring
TSC Confidentiality
Confidentiality criteria address protection of information designated confidential through retention, disposal, and access.
- Confidential information identification
- Handling and disposal procedures
- Encryption of confidential data
- Confidentiality criterion needed but out of scope
TSC PI
Processing integrity criteria address completeness, accuracy, timeliness, and authorization of system processing.
- Processing completeness/accuracy controls
- Input/output validation
- Error handling
- Processing integrity criterion not tested
TSC Privacy
Privacy criteria cover notice, choice, collection, use, retention, disclosure, quality, monitoring, and access for personal information.
- Privacy notice
- Consent/choice records
- PII collection-use-retention-disposal controls
- Privacy criterion needed but out of scope
TSC Security
Common Criteria 1 to 9 establish baseline security covering control environment, communication, risk, monitoring, and operations.
- Common Criteria control set (mandatory)
- Security policies and controls
- Security category (mandatory) has gaps
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the AICPA SOC 3 framework page.