SOC 2
Evidence request list. 61 controls, 61 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
A - Availability
Maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives
- Monitoring evidence of current processing capacity and use across infrastructure, data and software components
- Defined thresholds and alerting on approach to capacity limits, with evidence of the alerts raised in the period
- Capacity forecasts reflecting expected demand, business change and growth, with the review cycle and who performs it
- Records of capacity being added or adjusted as a result of the evaluation
- Evidence capacity management covers cloud quotas and licence limits, which behave as hard capacity constraints
- Utilisation monitored with no defined threshold, so evaluation only happens after the availability commitment is missed
- Forecasting based on past trend with no input from planned business change
- Capacity considered for compute and storage while log storage, database connections and quota limits are unmanaged
- Evaluation performed with no record, so the criterion cannot be tested even though the activity occurs
Authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives
- Evidence of environmental protections at the facilities in scope, covering fire detection and suppression, power continuity, cooling and water detection, with testing and maintenance records
- The backup configuration showing scope, frequency and retention against the recovery point objective
- Evidence of protection of backup data, including encryption, access restriction and an immutable or offline copy
- Evidence of the recovery infrastructure, including alternative processing capability and its readiness
- Evidence these are authorised, approved, maintained and monitored, including who approved the design
- Backups configured with failures reported and never investigated, so gaps in the backup set are unknown
- Backups reachable using production credentials, so a single compromise destroys both
- Environmental protections at the primary site only, with the recovery site unassessed
- Reliance on a cloud provider's environmental controls with no review of their assurance report or of the complementary controls it assumes
Tests recovery plan procedures supporting system recovery to meet its objectives
- The recovery test plan for the period, showing scope, scenario, participants and the objectives being tested
- Test results recording what was recovered, the time taken and whether the recovery objectives were met
- Evidence of actual restoration of data from backup, verified for completeness and integrity, not only that a job reported success
- Records of issues identified during testing and evidence of their remediation
- Evidence of the frequency of testing and that it covers the systems within the availability commitment
- Testing limited to a walkthrough or a single file restore, which does not test the recovery plan procedures the criterion names
- Restore performed with no verification the recovered data was complete and usable
- Results recorded as successful with no measurement against the recovery time and recovery point objectives
- Issues found in the test carried forward to the next test unresolved
C - Confidentiality
Identifies and maintains confidential information to meet the entity's objectives related to confidentiality
- The definition of confidential information for the entity, including information designated confidential by customers or by contract
- Evidence confidential information is identified across the system, covering where it is received, processed, stored and transmitted
- The protections applied, such as access restriction, encryption and handling rules, tied to the identification
- Evidence of the retention period applied to confidential information and of its basis
- Evidence customers are informed of and agree the confidentiality commitments the entity makes
- Confidentiality commitments made in contracts that were never translated into an internal definition anyone operates against
- Confidential information identified in the primary system while copies in analytics, support tooling and non production environments are unidentified
- Retention undefined, so confidential information is held indefinitely with no basis
- Protection applied uniformly with no relation to the identification, so the identification step adds nothing
Disposes of confidential information to meet the entity's objectives related to confidentiality
- The disposal procedure for confidential information, defining the method per medium and per system
- Records of disposal performed in the period, showing what was disposed of, when and by what method
- Evidence disposal covers all copies, including backups, archives, replicas and third party held copies
- Certificates or records from any third party performing destruction, reconciled at item level
- Evidence of verification that disposal was effective and that the information is no longer recoverable
- Retention periods defined and never enforced, so nothing is actually disposed of
- Disposal performed in the primary system while backups retain the information beyond the committed period
- Third party destruction certificates accepted with no reconciliation to what was sent
- Logical deletion treated as disposal, leaving the data present and recoverable
CC - Common Criteria (Security)
Demonstrates a commitment to integrity and ethical values
- The code of conduct or ethics policy, with evidence of board or senior management approval
- Acknowledgement records from personnel, contractors and, where relevant, vendors, covering the full population in the period
- Evidence standards of conduct are communicated on an ongoing basis, not only at hire
- Records of the whistleblower or ethics reporting channel, including its independence and evidence of use
- Evidence of evaluation of adherence and of deviations addressed in a timely manner, including the outcome of investigated matters
- Code of conduct exists with acknowledgement captured for employees only, leaving contractors with system access uncovered
- No evidence any deviation was ever identified, which auditors read as absence of monitoring rather than absence of issues
- Ethics hotline available but no record of how reports are triaged, by whom, or whether anonymity is preserved
- Consequences for deviation described in policy with no example of them being applied
The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control
- Board or equivalent governing body charter defining its oversight responsibilities over internal control
- Membership records evidencing independence from management, and the skills or expertise relevant to security and technology
- Minutes of board or committee meetings in the period showing internal control and security matters were presented and challenged
- Reporting pack provided to the board, including security metrics, risk reporting and incident summaries
- Evidence of board decisions or direction resulting from that oversight
- A board exists on paper for a smaller entity, with no meetings, no minutes and therefore no oversight to evidence
- Minutes recording that a security update was given, with no indication of what was said or what the board concluded
- Independence asserted while every member is an executive of the entity or its investor with a management role
- Security reporting reaching management only, never the governing body
Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives
- Organisational charts showing structures and reporting lines in the period, with evidence of board oversight of that structure
- Documented authorities and responsibilities, including delegation of authority limits and who may approve what
- Job descriptions for roles with internal control or security responsibility
- Evidence of review of the structure after change, such as reorganisation, acquisition or significant growth
- Evidence responsibilities for outsourced functions are defined and assigned to an internal owner
- Organisation chart current for the audit while the period contained an unrecorded restructure
- Delegation of authority undocumented, so approvals cannot be tested against a defined limit
- Outsourced functions treated as the vendor's responsibility with no named internal owner
- Security responsibility assigned to a role that has no authority over the systems concerned
Demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives
- Defined competence requirements for roles, particularly those with security and internal control responsibilities
- Recruitment records showing candidates were evaluated against those requirements, including background checks where performed
- Training and development records for the period, covering both general awareness and role specific competence
- Performance evaluation records addressing competence and development needs
- Succession or contingency planning for key roles, showing the entity considered loss of critical individuals
- Competence requirements exist for hiring and are never revisited as the role changes
- Training records show completion percentages with no evidence of what was covered or whether it was understood
- Background checks performed for employees and skipped for contractors doing identical work
- No succession consideration, so a single administrator holds knowledge nobody else has
Holds individuals accountable for their internal control responsibilities in the pursuit of objectives
- Evidence that internal control responsibilities are embedded in performance objectives or role expectations
- Performance evaluation records referencing those responsibilities for the period
- Evidence of incentive and reward structures being considered for the pressures they create
- Records of corrective or disciplinary action taken where responsibilities were not met
- Evidence accountability extends to service providers through contract terms and performance review
- Accountability stated in policy with no mechanism connecting it to any consequence
- Performance reviews conducted with no reference to security or control responsibilities at all
- Excessive pressure or incentive structures never evaluated, which is an explicit point of focus in the criterion
- No evidence of any corrective action, so accountability cannot be demonstrated as operating
Obtains or generates and uses relevant, quality information to support the functioning of internal control
- Identification of the information requirements supporting the functioning of internal control, such as security metrics, risk data and system inventories
- Evidence of the sources used, both internal and external, and of how data is captured and processed into usable information
- Evidence of the quality of that information, covering completeness, accuracy, timeliness and its retention
- Reporting produced during the period and evidence it was used in decisions
- Evidence of review where information quality was found deficient and corrected
- Reports produced from a manually maintained spreadsheet with no control over its completeness or accuracy
- Asset and system inventories used as the basis for other controls while nothing verifies they are complete
- Information generated and never used, so relevance to internal control cannot be shown
- Cost and quality of the information never balanced, producing volume that obscures the signal
Internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control
- Evidence of internal communication of objectives and of internal control responsibilities, such as policies, briefings and intranet content
- Evidence of communication between management and the board, and its frequency
- The separate communication channel allowing anonymous or confidential reporting when normal channels are inoperative, and evidence it works
- Records of communication with personnel about security responsibilities, incident reporting and changes to controls
- Evidence communication reaches contractors and temporary personnel on the same basis
- Policies published to a portal with no evidence anyone read or was directed to them
- No separate confidential channel, which is a specific point of focus and a common exception
- Communication one directional, with no evidence personnel can raise matters upward
- New joiners informed at induction with nothing reinforcing it during the period
Communicates with external parties regarding matters affecting the functioning of internal control
- Evidence of communication to customers and other external parties about the entity's commitments and system requirements, such as terms of service, service descriptions and the system description itself
- Records of communication with vendors and business partners regarding control responsibilities
- Evidence of the channel for external parties to report matters, including security issues, and records of its use
- Evidence of communication with regulators, shareholders and other relevant external parties as applicable
- Records of how external communications about incidents affecting external parties are handled and approved
- Commitments made in sales material and contracts that the operating controls were never designed to meet
- No external reporting channel for security issues, or one that routes to a sales mailbox
- Vendor communication limited to commercial matters with control responsibilities never stated
- Incident communication to customers handled ad hoc with no defined process or approval
Specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives
- Documented objectives relating to operations, reporting and compliance, specific enough that risks to them can be identified
- Evidence the objectives reflect the service commitments and system requirements made to customers
- Evidence of management approval of the objectives and of their review during the period
- Traceability from objectives to the risk assessment, showing risks are assessed against stated objectives
- Evidence materiality or tolerance levels were considered
- Objectives stated so broadly that any risk relates to them and none can be ruled out
- Service commitments in customer contracts never reflected in the internal objectives, so the risk assessment misses what the entity actually promised
- Objectives set once at the start of the programme and unchanged despite significant business change
- Risk assessment performed with no reference to objectives at all, which breaks the link this criterion requires
Identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed
- The risk assessment covering the entity, its subsidiaries, divisions and operating units, and relevant external factors
- The risk register with likelihood, impact, analysis and the determined response for each risk
- Evidence of the involvement of appropriate levels of management in the assessment
- Evidence of the frequency of assessment and of reassessment when conditions changed
- Evidence risk responses were implemented, with owners and completion status
- Risk register produced annually as a compliance artefact with no evidence it drove any decision
- Analysis reduced to a colour rating with no reasoning recorded behind likelihood or impact
- External factors, such as vendor concentration and regulatory change, absent from the assessment
- Responses recorded as accept for risks well outside any stated tolerance, with no approval at an appropriate level
Considers the potential for fraud in assessing risks to the achievement of objectives
- A fraud risk assessment considering fraudulent reporting, misappropriation of assets, corruption and management override of controls
- Analysis of incentives, pressures, opportunities and rationalisations relevant to the entity
- Evidence the assessment considers fraud involving technology, such as unauthorised access, data theft and misuse of privileged access
- Controls identified to address the fraud risks and evidence of their operation
- Evidence of who performed the assessment and of its review by management or the board
- Fraud risk omitted entirely from the risk assessment, which is one of the most common exceptions against this criterion
- Fraud considered as financial only, with no consideration of insider misuse of system access
- Management override acknowledged as a risk with no control addressing it
- Assessment performed once at implementation and never repeated as the business changed
Identifies and assesses changes that could significantly impact the system of internal control
- The process for identifying and assessing changes that could significantly affect internal control, covering the external environment, the business model, leadership and technology
- Records of changes identified in the period and the assessment of their impact on the control environment
- Evidence of reassessment of risks following those changes
- Evidence the process covers changes at vendors and business partners
- Records of controls added or amended as a result
- Change assessment limited to technical change management, missing business, leadership and regulatory change
- Significant changes such as an acquisition, a new product or a cloud migration occurring with no reassessment of risk
- Vendor changes, including a vendor changing subprocessor or location, never identified
- Process defined with no evidence it operated during a period in which the entity plainly changed
Selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning
- The plan for ongoing and separate evaluations, showing scope, type, frequency and who performs them
- Results of evaluations performed in the period, such as internal audit reports, control self assessments, vulnerability assessments and penetration tests
- Evidence evaluators are objective and knowledgeable, and independent of the activity evaluated
- Evidence a baseline understanding of the control system exists and is used to scope evaluations
- Evidence of the mix and rate of change, showing evaluations are adjusted as risk changes
- Only one annual assessment performed, with no ongoing evaluation between times
- Evaluations performed by the people who operate the controls, so objectivity fails
- Scope repeated year on year with no adjustment for change in the environment
- Penetration testing treated as the whole of the monitoring activity, leaving process controls unevaluated
Evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate
- The process for evaluating identified deficiencies, including how severity is determined
- The deficiency or findings log for the period, with owner, severity, target date and status
- Evidence of communication of deficiencies to the parties responsible for corrective action and, where appropriate, to senior management and the board
- Evidence of timeliness, showing the interval between identification and communication
- Evidence of remediation and of verification that the corrective action was effective
- Findings tracked in a spreadsheet with due dates long passed and no escalation
- Deficiencies reported to the team that owns them and never aggregated for senior management or the board
- Severity assigned informally, so a significant deficiency and a minor observation are treated the same
- Remediation marked complete on assertion with no verification
Selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels
- Evidence control activities were selected in response to identified risks, traceable from the risk register to specific controls
- The control matrix or equivalent, showing the mix of control types including preventive and detective and manual and automated
- Evidence of consideration of the relevant business processes and of the level at which each control applies
- Evidence of segregation of duties considered in control design, and compensating controls where segregation was not practicable
- Evidence controls were assigned owners responsible for their performance
- Controls listed with no traceability to any risk, so the entity cannot show they mitigate anything identified
- Detective controls absent, leaving no means to identify failure of the preventive ones
- Segregation of duties not considered in design, discovered only when the auditor tests it
- Controls owned by no one, so performance depends on habit
Also selects and develops general control activities over technology to support the achievement of objectives
- Evidence of general technology controls over infrastructure, security management and technology acquisition, development and maintenance
- Dependency analysis showing which business process controls rely on technology, and therefore on these general controls
- Evidence of controls over the technology infrastructure, such as change management, configuration and capacity
- Evidence of access security controls over the technology, restricting who can affect it
- Evidence of control over technology acquired from vendors, including cloud services
- General controls documented for on premises infrastructure while the cloud platform hosting the service is out of scope
- Dependency between automated business controls and the general controls never identified, so a general control failure invalidates untested reliance
- Controls over technology acquisition absent, so services enter production with no control assessment
- Segregation between development and production undocumented at the technology layer
Deploys control activities through policies that establish what is expected and in procedures that put policies into action
- Policies establishing what is expected and the procedures putting them into action, with owners and approval evidence
- Evidence responsibility and accountability for executing each procedure is established with competent personnel
- Evidence procedures are performed timely, with records showing when each was performed during the period
- Evidence corrective action is taken where a procedure identifies an issue
- Evidence policies and procedures are reassessed periodically and updated as needed
- Policy exists with no corresponding procedure, so nothing tells anyone how to perform the control
- Procedures performed irregularly with records showing large gaps in the period
- Procedures assigned to individuals who have left, so the control lapses silently
- Annual review evidenced by a version date change with no indication anything was reconsidered
Restricts logical access to protected information assets using access control software, supporting infrastructure and system architectures, covering inventory and classification of information assets, identification and authentication of users and system components before access, network segmentation, managed points of access for outside parties, controlled issue and removal of credentials, and encryption of data with protected keys, so that security events cannot reach those assets.
- Inventory of information assets with classification and owner
- Access control software configuration and the rule sets that enforce it
- Joiner, mover and leaver records showing credential issue and removal for people, infrastructure and software
- Network segmentation design with firewall or ACL rule review evidence
- Register of points of access used by outside entities and the data that flows through each
- Encryption standard covering data at rest and in transit, with key generation, storage, use and destruction records
- Physical access evidence offered against a criterion that is logical only, which belongs at CC6.4
- Asset inventory incomplete, so unmanaged systems sit outside the access control rule sets
- Service, machine and infrastructure accounts excluded from identification and authentication
- Encryption keys held by the same administrators the encryption is meant to constrain
- Credentials for decommissioned infrastructure and software never removed
Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by
- The registration and authorisation procedure that must complete before credentials are issued, for internal and external users
- Authorisation records for users provisioned in the period, showing the requester, the approver and the access requested
- Evidence credentials were issued only after authorisation, with dates supporting the sequence
- Evidence of removal of access when access is no longer authorised, with the interval between the trigger and the removal
- Evidence covering users whose access is administered by the entity on behalf of a customer, where that applies
- Access granted first and approved retrospectively, which reverses the order the criterion requires
- Approval by the requester's peer or by the person implementing the change, so no independent authorisation exists
- External and customer administered users provisioned through a different route with no equivalent authorisation record
- Removal triggered by a manual notification that is sometimes not sent, so leavers retain credentials
Authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation
- Role definitions showing the access attached to each role, and the basis in job responsibility
- Evidence of authorisation for access changes during the period, including modifications on role change
- Evidence prior access was removed on role change, not merely supplemented
- Access review evidence per system, showing the reviewer, the population reviewed and the revocations made and completed
- Evidence least privilege and segregation of duties were considered in the role design, with the conflict analysis
- Access accumulation across role changes, which is the most frequently observed failure of this criterion
- Reviews certified in bulk with no revocations, indicating the review was not performed with real scrutiny
- Revocations identified in a review and never actioned, with no tracking to closure
- Roles defined so broadly that least privilege cannot be demonstrated for any individual
Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
- List of facilities and protected information assets in scope, including data centre space, back-up media storage and other sensitive locations
- Authorisation records showing who is permitted physical access to each location and on what basis
- Access control system configuration and badge listings for those locations, reconciled against the authorisation records
- Records of periodic review of physical access rights and of removals made as a result
- Visitor and third party access records for the same locations, including escort evidence
- Primary data centre well controlled while back-up media storage and offsite locations rely on a provider attestation with no entity level review
- Physical access rights reviewed less often than logical access, so leavers keep badge access after their accounts are disabled
- Sensitive locations such as network rooms and media handling areas omitted from the scope list entirely
Discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's
- Documented procedure defining when protections may be discontinued and what sanitisation must precede it
- Sanitisation or destruction records for each asset released, naming the method used and the operator
- Verification evidence that the ability to read or recover data and software has been diminished, such as verification passes or destruction certificates
- Asset register entries showing the transition from in use to sanitised to released, with dates
- Evidence the requirement for the asset was formally determined to have ended before protections were removed
- Assets released to disposal or resale with protections removed before sanitisation is confirmed, reversing the required order
- Certificates of destruction accepted from a vendor with no serial level reconciliation against the assets sent
- Encrypted media treated as sanitised by key destruction with no record of where else that key was held
Implements logical access security measures to protect against threats from sources outside its system boundaries
- Identification of the system boundaries and of the points at which external access is possible
- Configuration of boundary protections, such as firewalls, intrusion prevention, denial of service protection and web application firewalls
- Evidence of controls over remote access, including multi factor authentication and restriction of the routes available
- Evidence of encryption or other protection of credentials and data crossing the boundary
- Evidence of monitoring for and response to external attack attempts
- Multi factor authentication enforced on the main access route while legacy access paths and application programming interfaces bypass it
- Boundary defined by network only, missing identity based access from anywhere as the actual boundary
- Rules permitting broad external access retained from an earlier configuration with no review
- Attack attempts logged with no monitoring and no response defined
Restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives
- Restrictions on transmission, movement and removal of information, showing which users and processes are authorised
- Configuration evidence of protection during transmission, such as enforced transport encryption and secure file transfer
- Controls over removable media and other portable devices, including restriction, encryption and logging
- Evidence covering movement to third parties and to personal accounts or devices
- Records of monitoring or detection of unauthorised movement of information
- Transmission protected on the primary channel while batch feeds, integrations and support extracts move data unprotected
- Removable media addressed by policy alone with no technical restriction or detection
- Personal cloud storage and personal email as an exfiltration route neither blocked nor monitored
- Encryption in transit claimed from the provider with no verification of the negotiated protocol and cipher
Implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives
- Controls preventing or detecting introduction of unauthorised or malicious software, covering endpoints, servers and, where relevant, the build pipeline
- Coverage reporting for protective software, showing devices covered, devices not covered and definition currency
- Evidence of restriction on installation of unauthorised software, such as removal of administrative rights or application allow listing
- Detection records for the period and evidence of the action taken
- Evidence of controls over software introduced through the supply chain, including third party components
- Coverage measured only across devices reporting in, hiding the devices that stopped reporting
- Detection alerts closed automatically with no analysis of repeated infection on the same host
- Users retaining local administrator rights, which nullifies restriction on installation
- Build and deployment pipelines outside the scope, though they are the most efficient route to introduce malicious code
To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities
- Defined configuration standards or baselines and evidence of monitoring for changes that introduce new vulnerabilities
- Vulnerability scanning results for the period, including scope, frequency and whether scanning is authenticated
- Evidence of monitoring for newly discovered vulnerabilities affecting the technologies in use
- Records of deviations detected, the assessment of them and the remediation taken
- Evidence the monitoring covers infrastructure, applications and cloud configuration
- Configuration monitored at build only, so drift introduced afterwards is never detected
- Scanning performed quarterly against an environment that changes daily
- Newly published vulnerabilities tracked for operating systems while application and library exposure is unmonitored
- Detected deviations recorded with no remediation timeline and no follow up
Monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine
- The monitoring design for system components and their operation, showing what constitutes anomalous behaviour
- Detection rules or analytics deployed, and evidence of the tuning applied over time
- Evidence of the sources monitored, covering infrastructure, applications, identity and, where applicable, physical and environmental conditions
- Records of anomalies detected during the period and of the analysis performed to determine whether they represent a security event
- Evidence of the coverage of the monitoring against the components in the system description
- Logs collected without any detection logic applied, so anomalies are only visible in hindsight
- Monitoring covers malicious acts and omits natural disaster and error, both of which the criterion names
- Alert volume exceeding triage capacity, so alerts are closed without analysis
- Components in the system description with no monitoring coverage at all
Evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures
- The criteria for evaluating whether a security event could result or has resulted in a failure to meet objectives
- Records of events evaluated during the period, including those determined not to be incidents, with the reasoning
- Evidence of who performs the evaluation and their authority to declare an incident
- Evidence of the actions taken to prevent or address a failure, following the determination
- Evidence of communication of the determination to those who need to act on it
- Only declared incidents are documented, so the evaluation step itself leaves no evidence and cannot be tested
- Evaluation criteria informal, producing inconsistent determinations between shifts and individuals
- Determination made without reference to the entity's service commitments, so customer impacting events are judged internally trivial
- No record of the actions taken following the determination
Executes a defined incident response program once a security incident is identified, with roles and responsibilities assigned, the nature and severity of the incident understood, the active threat contained and mitigated, the underlying vulnerability remediated, operations restored to a state that meets objectives, and the incident and the actions taken communicated to affected parties, with the effectiveness of the response evaluated periodically.
- Incident response program naming roles, escalation paths and the use of external resources
- Incident tickets carrying detection, containment, eradication and recovery timestamps
- Severity assessment and containment strategy record for individual incidents
- Remediation records tying each incident to closure of the underlying vulnerability
- Records of communication to affected parties and, where privacy is in scope, to data subjects and regulators
- Periodic evaluation or exercise of the response program with resulting changes
- A response plan exists but no incident record shows it was followed
- Containment recorded while the vulnerability that allowed the incident stays open
- No evidence that affected parties were told anything
- Effectiveness never evaluated, so the same root cause recurs across periods
- Roles named in the plan no longer match the people who actually respond
Identifies, develops, and implements activities to recover from identified security incidents
- Recovery procedures for identified security incidents, and evidence they were applied to incidents in the period
- Root cause analysis records, distinguishing the immediate technical cause from the control failure that allowed it
- Records of the restoration of operations, including verification the system was returned to a known good state
- Evidence of improvements implemented as a result, with owners and completion
- Evidence of testing or exercising of incident recovery, and lessons taken from it
- Recovery recorded as service restored with no verification the cause was removed, so the incident recurs
- Root cause recorded as human error, which stops the analysis before it reaches the control weakness
- Improvement actions raised and left open, with no tracking to closure
- Recovery procedures never exercised, so their first use is under real pressure
Authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives
- The change management process covering infrastructure, data, software and procedures, including the emergency change route
- Change records for the period showing design, development or acquisition, configuration, documentation, testing, approval and implementation
- Evidence of segregation between those who develop, approve and implement changes
- Testing evidence per change proportionate to its risk, including security testing where relevant
- Evidence of rollback capability and of post implementation verification
- Emergency changes used routinely, with retrospective approval that is never withheld
- Approval and implementation performed by the same person, so the approval is not independent
- Automated deployment pipelines outside the documented process, so most changes are untested against it
- Infrastructure and configuration change treated as out of scope because the process was written for application code
Identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions
- Identification of risks arising from potential business disruption, and the mitigation activities selected for each
- Business continuity and disaster recovery plans, with recovery objectives derived from a business impact analysis
- Evidence of testing of those plans in the period, with results measured against the objectives
- Evidence of insurance or other risk transfer where used as part of the mitigation
- Evidence the plans are maintained and updated after significant change
- Recovery objectives set by technology teams with no business impact analysis behind them
- Plans tested as a tabletop walkthrough only, which never proves the objective is achievable
- Dependencies on cloud providers and other third parties excluded from the plan and the test
- Plans unchanged after major infrastructure change, describing an environment that no longer exists
Assesses and manages risks associated with vendors and business partners
- The vendor and business partner inventory, with risk tiering based on data access and criticality
- Due diligence records performed before engagement, at the depth the tier requires
- Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess
- Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them
- Evidence of termination handling, including return or deletion of data and revocation of access
- Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs
- Inventory covering vendors known to procurement, missing services engaged directly by teams
- Due diligence performed at onboarding with no reassessment during a multi year relationship
- Subservice organisations engaged by the vendor never identified, so risk stops at the first tier
P - Privacy
Provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the
- The privacy notice as published, covering the purposes for collection, use, retention and disclosure of personal information
- Evidence the notice is provided at or before the point of collection, and evidence of the mechanism used
- Version history of the notice with the dates of change, and evidence changes were communicated to data subjects in a timely manner
- Evidence the notice is written in plain and conspicuous language, and evidence of the review that concluded so
- Reconciliation between the practices described in the notice and the processing actually performed
- Notice describes practices the entity no longer follows, or omits processing it has since started, so the notice and the reality diverge
- Changes to the notice published silently with no communication to existing data subjects
- Notice provided after collection, or buried where it is not conspicuous at the point of collection
- No evidence of the review confirming the notice matches actual processing, which is the substantive test
Communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use, retention, disclosure,
- Documentation of the choices communicated to data subjects regarding collection, use, retention, disclosure and disposal, and the consequences of each choice
- Evidence consent is obtained where required, with the record of consent including its date, scope and the version of the notice in force
- Evidence of the mechanism by which a data subject exercises or changes a choice, and records of choices exercised in the period
- Evidence consent records are used to drive actual processing, such as suppression or restriction applied downstream
- Evidence of the treatment of withdrawal of consent, including its propagation to third parties
- Consent captured at the point of collection and never linked to the systems that process the data, so a withdrawal changes nothing
- Consequences of declining a choice not communicated, which the criterion explicitly requires
- Consent recorded without the version of the notice it was given against, so the scope of what was agreed cannot be established
- Withdrawal handled in the primary system while third parties who received the data are never told
Limits collection of personal information to what the entity's stated privacy purposes require, obtains it by means reviewed by management as fair and lawful before they are used, confirms that third party sources of personal information themselves collect it fairly and lawfully, and informs data subjects when the entity develops or acquires additional information about them.
- Record of processing showing each purpose and the data elements collected for it
- Management review and approval of collection methods before they go live
- Due diligence records for third party and broker sources of personal information
- Notices issued to data subjects when the entity derives or acquires further information about them
- Data minimisation review of forms, trackers, integrations and log capture
- Collection scoped to what the system can capture rather than what the purpose needs
- Collection methods deployed with no documented fairness and lawfulness review
- Enrichment or broker data ingested with no check that the source collected it lawfully
- Derived and inferred attributes never disclosed to the data subject
- Legacy fields still collected after the purpose that justified them ended
For information requiring explicit consent, the entity communicates the need for such consent, as well as the consequences of a failure to provide consent for the request for personal information, and obtains the consent
- Identification of the personal information the entity holds that requires explicit consent, and the basis for that determination
- Evidence of the communication explaining the need for explicit consent and the consequences of failing to provide it
- Records of explicit consent obtained, distinguishable from general consent, with date, scope and method
- Evidence of how processing is prevented where explicit consent was not obtained
- Evidence of review where the categories of information collected changed
- Sensitive categories never identified, so explicit consent is never sought for information that requires it
- Explicit consent bundled into a general acceptance, so it is neither explicit nor separable
- Consequences of refusal not communicated, leaving the choice uninformed
- No enforcement, so processing continues for individuals who did not give explicit consent
Limits the use of personal information to the purposes identified in the entity's objectives related to privacy. The following point of focus, which applies only to an engagement using the trust services criteria for
- The record of purposes for which personal information may be used, tied to the privacy notice and to the consent obtained
- Evidence of controls limiting use to those purposes, such as access restriction by purpose, system configuration or approval for new uses
- Records of requests for new or secondary uses and the assessment and approval of them
- Evidence of review of actual use against the stated purposes, sampled across systems and teams
- Evidence covering use by third parties acting on the entity's behalf
- New uses adopted by product or analytics teams with no assessment against the stated purposes
- Use limitation stated in policy with no technical or procedural control preventing anything
- Personal information copied into analytics and machine learning environments where purpose is no longer tracked
- Third party use unconstrained beyond a general confidentiality clause
Retains personal information consistent with the entity's objectives related to privacy
- The retention schedule for personal information, with the period per data type and its legal or business basis
- Evidence of enforcement, such as automated deletion jobs, purge reports or records of manual disposal
- Evidence retention covers all copies, including backups, archives, replicas, exports and third party held data
- Records of legal holds or other justified exceptions, with approval and expiry
- Evidence of monitoring showing personal information beyond its retention period is identified and removed
- Retention schedule documented with no enforcement anywhere, so nothing is deleted
- Deletion performed in the production database while backups, data warehouses and exports retain the data
- Legal holds applied and never released, becoming permanent retention by default
- No monitoring, so overdue data is only discovered during an audit or an incident
Securely disposes of personal information to meet the entity's objectives related to privacy
- The disposal procedure for personal information, defining the method per medium and per system
- Disposal records for the period, showing what was disposed of, when, by what method and by whom
- Evidence of verification that the information is no longer recoverable, including certificates where a third party performed the destruction
- Evidence disposal extends to physical records and media as well as electronic data
- Evidence of the handling of data held by third parties on disposal, including confirmation of deletion
- Deletion recorded as a status flag with the underlying data retained and recoverable
- Third party deletion requested with no confirmation received or sought
- Physical records of personal information disposed of by ordinary waste rather than by secure destruction
- No verification step, so a failed disposal job is indistinguishable from a successful one
Grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity's
- The process for receiving and responding to data subject access requests, including timescales
- Evidence of identification and authentication of the data subject before information is released
- Records of requests received in the period, with the date received, the date responded and the content provided
- Evidence the response covers all systems holding the individual's personal information, not only the primary one
- Evidence of the handling of requests that are denied, including the reason and its communication to the data subject
- Search performed manually and dependent on who searches, so completeness cannot be demonstrated
- Identity verification weak or absent, which turns the access right into a disclosure vulnerability
- Requests handled outside any tracked process, so timeliness cannot be evidenced
- Denials issued with no recorded basis and no communication of the reason
Corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity's objectives related to privacy. If a
- The process for correcting, amending or appending personal information on the basis of information provided by data subjects
- Records of correction requests in the period, with the outcome and the date completed
- Evidence corrections are propagated to third parties who received the information, as committed or required
- Evidence of the handling of a denied correction request, including the reason and its communication to the data subject
- Evidence corrections reach every system holding the data, not only the system of record
- Corrections applied in one system while downstream copies and third parties retain the previous value
- No process for denial, so a contested correction simply goes unanswered
- Propagation to third parties committed in the notice and never performed
- Correction records not retained, so the entity cannot show the request was handled
Discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity's objectives related to privacy
- The inventory of third parties to whom personal information is disclosed, and the purpose of each disclosure
- Evidence of the consent obtained before disclosure, with its date preceding the disclosure
- Evidence of the mechanism preventing disclosure where consent was not given or was withdrawn
- Contractual terms with each recipient governing their use of the information
- Records of disclosures made in the period, reconciled to the consent held
- Consent obtained generally at signup and treated as covering disclosures introduced afterwards
- Disclosures through integrations, tags and analytics services never recognised as disclosures at all
- No mechanism enforcing consent, so a withdrawal does not stop the data flow
- Reconciliation between actual disclosures and consent never performed
Creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity's objectives related to privacy. The following point of focus, which applies only to an engagement
- The register of authorised disclosures of personal information, showing recipient, information disclosed, purpose and date
- Evidence the register is complete, covering automated and system to system disclosures as well as manual ones
- Evidence entries are created at the time of disclosure rather than reconstructed later
- Reconciliation of the register against other sources, such as integration configuration and vendor inventories
- Evidence of retention of the records for the required period
- Register captures manual disclosures while continuous automated flows to third parties are never recorded
- Entries reconstructed at audit time, which fails the timeliness the criterion requires
- No reconciliation, so a disclosure route introduced by an engineering change never enters the register
- Register held by one team with no view of disclosures made by other parts of the business
Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which
- The register of detected or reported unauthorised disclosures of personal information, including breaches
- Evidence each entry is complete, accurate and timely, showing detection date, disclosure date and the information involved
- Intake routes feeding the register, covering internal detection, individual reports and third party notification
- Reconciliation between the register and other sources such as help desk tickets and vendor notifications
- Retention evidence showing the records are kept for the defined period
- Only incidents that reached formal breach assessment recorded, so smaller detected disclosures never enter the register
- Entries created at closure rather than detection, which loses the timeliness the criterion requires
- Disclosures reported by vendors or by the affected individual never captured because the register is fed only by internal monitoring
Obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed
- Inventory of vendors and other third parties with access to personal information
- Signed privacy commitments for each, such as contract clauses, data processing terms or a data protection agreement
- Records of the periodic assessment of those parties' compliance, with the assessment method used
- Records of as-needed assessments triggered by an event, such as a change in processing or an incident
- Findings from assessments and evidence of remediation or escalation
- Commitments obtained from contracted vendors while sub-processors they engage carry no equivalent commitment
- Assessment consists of collecting a report at onboarding, with no periodic re-assessment as the criterion requires
- Assessment findings recorded with no follow-up, so a non-compliant processor keeps access
Obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to
- Contractual commitments from vendors and third parties requiring notification of actual or suspected unauthorised disclosure
- Evidence of the notification channel and the timeframe committed to
- Records of notifications actually received during the period and the date each arrived
- Evidence received notifications are reported to the personnel responsible for privacy incident handling
- Escalation evidence where a third party notified late or not at all
- Notification clause requires disclosure without a timeframe, so late notification breaches nothing
- Notifications arrive to a commercial or account contact and never reach privacy or incident response
- Suspected disclosure excluded from the clause, so a third party waits until an event is confirmed before telling anyone
Provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy
- Documented breach notification procedure identifying the recipients, being affected data subjects, regulators and others, and the trigger and timeframe for each
- Notification records for the period, showing what was sent, to whom and when
- Templates or sample notifications showing the content provided to data subjects
- Assessment records determining whether notification was required for each incident, including where it was assessed as not required
- Evidence of the legal or regulatory analysis underpinning the notification decision
- Procedure covers regulator notification while notification to affected data subjects is undefined
- Decisions not to notify recorded as a conclusion with no supporting assessment, leaving the judgement unauditable
- Contact information for affected individuals unavailable or stale, so notification cannot be executed within the timeframe
Provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy
- The process for receiving and responding to data subject requests for an accounting of personal information held and of disclosures made
- The underlying record of disclosures that the accounting is produced from, maintained as disclosures occur
- Sample accountings provided to data subjects during the period, with the request and response dates
- Identity verification evidence performed before the accounting was released
- Evidence the accounting covers all systems holding the individual's personal information, not only the primary one
- Accounting assembled by manual search at request time, so completeness depends on who searches and what they remember
- Disclosures to service providers and internal transfers omitted, leaving the accounting materially incomplete
- No identity verification before release, so the response itself becomes an unauthorised disclosure
Collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy
- Evidence of the controls maintaining accuracy, currency, completeness and relevance of personal information
- Validation controls at the point of collection, and evidence of their operation
- Processes for periodic review or refresh of personal information, particularly where it is used for decisions about individuals
- Evidence of the handling of information identified as inaccurate, including its correction and any notification
- Evidence of minimisation, showing information collected and retained is relevant to the stated purpose
- Accuracy assumed from the data subject having supplied the information originally, with no refresh over years
- Relevance never assessed, so fields collected for a purpose that has ended are still populated and retained
- Derived and inferred attributes treated as outside data quality controls even though decisions are made from them
- Inaccuracies corrected locally with no notification to those who relied on the previous value
Implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity's objectives related to privacy. Corrections
- The documented process for receiving, addressing, resolving and communicating the resolution of inquiries, complaints and disputes
- The complaints register for the period, with the date received, nature, resolution and date communicated
- Evidence the channel is communicated to data subjects and is accessible
- Evidence of periodic monitoring of compliance with privacy commitments and requirements, and of the corrections made as a result
- Evidence of escalation and of root cause action where complaints indicate a systemic issue
- Complaints handled through general customer support with no privacy specific process, so none are identifiable as privacy matters
- Register showing no complaints at all, which auditors read as a broken intake rather than perfect performance
- Resolution reached with no evidence it was communicated back to the data subject
- Periodic compliance monitoring, which the criterion explicitly requires, never performed
PI - Processing Integrity
Obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services
- Documented definitions of the data processed and the product and service specifications, and evidence they are current
- Evidence these definitions are communicated to the users of the products and services, such as documentation, interface specifications and service descriptions
- Evidence of the quality of the information used to support processing, including its source, accuracy and timeliness
- Records showing the specifications are used as the basis for the processing controls that follow
- Evidence of update to specifications and their communication when processing changes
- Specifications held informally by the engineering team and never communicated to the users who rely on them
- Definitions out of date against the processing actually performed, so every downstream completeness and accuracy control tests the wrong thing
- No traceability from the specification to the input, processing and output controls
- Changes to processing made with the documentation left describing the previous behaviour
Implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives
- Documented policies and procedures over system inputs, including validation, edit checks and authorisation of inputs
- Evidence of the controls in operation, such as validation rule configuration, rejection reports and reconciliation of input counts and values
- Records of the handling of rejected or exception items, showing they are corrected and resubmitted rather than lost
- Evidence controls cover all input routes, including manual entry, file and batch feeds and application programming interfaces
- Evidence of monitoring of input timeliness against the specification
- Validation implemented in the user interface while the application programming interface and batch routes accept the same data unvalidated
- Rejected items written to an error queue that nobody monitors, so they are silently dropped
- Input completeness assumed from the absence of errors with no reconciliation of counts or totals to the source
- Timeliness of input not measured, though the criterion requires it
Implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives
- Policies and procedures over system processing, and evidence of the controls implementing them
- Evidence processing is complete, valid, accurate, timely and authorised, such as reconciliations, control totals, exception reports and processing logs
- Records of processing exceptions and errors, with their investigation and correction
- Evidence of authorisation controls over processing, including who may initiate, override or reprocess
- Evidence of monitoring of processing against the defined specifications and service commitments
- Reconciliation performed at a summary level that would not detect an offsetting error
- Manual overrides and reprocessing permitted with no authorisation record or subsequent review
- Exception reports produced and reviewed by the same person who performs the processing
- Timeliness of processing not measured against any stated commitment
Implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives
- Policies and procedures governing the creation, availability and delivery of outputs, including who is authorised to receive each output
- Evidence outputs are complete and accurate, such as reconciliation of output to input and to processing records
- Evidence of timeliness of delivery against the specification or service commitment
- Evidence of controls over distribution, ensuring outputs reach only authorised recipients and are protected in transit
- Records of output errors or failed deliveries and their resolution
- Delivery confirmed as sent with no confirmation it was received or usable
- Output completeness never reconciled back to the input, so a partial output looks successful
- Distribution lists maintained informally, so outputs continue to reach people who should no longer receive them
- Failed deliveries retried automatically with no alert, so persistent failure goes unnoticed
Implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives
- Policies and procedures over the storage of inputs, items in processing and outputs, in accordance with the system specifications
- Evidence of completeness and accuracy of stored data, such as integrity checks, checksums or reconciliation between stored and source data
- Evidence of protection of stored data against alteration, loss and unauthorised change, including access controls and audit trails
- Evidence of retention and archival of stored items in line with the specification and any commitment
- Evidence of backup and recovery of stored items and of verification of their integrity on restore
- Integrity of stored data assumed from the storage platform with no independent check
- Items in processing held in transient stores with no protection or recovery capability, so a failure mid process loses them
- Retention applied to outputs while inputs and intermediate items are kept indefinitely or discarded arbitrarily
- Restore tested for availability with no verification that the restored data is complete and accurate
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SOC 2 framework page.