Skip to content

Evidence request lists

SSAE 18 - Attestation Standards (SOC Reporting)

Evidence request list. 67 controls, 67 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

AUP

SSAE-04
Agreed-Upon Procedures (AT-C 215)

AUP engagements involve performing specific procedures and reporting findings without providing an opinion or conclusion, with intended users acknowledging procedures are sufficient for their purposes.

Artefacts an auditor will ask for
  • Engagement letter with specific procedures listed
  • Acknowledgement from intended users of procedure sufficiency
  • Findings report listing each procedure and result
  • No expression of opinion or conclusion in report
Where this commonly fails
  • User acknowledgement missing from file
  • Report inadvertently expresses conclusion
  • Procedures vague rather than specific

Acceptance

SSAE-08
Preconditions for Attestation Engagement

The practitioner must establish preconditions including suitable and available criteria, sufficient evidence access, and responsible party willingness to provide written representations.

Artefacts an auditor will ask for
  • Pre-engagement evaluation memo documenting preconditions
  • Criteria suitability assessment
  • Confirmation of evidence access and management cooperation
  • Written agreement on terms of engagement
Where this commonly fails
  • Preconditions evaluation not documented
  • Criteria not measurable or relevant
  • Engagement accepted despite scope limitations

Documentation

SSAE-17
Engagement Documentation

Documentation must be sufficient to enable an experienced practitioner with no previous connection to the engagement to understand the work performed, evidence obtained, and conclusions reached.

Artefacts an auditor will ask for
  • Work papers with preparer, reviewer, and date stamps
  • Index linking work papers to report assertions
  • Final file assembly within 60 days of report release
  • Retention for minimum five years
Where this commonly fails
  • Work papers missing reviewer sign-off
  • Cross-references broken or missing
  • Late additions to file after lockdown

Ethics

SSAE-09
Independence and Ethics

The practitioner must be independent of the responsible party and comply with the AICPA Code of Professional Conduct throughout the engagement period.

Artefacts an auditor will ask for
  • Independence confirmations from all engagement team members
  • Threats and safeguards analysis where non-attest services exist
  • Ethics training records for engagement team
  • Monitoring of independence during engagement period
Where this commonly fails
  • Independence assessed only at acceptance not ongoing
  • Non-attest services not analysed for self-review threat
  • Family member relationships not declared

Evidence

SSAE-12
Written Representations

The practitioner must obtain written representations from the responsible party regarding responsibility for the subject matter, completeness of information provided, and other relevant assertions.

Artefacts an auditor will ask for
  • Signed representation letter dated as of report date
  • Representations covering responsibility, completeness, disclosure
  • Subsequent events representations included
  • Refusal to provide representations escalated
Where this commonly fails
  • Representations dated significantly before report
  • Missing representations for specific risk areas
  • Letter signed by inappropriate party

Examination

SSAE-02
Examination Engagements (AT-C 205)

Examination engagements provide a high level of assurance and require obtaining sufficient appropriate evidence to reduce attestation risk to an acceptably low level, expressed as an opinion.

Artefacts an auditor will ask for
  • Engagement plan documenting risk assessment and procedures
  • Sufficient appropriate evidence to support positive opinion
  • Work papers showing nature, timing, and extent of procedures
  • Opinion letter in form prescribed by AT-C 205
Where this commonly fails
  • Procedures designed without documented risk assessment
  • Evidence insufficient for reasonable assurance level
  • Opinion form not aligned with AT-C 205 illustrations

General Standards

SSAE-01
Common Attestation Concepts (AT-C 105)

SSAE 18 reorganises attestation standards into a common concepts section (AT-C 105) that applies to all attestation engagements, including examination, review, and agreed-upon procedures.

Artefacts an auditor will ask for
  • Firm methodology referencing AT-C 105 common concepts
  • Engagement templates aligned to clarified standards
  • Staff training records on SSAE 18 changes from SSAE 16
  • Quality manual addressing all attestation service types
Where this commonly fails
  • Methodology still references SSAE 16 or SAS 70
  • Templates not updated for clarified standards
  • Training not refreshed for new staff

Planning

SSAE-10
Engagement Risk Assessment

The practitioner must obtain an understanding of the subject matter and assess risks of material misstatement to design responsive procedures.

Artefacts an auditor will ask for
  • Subject matter understanding memo
  • Risk assessment linking risks to assertions
  • Planning analytics where applicable
  • Procedures designed responsive to assessed risks
Where this commonly fails
  • Risk assessment is generic template
  • No linkage from risks to specific procedures
  • Subject matter understanding shallow
SSAE-11
Materiality in Attestation

The practitioner must consider materiality when planning procedures and evaluating findings, recognising that materiality in attestation may be qualitative as well as quantitative.

Artefacts an auditor will ask for
  • Materiality determination memo
  • Quantitative and qualitative factors considered
  • Reassessment during the engagement when conditions change
  • Documentation of materiality applied to findings evaluation
Where this commonly fails
  • Materiality not documented for non-financial subject matter
  • Qualitative factors ignored
  • No reassessment despite changes

Quality

SSAE-18
Quality Management at Firm and Engagement Level

Firms must implement a system of quality management with engagement-level controls including engagement quality reviews for high-risk engagements such as SOC reports.

Artefacts an auditor will ask for
  • Firm QM 1 system documentation
  • Risk assessment of attestation services for EQR triggers
  • EQR documentation completed before report release
  • Annual internal monitoring inspections
Where this commonly fails
  • EQR not performed for SOC engagements
  • QM system not updated for new standards
  • Monitoring inspections deferred

Reporting

SSAE-13
Other Information in Reports

When other information accompanies the subject matter information, the practitioner must read it for material inconsistencies with the attestation subject matter and respond appropriately.

Artefacts an auditor will ask for
  • Documentation of reading other information
  • Discussion of inconsistencies with management
  • Disclaimer or other-information paragraph where required
  • Section V management responses reviewed
Where this commonly fails
  • Section V responses not read
  • Inconsistencies not raised with management
  • No disclaimer paragraph despite extensive other information
SSAE-19
Modifications to the Standard Report

When circumstances warrant, the practitioner must modify the standard report through qualification, adverse opinion, or disclaimer, with reasons clearly described.

Artefacts an auditor will ask for
  • Memo documenting circumstances requiring modification
  • Modification language consistent with AICPA illustrations
  • Basis for modification paragraph with specifics
  • Engagement quality review of modification
Where this commonly fails
  • Qualification language vague
  • Pervasive issues qualified rather than adverse
  • Disclaimer used to avoid difficult conclusions
SSAE-20
Use by Specified Parties and Restricted Distribution

Reports on subject matter intended for specified parties must include a restricted use paragraph identifying intended users and prohibiting general distribution.

Artefacts an auditor will ask for
  • Restricted use paragraph in report
  • Identification of intended parties in engagement letter
  • Service organisation distribution controls
  • Process for handling requests from non-specified parties
Where this commonly fails
  • Restricted use paragraph omitted from SOC 1 or SOC 2
  • Intended users not identified
  • Distribution controls weak at service organisation

Review

SSAE-03
Review Engagements (AT-C 210)

Review engagements provide limited assurance through inquiry and analytical procedures, expressed as a conclusion about whether anything has come to attention that the subject matter is materially misstated.

Artefacts an auditor will ask for
  • Review program emphasising inquiry and analytical procedures
  • Documentation of unexpected results investigation
  • Limited assurance conclusion in report
  • Engagement letter specifying review service
Where this commonly fails
  • Review conducted as if examination without scope clarity
  • Analytical procedures not documented
  • Conclusion phrased as opinion rather than limited assurance

SOC 1

SSAE-05
SOC 1 Engagements (AT-C 320)

AT-C 320 governs SOC 1 engagements over controls at a service organisation relevant to user entity ICFR, requiring written assertion, system description, and (for Type 2) operating effectiveness testing.

Artefacts an auditor will ask for
  • AT-C 320 engagement letter and management assertion
  • Description meeting DC section 200 criteria
  • Tests of design and (for Type 2) operating effectiveness
  • Report following AICPA SOC 1 illustrative format
Where this commonly fails
  • Engagement performed under outdated SSAE 16 references
  • Description omits required components
  • Reports labelled SOC 1 when subject matter is non-ICFR

SOC 1 - Internal Controls over Financial Reporting

SSAE18-SOC1-01
Control Environment

The service organization demonstrates a commitment to integrity and ethical values. Management establishes structure, authority, and responsibility, and attracts, develops, and retains competent individuals.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified
SSAE18-SOC1-02
Risk Assessment

The service organization identifies risks to the achievement of its objectives and analyzes risks as a basis for determining how the risks should be managed.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified
SSAE18-SOC1-03
Information and Communication

The service organization generates and uses relevant, quality information to support the functioning of internal control. Communication provides the information necessary to carry out responsibilities.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified
SSAE18-SOC1-04
Monitoring Activities

The service organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified
SSAE18-SOC1-05
Control Activities for Financial Processing

The service organization selects and develops control activities that contribute to the mitigation of risks to the achievement of financial reporting objectives.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified
SSAE18-SOC1-06
Transaction Processing Controls

Controls over the completeness, accuracy, timeliness, and authorization of transaction processing on behalf of user entities.

Artefacts an auditor will ask for
  • System description
  • Control matrix
  • Evidence library
  • Auditor report
Where this commonly fails
  • Description thin
  • Matrix incomplete
  • Evidence stale
  • Opinion qualified

SOC 2

SSAE-06
SOC 2 Engagements (AT-C 205 with TSC)

SOC 2 engagements apply AT-C 205 examination standards to controls relevant to the Trust Services Criteria covering security, availability, processing integrity, confidentiality, and privacy.

Artefacts an auditor will ask for
  • Selection of trust services categories with rationale
  • Mapping of controls to applicable TSC points of focus
  • Description meeting DC section 200 criteria for SOC 2
  • Examination report following AICPA SOC 2 illustrative format
Where this commonly fails
  • Only security selected when availability is also implied
  • Points of focus not addressed in description
  • SOC 2 used for ICFR purposes (should be SOC 1)

SOC 2 - Additional Trust Services Categories

SSAE18-A1.1
A1.1 - Availability Commitments and Requirements

The entity maintains, monitors, and evaluates current processing capacity and use of system components to manage capacity demand and enable implementation of additional capacity.

Artefacts an auditor will ask for
  • Availability commitments register
  • Environmental and backup control records
  • Recovery plan exercise reports
  • Capacity planning records
Where this commonly fails
  • Commitments unwritten
  • Restore tests skipped
  • RTO unmet
  • Capacity reactive
SSAE18-A1.2
A1.2 - Environmental Protections and Recovery

The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data backup processes, and recovery infrastructure.

Artefacts an auditor will ask for
  • Availability commitments register
  • Environmental and backup control records
  • Recovery plan exercise reports
  • Capacity planning records
Where this commonly fails
  • Commitments unwritten
  • Restore tests skipped
  • RTO unmet
  • Capacity reactive
SSAE18-A1.3
A1.3 - Recovery Plan Testing

The entity tests recovery plan procedures supporting system recovery to meet its objectives.

Artefacts an auditor will ask for
  • Availability commitments register
  • Environmental and backup control records
  • Recovery plan exercise reports
  • Capacity planning records
Where this commonly fails
  • Commitments unwritten
  • Restore tests skipped
  • RTO unmet
  • Capacity reactive
SSAE18-C1.1
C1.1 - Confidential Information Identification

The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.

Artefacts an auditor will ask for
  • Confidential information inventory
  • Encryption and access control records
  • Disposal certificates
  • Contractual confidentiality terms
Where this commonly fails
  • Inventory thin
  • Encryption gaps
  • Disposal undocumented
  • Contracts stale
SSAE18-C1.2
C1.2 - Confidential Information Disposal

The entity disposes of confidential information to meet the entity's objectives related to confidentiality.

Artefacts an auditor will ask for
  • Confidential information inventory
  • Encryption and access control records
  • Disposal certificates
  • Contractual confidentiality terms
Where this commonly fails
  • Inventory thin
  • Encryption gaps
  • Disposal undocumented
  • Contracts stale
SSAE18-P1.1
P1.1 - Privacy Notice

The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy.

Artefacts an auditor will ask for
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
Where this commonly fails
  • Notice outdated
  • Consent not granular
  • Requests aging
  • Inventory incomplete
SSAE18-P1.2
P1.2 - Choice and Consent

The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to data subjects.

Artefacts an auditor will ask for
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
Where this commonly fails
  • Notice outdated
  • Consent not granular
  • Requests aging
  • Inventory incomplete
SSAE18-PI1.1
PI1.1 - Processing Integrity Definition

The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product or service specifications.

Artefacts an auditor will ask for
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
Where this commonly fails
  • Notice outdated
  • Consent not granular
  • Requests aging
  • Inventory incomplete
SSAE18-PI1.2
PI1.2 - System Processing Completeness and Accuracy

The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.

Artefacts an auditor will ask for
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
Where this commonly fails
  • Notice outdated
  • Consent not granular
  • Requests aging
  • Inventory incomplete
SSAE18-PI1.3
PI1.3 - Processing Error Handling

The entity implements policies and procedures over system inputs, including controls over completeness, accuracy, and timeliness of inputs and error handling.

Artefacts an auditor will ask for
  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
Where this commonly fails
  • Notice outdated
  • Consent not granular
  • Requests aging
  • Inventory incomplete

SOC 2 - Logical and Physical Access Controls

SSAE18-CC5.1
CC5.1 - COSO Principle 10: Control Activity Selection

The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC5.2
CC5.2 - COSO Principle 11: Technology General Controls

The entity also selects and develops general control activities over technology to support the achievement of objectives.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC5.3
CC5.3 - COSO Principle 12: Control Activity Policies

The entity deploys control activities through policies that establish what is expected and procedures that put policies into action.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.1
CC6.1 - Logical Access Security Software

The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.2
CC6.2 - New User Registration and Authorization

Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.3
CC6.3 - Access Removal

The entity removes access to protected information assets when an individual no longer requires access.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.4
CC6.4 - Physical Access Restrictions

The entity restricts physical access to facilities and protected information assets to authorized personnel.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.5
CC6.5 - Logical Access to Protected Assets

The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.6
CC6.6 - External Threats and Security Measures

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.7
CC6.7 - Data Transmission Restrictions

The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit
SSAE18-CC6.8
CC6.8 - Unauthorized Software Prevention

The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.

Artefacts an auditor will ask for
  • Access provisioning workflows
  • User registration and authorisation records
  • Access removal evidence within SLA
  • Physical access logs and badge inventory
  • Threat detection configuration
  • Data transmission encryption evidence
Where this commonly fails
  • Provisioning manual and inconsistent
  • Removal SLA missed
  • Physical access not reviewed
  • Encryption gaps for transit

SOC 2 - Security (Common Criteria)

SSAE18-CC1.1
CC1.1 - COSO Principle 1: Integrity and Ethical Values

The entity demonstrates a commitment to integrity and ethical values.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC1.2
CC1.2 - COSO Principle 2: Board Independence and Oversight

The board of directors demonstrates independence from management and exercises oversight of internal control development and performance.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC1.3
CC1.3 - COSO Principle 3: Management Structure and Authority

Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC1.4
CC1.4 - COSO Principle 4: Commitment to Competence

The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC1.5
CC1.5 - COSO Principle 5: Accountability

The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC2.1
CC2.1 - COSO Principle 13: Quality Information

The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC2.2
CC2.2 - COSO Principle 14: Internal Communication

The entity internally communicates information, including objectives and responsibilities for internal control.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC2.3
CC2.3 - COSO Principle 15: External Communication

The entity communicates with external parties regarding matters affecting the functioning of internal control.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC3.1
CC3.1 - COSO Principle 6: Risk Identification

The entity specifies objectives with sufficient clarity to enable identification and assessment of risks relating to objectives.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC3.2
CC3.2 - COSO Principle 7: Risk Analysis

The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how to manage them.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC3.3
CC3.3 - COSO Principle 8: Fraud Risk Assessment

The entity considers the potential for fraud in assessing risks to the achievement of objectives.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis
SSAE18-CC3.4
CC3.4 - COSO Principle 9: Change Management

The entity identifies and assesses changes that could significantly impact the system of internal control.

Artefacts an auditor will ask for
  • Policies mapped to COSO 17 principles
  • Risk assessment workpapers
  • Internal and external communication evidence
  • Fraud risk assessment results
  • Change management evidence
Where this commonly fails
  • Principles not mapped
  • Fraud assessment skipped
  • Communication ad hoc
  • Changes lack analysis

SOC 2 - System Operations and Change Management

SSAE18-CC7.1
CC7.1 - Infrastructure and Software Monitoring

To meet its objectives, the entity uses detection and monitoring procedures to identify changes to configurations that result in introduction of new vulnerabilities and susceptibilities to newly discovered vulnerabilities.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC7.2
CC7.2 - Anomaly Monitoring in Operations

The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet objectives.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC7.3
CC7.3 - Security Event Evaluation

The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC7.4
CC7.4 - Incident Response

The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC7.5
CC7.5 - Incident Recovery

The entity identifies, develops, and implements activities to recover from identified security incidents.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC8.1
CC8.1 - Infrastructure and Software Change Management

The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC9.1
CC9.1 - Risk Mitigation Activities

The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale
SSAE18-CC9.2
CC9.2 - Vendor and Business Partner Risk Management

The entity assesses and manages risks associated with vendors and business partners.

Artefacts an auditor will ask for
  • Monitoring configuration and alert rules
  • Anomaly detection logs
  • Security event evaluation records
  • Incident response playbooks
  • Recovery and post incident reports
  • Change management tickets with approvals
Where this commonly fails
  • Monitoring blind spots
  • Events not triaged
  • Recovery untested
  • Vendor reviews stale

SOC 3

SSAE-07
SOC 3 General Use Reports

SOC 3 reports provide an examination opinion on controls relevant to the Trust Services Criteria for general distribution, without the detailed description and test results found in SOC 2.

Artefacts an auditor will ask for
  • Management's assertion suitable for general distribution
  • Short-form examination report
  • Use of SOC 3 logo and seal in accordance with AICPA rules
  • Underlying SOC 2 examination work supporting SOC 3 opinion
Where this commonly fails
  • SOC 3 issued without underlying SOC 2 examination
  • Distribution restrictions inappropriately applied to SOC 3
  • Seal usage not registered with AICPA

Specialised

SSAE-14
Reporting on Pro Forma Financial Information (AT-C 310)

AT-C 310 governs examinations and reviews of pro forma financial information, requiring the practitioner to evaluate management's assumptions and consistency with historical financial statements.

Artefacts an auditor will ask for
  • Pro forma assumptions documented and assessed for reasonableness
  • Reconciliation to historical financial statements
  • Examination or review procedures aligned with assurance level
  • Report following AT-C 310 illustrative format
Where this commonly fails
  • Pro forma issued as audit rather than attestation
  • Assumptions not separately tested
  • Historical link to underlying audited statements weak
SSAE-15
Reporting on Compliance (AT-C 315)

AT-C 315 provides standards for examinations and reviews of an entity's compliance with specified requirements, including the effectiveness of internal control over compliance.

Artefacts an auditor will ask for
  • Specified compliance requirements clearly identified
  • Examination procedures over compliance and related controls
  • Findings of noncompliance evaluated for materiality
  • Report following AT-C 315 illustrative format
Where this commonly fails
  • Compliance requirements not clearly stated in report
  • Internal control over compliance not separately addressed
  • Findings not quantified or qualified
SSAE-16
Examinations of Prospective Financial Information (AT-C 305)

AT-C 305 covers examinations of financial forecasts and projections, requiring evaluation of assumptions, preparation, and presentation in accordance with AICPA guidelines.

Artefacts an auditor will ask for
  • Evaluation of assumptions and supporting evidence
  • Computational accuracy and consistency checks
  • Disclosure of significant assumptions in presentation
  • Report referencing AICPA Guide for Prospective Financial Information
Where this commonly fails
  • Forecast and projection terminology conflated
  • Assumptions not separately listed
  • Restricted use paragraph missing for projections
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SSAE 18 - Attestation Standards (SOC Reporting) framework page.