Skip to content

A control needs more than a screenshot.

The business keeps who had access, what was approved and what changed. A SOC 2 review can examine those records within its agreed scope and period, alongside the other evidence your auditor requires.

What a reviewer needs to connect

The control and its operation.

Defined scope
Systems and review period
Named responsibility
The person who owns the control
Supporting records
Access, changes and approval history

A guide to the evidence request, not an audit result.

Assurance depends on controls and how they operate.

SOC 2 examinations address controls relevant to selected Trust Services Criteria. The system description, scope, type of examination and auditor’s work determine the report. Product records can contribute evidence; they cannot provide an audit opinion.

Connect review topics with available records.

These are relevant review topics. The current catalog does not map SOC 2 Trust Services Criteria, and these records do not constitute a SOC 2 report.

Access and responsibility

Organization roles, account security controls, and recorded administrative changes.

Still needs review

Organization-wide access reviews and offboarding need supporting evidence beyond the connected record.

Governed activity

Company-rule checks and approval records for actions sent through them.

Still needs review

Other systems and actions need their own supporting evidence.

Record integrity

Recorded changes and linked receipts that preserve the history of captured activity.

Still needs review

Integrity checks do not demonstrate the effectiveness of every control over an assessment period.

These review topics are not a control mapping, an audit opinion or a finding of legal compliance.

One approval is a record, not a whole control test.

Maya Okafor’s approval of the $612 credit answers who signed off on that action. It does not establish that every credit was checked across an assessment period.

The finance example is illustrative. The auditor defines the scope, sample and testing needed.

Keep independent assurance at the center of the review.

Use the relevant records within the evidence program defined with your auditor.

Trust & security
  • 01

    Selected Trust Services Criteria and examination scope

  • 02

    Control ownership, testing, and assessment-period evidence

  • 03

    System description, service commitments, and external dependencies

Questions about SOC 2?

Does Orcinta have a SOC 2 report?

No SOC 2 attestation is currently claimed. Ask for the current assessment status and the evidence available for your security review.

Does an evidence packet replace a SOC 2 report?

No. An evidence packet presents the company’s own records for an agreed scope, with selected framework references. A SOC 2 report is the result of an independent examination.

Are SOC 2 criteria mapped in the receipt catalog?

No. This page describes relevant architecture and evidence topics. It does not claim an implemented Trust Services Criteria crosswalk or complete examination coverage.

Go back to the source.

The authoritative framework and the scope of your review remain the reference points.

Make the next evidence request easier to answer.

Discuss your requirements