Access and responsibility
Organization roles, account security controls, and recorded administrative changes.
Still needs review
Organization-wide access reviews and offboarding need supporting evidence beyond the connected record.
The business keeps who had access, what was approved and what changed. A SOC 2 review can examine those records within its agreed scope and period, alongside the other evidence your auditor requires.
A guide to the evidence request, not an audit result.
SOC 2 examinations address controls relevant to selected Trust Services Criteria. The system description, scope, type of examination and auditor’s work determine the report. Product records can contribute evidence; they cannot provide an audit opinion.
These are relevant review topics. The current catalog does not map SOC 2 Trust Services Criteria, and these records do not constitute a SOC 2 report.
Organization roles, account security controls, and recorded administrative changes.
Organization-wide access reviews and offboarding need supporting evidence beyond the connected record.
Company-rule checks and approval records for actions sent through them.
Other systems and actions need their own supporting evidence.
Recorded changes and linked receipts that preserve the history of captured activity.
Integrity checks do not demonstrate the effectiveness of every control over an assessment period.
These review topics are not a control mapping, an audit opinion or a finding of legal compliance.
Maya Okafor’s approval of the $612 credit answers who signed off on that action. It does not establish that every credit was checked across an assessment period.
The finance example is illustrative. The auditor defines the scope, sample and testing needed.
Use the relevant records within the evidence program defined with your auditor.
Trust & securitySelected Trust Services Criteria and examination scope
Control ownership, testing, and assessment-period evidence
System description, service commitments, and external dependencies
No SOC 2 attestation is currently claimed. Ask for the current assessment status and the evidence available for your security review.
No. An evidence packet presents the company’s own records for an agreed scope, with selected framework references. A SOC 2 report is the result of an independent examination.
No. This page describes relevant architecture and evidence topics. It does not claim an implemented Trust Services Criteria crosswalk or complete examination coverage.
The authoritative framework and the scope of your review remain the reference points.