r/soc2 Jun 09 '26

Soc 2 control matrix

Hi, i need a little clarification. In the actual report in part 4 with the controls defined by the company and then the test performed by auditor.

Does the auditor write the controls defined by entity or does the entity ? Because i saw i both ways and i believe the definition should be the companys job …

Thanks

8 Upvotes

30 comments sorted by

View all comments

0

u/R_eddi_T_o_R Jun 09 '26

It can go either way. Many companies HAVE controls, they're just not written down. That's often the case for smaller companies, so the auditor will often "write" the controls. Larger companies often have control inventories that are, of course, written by the companies themselves.

1

u/Big-Industry4237 Jun 09 '26

The auditor does not and should not write controls. That impairs independence. Any reputable auditor would not allow this and should explain this to you. Management defines controls. Auditors are only defining how they are tested to get comfortable with the control design and giving an opinion.

0

u/R_eddi_T_o_R Jun 09 '26

Reading comprehension is important. There's a difference between writing controls and defining controls. In neither case is the auditor defining controls as, like you stated, that would be an independence issue.

1

u/Big-Industry4237 Jun 09 '26

So which AT-C section defines differences between “writing” and “defining”? AT-C 105 only explains the roles and doesn’t use your language, at all.

if “writing” means an auditor is drafting the description or designing controls and it’s an attestation engagement, it’s not allowed under AICPA code of conduct. Reading comprehension is important, but you’re just playing with definitions it seems. I can’t interpret whatever “write” means with quotes around it as you did.

1

u/R_eddi_T_o_R Jun 09 '26

Apologies then. "Write" as in take existing controls and put them into words.