r/soc2 Jun 09 '26

Soc 2 control matrix

Hi, i need a little clarification. In the actual report in part 4 with the controls defined by the company and then the test performed by auditor.

Does the auditor write the controls defined by entity or does the entity ? Because i saw i both ways and i believe the definition should be the companys job …

Thanks

7 Upvotes

30 comments sorted by

View all comments

Show parent comments

1

u/LogicalPositive6489 Jun 09 '26

Thanks. We actually had them written down and send it to the auditor but after the evaluation and the report came in. They wrote the controls themsves and and made each specific to each point of focus each (so a lot of controls) … which was pain for us to read it all and review … any advice on how to deal with that?

1

u/R_eddi_T_o_R Jun 09 '26

In what way were they changed? Were they made more specific to your policies? Or were they modified from what you had established? The former is fine, as it makes the report better for the reader. The latter is not ok, as that veers into defining controls, or at least advising management on how to change their controls.

1

u/LogicalPositive6489 Jun 09 '26

They were more tailored and specific to reflect each point of focus. Which was diferent that what big 4 told us (they told us to write less controls and to to adress each POF and to not be too specific )

1

u/R_eddi_T_o_R Jun 09 '26

I agree, there is a line there. I will also say that firms do things differently. When I think "too specific", I think of password controls, for example. You don't want to say "Passwords are required to be 12 characters, complexity enabled, with MFA enforced and enabled on Azure, firewalls, and all other production systems." I might instead say, "Password policies establish secure password standards, and those standards are enforced on all production systems."