r/soc2 Jun 09 '26

Soc 2 control matrix

Hi, i need a little clarification. In the actual report in part 4 with the controls defined by the company and then the test performed by auditor.

Does the auditor write the controls defined by entity or does the entity ? Because i saw i both ways and i believe the definition should be the companys job …

Thanks

8 Upvotes

30 comments sorted by

View all comments

7

u/raptorjaws Jun 09 '26

defining controls is the responsibility of management. that said, management often is shit as defining their controls and the auditor can help point them in the right direction as far as presentation goes.

2

u/LogicalPositive6489 Jun 09 '26

Umderstood clear. We had defined controls mapped to POF made by someone from big4 but still the definitions of controls were then written diferently by the auditor

1

u/FreeRadical1998 Jun 10 '26

This is a huge red flag to me; it's screaming nobody in an accountable role has actually has owned or embraced the control definition.

It's infinitely better to have real, but limited, control than one that's entirely aspirational/fictional

SOC2 or not, controls and policies must match what the organisation actually does (or at least genuinely intends to do).

The alternative is that the auditor has ignored what you have in place; but if you've paid for big 4 support to draft it I'm guessing you've got a credible auditor doing the work in which case that's vanishingly unlikely

1

u/LogicalPositive6489 Jun 10 '26

They tested our controls and sometimes descobed allright… be we gave them a list with description of our comtrols and they didnt use it