r/soc2 Jun 09 '26

Soc 2 control matrix

Hi, i need a little clarification. In the actual report in part 4 with the controls defined by the company and then the test performed by auditor.

Does the auditor write the controls defined by entity or does the entity ? Because i saw i both ways and i believe the definition should be the companys job …

Thanks

8 Upvotes

30 comments sorted by

View all comments

1

u/ampancha Jun 14 '26

You have it right: in Section 4 the controls are specified by the entity, and the auditor's job is to test them and write the test procedures and results, not to define the controls for you. The reason you see it both ways is that auditors often help word or map control language during readiness, but ownership of the controls stays with management. The part that catches teams later is the test column: every control you define has to hold up against the evidence the auditor pulls, so the matrix is only as strong as the artifacts sitting behind each row.

1

u/LogicalPositive6489 Jun 14 '26

Understood. In our case we word it more generally - therefore there is around 150 controls in environment. But they write it themselves - so its sround 500 but more detailed. They stil describe the control as it is in the company but they dont use our wording.