SOC 2 Academy: The Importance of Organizational Communication

by Joseph Kirkpatrick / December 16, 2022

Common Criteria 2.2 Communication is one of the underpinnings of meeting the requirements within the SOC 2 Trust Services Criteria. Common criteria 2.2 says, “The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.” For any type of organization to operate efficiently, there needs to be established avenues of communication for all employees. How will an employee know who to…

SOC 2 Academy: Making Informed Decisions

by Joseph Kirkpatrick / December 16, 2022

Common Criteria 2.1 When a service organization undergoes a SOC 2 audit, auditors will be looking to validate that they comply with the common criteria listed in the 2017 SOC 2 Trust Services Criteria. Common criteria 2.1 states, “The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.” Let’s discuss why it’s important that service organizations demonstrate that they are making informed decisions…

SOC 2 Academy: Holding Your Employees Accountable

by Joseph Kirkpatrick / December 16, 2022

Common Criteria 1.5 When a service organization undergoes a SOC 2 audit, auditors will be looking to validate that they comply with the common criteria listed in the 2017 SOC 2 Trust Services Criteria. Common criteria 1.5 (CC1.5) states, “The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.” What do organizations need to do to demonstrate that they are holding employees accountable? Organizations can…

SOC 2 Academy: Attracting, Developing, and Retaining Confident Employees

by Joseph Kirkpatrick / December 16, 2022

Common Criteria 1.4 When a service organization undergoes a SOC 2 audit, auditors will be looking to validate that they comply with the common criteria listed in the SOC 2 Trust Services Criteria. Common criteria 1.4 says that an organization must demonstrate a commitment to attracting, developing, and retaining competent employees in alignment with objectives. How can organizations do this? Let’s discuss. Attracting, Developing, and Retaining Competent Employees During a SOC…

SOC 2 Academy: Defining the Responsibilities of Employees

by Joseph Kirkpatrick / December 16, 2022

Common Criteria 1.3 When a service organization undergoes a SOC 2 audit, auditors will be looking to validate that they comply with the common criteria listed in the 2017 SOC 2 Trust Services Criteria. Common criteria 1.3 (CC1.3) states, “Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.” Let’s discuss at how organizations can go about defining the responsibilities of employees…