Skip to content

How SOC 2 Auditors Test Controls

 

Learn about management assertion, sampling in the SOC 2 audit, control areas tested, and what happens if a sampled control instance shows a failure, and more through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for a SOC 2 Readiness Partner or would like to discuss a customized solution for your organization. 

Table of Contents

What is the Management Assertion in a SOC 2 Report? 

 

The Management Assertion is a required written statement included in every SOC 2 Report, Type 1 and Type 2, in which the organization’s leadership formally attests that the system description is accurate and complete, and that controls are suitably designed and/or operating effectively to meet the applicable Trust Services Criteria. The auditor reviews the Management Assertion and will challenge it if supporting evidence does not align. Management is formally on record in a document shared with customers and partners. A Management Assertion that overstates control effectiveness creates both credibility and legal exposure, preparing it accurately with readiness partner guidance before fieldwork begins is essential. 

 

What is sampling in a SOC 2 audit? 

 

Sampling is the auditor’s method of testing controls by selecting a representative subset of control executions to verify consistent performance, rather than examining every instance of operation. Sample sizes depend on the frequency of the control, the risk level, and the length of the observation period. For controls that operate daily, auditors may select twenty-five to sixty samples. For controls that operate monthly, they may test all instances or a representative subset. For annual controls, such as a risk assessment, they typically test the single occurrence. Auditors document which samples were selected, what evidence was reviewed, and whether the evidence confirmed the control operated as described. 

 

What happens if a sampled control instance shows a failure? 

 

If a specific sample shows that a control did not operate as intended, an access review not performed on schedule, a change deployed without proper approval, an employee completing training late, the auditor documents it as a deviation or exception. A single isolated exception in an otherwise well-controlled environment may be noted without affecting the overall opinion.  

A pattern of exceptions across multiple samples of the same control, or a failure in a high-risk control area, will typically result in a finding affecting the auditor’s opinion. This is why organizations should monitor control operation throughout the observation period rather than discovering failures for the first time during audit fieldwork.

 

What control areas do SOC 2 auditors test most intensively? 

 

Five control areas receive the most intensive auditor scrutiny and generate the highest proportion of exceptions across SOC 2 examinations. 

Logical access controls, who has access to which systems, how access is granted and revoked, and whether terminated employee access is removed promptly, are tested in every examination and are the most common source of findings. Change management, whether system changes follow an approved process with documented testing and authorization, is tested for every in-scope system change during the observation period. Vendor management, whether sub-processors have been assessed and whether contracts include security requirements, generates findings when assessments are incomplete or untimely. Incident response, whether the plan is documented, tested, and followed, generates findings when organizations have plans on paper that have never been exercised. Security awareness training, whether all employees completed required training within the required timeframe, produces exceptions when HR records and training platform records are not synchronized. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data
Sam-IT-Solutions Logo
SAM IT Solutions

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties