workflow
SOC 2 Readiness & Evidence Collection
SOC 2 Readiness & Evidence Collection runs ON an already-opened Audit item — the SOC examination engagement record (audit_type readiness, or external_attestation) whose scope (report type and Type 1/Type 2), examination period (period_start/period_end), and CPA firm (external_firm) are already set. That Audit item is an INPUT: this workflow enriches it and attaches its run to it, never creating a duplicate engagement. It consumes the organization's own Control library — the Control items, framework tagged soc2/soc1 — and no upstream workflow feeds it. In scope: one SOC examination cycle end to end — map the Control library to each in-scope Trust Services criterion (Security always; Availability, Confidentiality, Processing Integrity, or Privacy only where a customer commitment requires it) and SOC 1 control objective, close readiness gaps, run the provided-by-client (PBC) evidence request list with QA, and coordinate the CPA firm through fieldwork and follow-ups. Named deliverables: the criteria-to-control mapping matrix and graded gap matrix, the owned PBC evidence request list, the QA'd evidence set, and the cross-referenced PBC response package — all attached to the anchor Audit and its workflow instance. Out of scope: the SOC report the CPA firm drafts and continuous control monitoring between examinations. No downstream workflow is declared; this run's next-cycle seed artifacts (the PBC list and control calendar) stay on the close step as the de facto handoff to the next examination.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- soc2
- soc1
- sourceTemplateId
- workflow-library:controls-soc2-readiness-evidence-cycle
- releaseId
- sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4
- canonicalUrl
- https://workflow-library.com/all/?w=controls-soc2-readiness-evidence-cycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-AUDIT-21
- UC-AUDIT-23
- UC-AUDIT-25
- UC-RISK-14
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- independence
- competence
- evidence
- recency
- reliance rationale
- nodeIds
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4
Connections
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- SOC 2 Readiness & Evidence Collection oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-25 — Maintain quality records and information for internal control
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring