workflow

SOC 2 Readiness & Evidence Collection

SOC 2 Readiness & Evidence Collection runs ON an already-opened Audit item — the SOC examination engagement record (audit_type readiness, or external_attestation) whose scope (report type and Type 1/Type 2), examination period (period_start/period_end), and CPA firm (external_firm) are already set. That Audit item is an INPUT: this workflow enriches it and attaches its run to it, never creating a duplicate engagement. It consumes the organization's own Control library — the Control items, framework tagged soc2/soc1 — and no upstream workflow feeds it. In scope: one SOC examination cycle end to end — map the Control library to each in-scope Trust Services criterion (Security always; Availability, Confidentiality, Processing Integrity, or Privacy only where a customer commitment requires it) and SOC 1 control objective, close readiness gaps, run the provided-by-client (PBC) evidence request list with QA, and coordinate the CPA firm through fieldwork and follow-ups. Named deliverables: the criteria-to-control mapping matrix and graded gap matrix, the owned PBC evidence request list, the QA'd evidence set, and the cross-referenced PBC response package — all attached to the anchor Audit and its workflow instance. Out of scope: the SOC report the CPA firm drafts and continuous control monitoring between examinations. No downstream workflow is declared; this run's next-cycle seed artifacts (the PBC list and control calendar) stay on the close step as the de facto handoff to the next examination.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • soc2
  • soc1
sourceTemplateId
workflow-library:controls-soc2-readiness-evidence-cycle
releaseId
sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4
canonicalUrl
https://workflow-library.com/all/?w=controls-soc2-readiness-evidence-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-AUDIT-21
    • UC-AUDIT-23
    • UC-AUDIT-25
    • UC-RISK-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4

            Connections