{"description":"Interim fieldwork for the Type II examination: cycle walkthroughs, design assessment against the Trust Services Criteria, the first operating-effectiveness testing wave over the agreed interim evidence window, and exception triage feeding remediation and retest planning before the period closes. Interim SOC 2 Type II fieldwork for the listed control selections and agreed interim window. Later-period testing and the service auditor's independent opinion remain outside this module. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","edges":[{"id":"e-step-2-step-4","source":"step-2","target":"step-4"}],"isPublic":true,"itemTypeSlug":"audit","metadata":{"capabilities":[],"configuration":["engagement_scope","applicable_criteria","review_period","responsible_roles","resource_reference_index"],"controlMappingQualification":"Links reflect the procedures and scoped criteria in this module; other requirements sharing a unified control remain outside its conclusion.","controlVerbs":{},"controls":["UC-ACCESS-01","UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-09","UC-BCDR-03","UC-BCDR-10","UC-CONFIG-01","UC-CONFIG-02","UC-CRYPTO-01","UC-GOV-16","UC-GOV-21","UC-HR-01","UC-IR-06","UC-IR-10","UC-LOG-01","UC-RISK-14","UC-TRAIN-01","UC-VULN-03"],"department":"internal-audit","domains":["audit"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-type2-interim-testing","contentDigest":"sha256:26d1ded689c4f18e7d13568fab54fde2e1caa585cc01e7820226c793cfd2b175","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:26d1ded689c4f18e7d13568fab54fde2e1caa585cc01e7820226c793cfd2b175","schemaVersion":1,"sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing"},"lineOfDefense":"assure","mappingStatus":"mapped","risks":[],"scope":"Interim SOC 2 Type II fieldwork for the listed control selections and agreed interim window. Later-period testing and the service auditor's independent opinion remain outside this module.","slug":"audit-soc2-type2-interim-testing","source":"coworkcanvas-gallery","standards":["soc2"],"teams":["internal-audit"]},"name":"SOC 2 Type II Interim Testing","nodes":[{"data":{"controls":["UC-GOV-16","UC-ACCESS-03","UC-LOG-01","UC-CRYPTO-01","UC-VULN-03","UC-ACCESS-01","UC-CONFIG-02","UC-IR-06","UC-BCDR-03"],"description":"Conclude whether the controls as designed, if operated as described, would meet the applicable Trust Services Criteria. The assessment centers on the linked core: risk-based baseline selection under UC-GOV-16, least privilege and segregation under UC-ACCESS-03, security-event logging under UC-LOG-01, encryption at rest and in transit under UC-CRYPTO-01, and time-bound flaw remediation under UC-VULN-03 - each traced from criterion to control statement to the evidence the PBC requests will produce.","instructions":"**Objective**\nConclude whether the controls as designed, if operated as described, would meet the applicable Trust Services Criteria. The assessment centers on the linked core: risk-based baseline selection under UC-GOV-16, least privilege and segregation under UC-ACCESS-03, security-event logging under UC-LOG-01, encryption at rest and in transit under UC-CRYPTO-01, and time-bound flaw remediation under UC-VULN-03 - each traced from criterion to control statement to the evidence the PBC requests will produce.\n\n**Inputs**\nBefore starting, attach the approved scope and applicable criteria, review-period dates, responsible-role assignments, and a resource-reference index identifying the existing subject item, policy versions, systems of record, linked controls and processes, and any upstream evidence packages. Resolve each generic resource reference against that index; record unavailable resources as gaps.\n\nThe assigned assessor evaluates evidence and drafts each conclusion; an independent engagement reviewer challenges sufficiency and conclusions. Management sign-off acknowledges findings and action ownership. The service auditor retains responsibility for any SOC opinion.\n\n- The Information Security Policy as the umbrella authority for each walked cycle\n- One selected occurrence per cycle from the agreed opening weeks of the review period\n- The owning-process run records in AssureSwarm for each selected occurrence\n- Screen access to the systems of record: the workforce identity and collaboration platform admin, the source-control platform, the monitoring console, and the managed database service backup history\n\nThe Risk Assessment Methodology and the current risk register with treatment decisions\n- Walkthrough memos and divergence notes from the cycle walkthroughs\n- Control statements and framework reference rows for the linked consolidated controls\n- The readiness assessment's design conclusions from the completed prior readiness engagement, as prior-work input\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Walk Through Key Control Cycles”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Walk Through Key Control Cycles: Confirm the auditor's understanding of how the key cycles actually operate by walking one recent, real instance of each end to end with the control owner: account provisioning and deprovisioning under UC-ACCESS-01, change authorization and approval under UC-CONFIG-02, incident response and containment under UC-IR-06, and backup with verified restorability under UC-BCDR-03. Walkthroughs anchor the design assessment and the sampling approach for the operating-effectiveness waves.\n\n2. For the provisioning walkthrough, follow one joiner in the opening review window from HR trigger through account creation, group assignment, and first login, then one leaver through revocation - noting who acted, where approval is recorded, and how fast revocation landed.\n3. For the change walkthrough, follow one production merge request from authorship through review, pipeline checks, approval, and the application hosting service revision it produced.\n4. For the incident walkthrough, follow one declared event through triage, containment, and the postmortem record.\n5. For the backup walkthrough, inspect one completed the managed database service backup and the most recent restore verification.\n6. At each hand-off, ask the operator to show - not describe - the record; note any divergence between the documented procedure and observed practice as a design-assessment input.\n\n7. Assessment scope for Assess Control Design Against the Criteria: Conclude whether the controls as designed, if operated as described, would meet the applicable Trust Services Criteria. The assessment centers on the linked core: risk-based baseline selection under UC-GOV-16, least privilege and segregation under UC-ACCESS-03, security-event logging under UC-LOG-01, encryption at rest and in transit under UC-CRYPTO-01, and time-bound flaw remediation under UC-VULN-03 - each traced from criterion to control statement to the evidence the PBC requests will produce.\n\n8. For each linked control, map the criteria it serves and confirm the control statement actually addresses the risk the criterion contemplates - precision here prevents testing the wrong thing at the operating-effectiveness waves.\n9. Evaluate whether the control's frequency, owner, and evidence trail are specified tightly enough to test: an \"as needed\" control with no record is a design gap regardless of diligence.\n10. Assess the compensations where design deviates from convention - the firm's small-team structure leans on documented segregation compensations and the immutable audit-log sink; conclude whether those compensations are responsive.\n11. Reconcile against the readiness conclusions and investigate anything that regressed since the prior readiness assessment.\n12. Draft the design conclusion per control and agree the sampling approach and populations for the first operating-effectiveness wave.\n\n**Record in AssureSwarm**\nRecord one walkthrough memo per cycle on this activity, attaching the observed artifacts and naming the operators interviewed. Divergences are logged as candidate design observations, not yet findings.\n\nRecord the design conclusion matrix on this activity with criterion-to-control mapping attached. Design gaps raise issues on the examination with named owners; agreed sampling plans attach here for the testing wave to consume.\n\n**Exit criteria**\nAll four cycles carry a completed walkthrough memo confirmed by the control owner, and every observed divergence is queued for the design assessment. Every linked control carries a design conclusion, compensating designs are explicitly assessed, and the wave-one sampling plan is agreed with populations defined.","kind":"task","label":"Assess Control Design Against the Criteria","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-2"},{"data":{"controls":["UC-RISK-14","UC-IR-10","UC-GOV-21","UC-ACCESS-02","UC-ACCESS-09","UC-CONFIG-01","UC-TRAIN-01","UC-HR-01","UC-BCDR-10"],"description":"Triage every exception raised in wave-one testing, distinguish deviation from deficiency, and agree the remediation and retest plan while the review period still has room to demonstrate corrected operation. The linked controls govern the machinery: deficiency tracking to closure under UC-RISK-14, learning and corrective-action communication under UC-IR-10, and risk-and-control reporting to leadership under UC-GOV-21.","instructions":"**Objective**\nTriage every exception raised in wave-one testing, distinguish deviation from deficiency, and agree the remediation and retest plan while the review period still has room to demonstrate corrected operation. The linked controls govern the machinery: deficiency tracking to closure under UC-RISK-14, learning and corrective-action communication under UC-IR-10, and risk-and-control reporting to leadership under UC-GOV-21.\n\n**Inputs**\nThe Human Resources Security Policy for the screening and training provisions under test\n- Agreed sampling plans and populations from the design assessment\n- PBC evidence delivered against the access, operations, and identity requests\n- The examination's exception log, empty at wave open\n\nThe Nonconformity & Corrective Action Procedure for classification and root-cause handling\n- The wave-one exception log with test sheets and failed-attribute detail\n- Control-owner availability and the remediation capacity view for the remaining remediation window\n- The examination timeline: the agreed period end and the reporting activities that follow\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Execute Operating-Effectiveness Testing - Wave 1”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Execute Operating-Effectiveness Testing - Wave 1: Test operating effectiveness over the first tranche of the review period (agreed interim evidence window) for the wave-one selections: periodic access review under UC-ACCESS-02, multi-factor authentication under UC-ACCESS-09, configuration hardening under UC-CONFIG-01, security awareness training under UC-TRAIN-01, personnel screening under UC-HR-01, and recovery testing under UC-BCDR-10. Wave one establishes whether the period is trending clean while enough runway remains to remediate and retest before the agreed period end.\n\n2. Pull each sample per the agreed plan and document the selection method with the population hash, so reperformance is possible.\n3. For recurring controls, test each sampled occurrence against the control statement: performer, timeliness, evidence completeness, and follow-through on anything the occurrence flagged.\n4. For configuration controls, test the setting at multiple points in the tranche using the dated PBC captures - MFA enforcement and hardening baselines must hold across the window, not just at inspection.\n5. For the personnel controls, sample joiners within the interim evidence window for completed screening and the workforce for on-time training completion, tracing misses to documented follow-up.\n6. Write the test sheet per control as testing completes; an exception found mid-wave goes to the exception log the same day so triage never waits on the wave.\n\n7. Assessment scope for Triage Exceptions & Plan Remediation Retests: Triage every exception raised in wave-one testing, distinguish deviation from deficiency, and agree the remediation and retest plan while the review period still has room to demonstrate corrected operation. The linked controls govern the machinery: deficiency tracking to closure under UC-RISK-14, learning and corrective-action communication under UC-IR-10, and risk-and-control reporting to leadership under UC-GOV-21.\n\n8. Classify each exception with the auditor: isolated deviation, systematic deviation, or control deficiency - the classification drives whether a retest, an expanded sample, or a report disclosure follows.\n9. For each item needing remediation, agree the corrective action, owner, and completion date with enough lead time that a retest can cover post-remediation occurrences inside the period.\n10. Determine root cause per the corrective-action procedure; a fix that does not address cause earns a repeat exception at the second wave.\n11. Schedule the retests and the second-wave scope, folding in any control whose population shifted since the sampling plan was agreed.\n12. Brief leadership through the standing risk-reporting channel so the exception picture reaches the executive sponsor and security and compliance lead before the reporting activities begin, and take single sign-off on the triage disposition.\n\n**Record in AssureSwarm**\nAttach test sheets and sample workpapers to this activity, one packet per linked control. Exceptions reference the failed occurrence precisely - control, date, sample item, and the attribute that failed.\n\nRecord the triage disposition per exception on this activity, raise each remediation as an issue on the examination with owner and date, and attach the retest schedule.\n\n**Exit criteria**\nEvery wave-one control carries a completed test sheet with documented sampling, and all exceptions are logged with enough precision to triage without re-pulling evidence. Every wave-one exception carries an agreed classification and disposition, remediations have owners and dates inside the period, the retest schedule is attached, and sign-off is recorded.","kind":"task","label":"Triage Exceptions & Plan Remediation Retests","performedBy":{"note":"Agent retrieves authorized evidence and prepares workpaper attachments. The assigned human assessor evaluates sufficiency and signs the conclusion.","primitives":["coach-query-data","coach-document-upload"]}},"id":"step-4"}],"sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing"}
