Account for cloud and outsourced providers, user responsibilities, and evidence handoffs in the system description.
Trace the service, not the company chart
Start with the service named in customer contracts. Draw the data and operational path through infrastructure, applications, staff, support, and external providers. Identify which third parties are material to the service and which activities remain under the service organization’s control.
The independent CPA firm determines the examination approach and report. Readiness work can prepare an accurate inventory of subservice providers and the controls they contribute, but it should not predetermine the auditor’s conclusions.
Describe inherited and direct controls clearly
A cloud provider may operate physical security and portions of infrastructure security while the SaaS company configures accounts, application changes, logging, backups, and incident response. Write down the division in operational terms. Confirm contractual rights, notification routes, and available assurance reports for important providers.
A provider report has a boundary and period of its own. Check that the relied-on service and time frame are actually covered, and identify gaps or bridging evidence where appropriate.
Tell customers what they must do
Some service controls work only if a user entity configures access, reviews its own users, or follows an escalation process. Document these complementary customer responsibilities in terms buyers can act on. Do not bury a critical dependency in a generic statement that customers are responsible for security.
Test the customer handoff: can onboarding instructions, contracts, product settings, and the system description tell the same story?
Build the evidence trail before the period
For each control, keep the owner, frequency, evidence source, and exception route. For outsourced activities, preserve supplier assessments, reports, issue follow-up, and change notifications. Sample an access event, release, or incident across the boundary to see whether records join up.
SOC 2 is an attestation examination, not a certification. The report is most useful when the described system matches the service the buyer actually uses.
Put it into practice
- Map the service and all material providers in its delivery path.
- Document provider, supplier, and customer control responsibilities.
- Review supplier assurance for matching scope and period.
- Walk through one end-to-end control event across the boundary.
Primary sources
- AICPA & CIMA: SOC 2 and Trust Services Criteria resources
- AICPA & CIMA: SOC service organizations overview
Normstone resources are general information, not legal advice or an independent assessment.