FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / SOC 2 (Trust Services Criteria)

SOC 2 (Trust Services Criteria): the rules AI agent steps rest on

Edition
2017 Trust Services Criteria with revised points of focus (2022)
Checked current
2026-10-07
Official source
https://www.aicpa-cima.com/resources/download/2017-trust-services-criteria-with-revised-points-of-focus-2022
Licence
The standard is licensed: each rule is our statement of its clause, cited, never quoted.
RuleOur statementSteps that cite it
SOC 2 CC2.3 Communication with external parties about internal controlThe organisation communicates with outside parties on matters that affect how internal control functions. Points of focus: relevant, timely information reaches shareholders, partners, regulators, customers and other external parties; open channels let customers, suppliers, auditors and regulators provide input; findings from external assessments reach the board; separate confidential channels exist; the method reflects timing, audience and legal or fiduciary expectations; confidentiality and privacy objectives and their changes are communicated to users, vendors and partners in engagements covering those categories; and at system level, external users are told how the system works, its objectives, their responsibilities and how to report failures, incidents and complaints. The 2022 revision adds, for privacy engagements, telling customers, third parties, data subjects and others how to report a suspected privacy incident.KC-08 S2 What does the auditor get?
SOC 2 CC4.2 Evaluating and communicating control deficienciesControl deficiencies are evaluated and reported promptly to those who must fix them, including senior management and the board where appropriate. Points of focus: management and the board assess the results of evaluations; deficiencies go to the parties responsible for correction and upward as appropriate; and management tracks whether they are remedied on time.KC-08 S4 Report the deficiency
SOC 2 CC6.2 Registering and authorising users before issuing credentialsBefore system credentials are issued and access is granted, internal and external users whose access the organisation administers are registered and authorised; their credentials are removed once their access is no longer authorised. Points of focus (2022 revision): every kind of credential, for employees, contractors, vendors, partner staff, systems and software, is issued only after authorisation; credentials are reviewed periodically for continued validity, including inappropriate system or service accounts; and credentials that are no longer valid are disabled, destroyed or otherwise blocked from use.KC-01 S6 Decide the vendor's access; KC-08 S1 Find the leaver exceptions; KC-08 S3 Fix the still-open access
SOC 2 CC6.3 Role-based access, least privilege and segregation of dutiesRights over data, programs, functions and other protected assets is granted, changed or removed according to roles, responsibilities or system design and changes, applying least privilege and segregation of duties. Points of focus: access is created or modified on the asset owner's authorisation; it is removed when no longer needed; access structures (role-based, for example) limit privileges and separate incompatible functions; and roles and access rules are reviewed periodically for people who no longer need them (staff, contractors, vendors, partner personnel) and for system or service accounts that should not exist, and adjusted.KC-01 S6 Decide the vendor's access; KC-08 S1 Find the leaver exceptions
SOC 2 CC9.2 Assessing and managing vendor and business partner riskRisk from vendors and business partners is assessed and managed. Points of focus: engagement requirements cover scope and specification, roles, compliance duties and service levels; risks from vendors, partners and their own vendors are assessed periodically; responsibility for managing them is assigned; communication, resolution and exception-handling protocols are set; vendor and partner performance is assessed and issues are addressed; relationships are ended through defined procedures; in confidentiality engagements, confidentiality commitments consistent with the organisation's own are obtained and compliance checked; and in privacy engagements, privacy commitments are obtained, compliance assessed and corrective action taken. The 2022 revision adds: evaluating vulnerabilities created by vendor and partner relationships, including their access to the organisation's systems and network connections; keeping an inventory of vendors and partners and tiering them; considering threats such as a vendor's financial collapse, its security weaknesses, disruption to its operations, or its inability to satisfy business or regulatory obligations; setting review frequency by each vendor's risk; and ending relationships under procedures set in advance, which can cover getting data back securely and having it deleted from the vendor's systems.KC-01 S2 Set the supplier tier; KC-01 S4 Find the contract clause gaps; KC-01 S5 Assess the vendor's assurance report; KC-01 S8 Decide the onboarding outcome