FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC2.3 Communication with external parties about internal control

SOC 2 CC2.3 Communication with external parties about internal control

The organisation communicates with outside parties on matters that affect how internal control functions. Points of focus: relevant, timely information reaches shareholders, partners, regulators, customers and other external parties; open channels let customers, suppliers, auditors and regulators provide input; findings from external assessments reach the board; separate confidential channels exist; the method reflects timing, audience and legal or fiduciary expectations; confidentiality and privacy objectives and their changes are communicated to users, vendors and partners in engagements covering those categories; and at system level, external users are told how the system works, its objectives, their responsibilities and how to report failures, incidents and complaints. The 2022 revision adds, for privacy engagements, telling customers, third parties, data subjects and others how to report a suspected privacy incident.

SOC 2 (Trust Services Criteria). Edition: 2017 Trust Services Criteria with revised points of focus (2022). Checked 2026-10-07. Our statement of the clause, cited; the standard is licensed and not quoted. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.