Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC2.3 Communication with external parties about internal control
SOC 2 CC2.3 Communication with external parties about internal control
The organisation communicates with outside parties on matters that affect how internal control functions. Points of focus: relevant, timely information reaches shareholders, partners, regulators, customers and other external parties; open channels let customers, suppliers, auditors and regulators provide input; findings from external assessments reach the board; separate confidential channels exist; the method reflects timing, audience and legal or fiduciary expectations; confidentiality and privacy objectives and their changes are communicated to users, vendors and partners in engagements covering those categories; and at system level, external users are told how the system works, its objectives, their responsibilities and how to report failures, incidents and complaints. The 2022 revision adds, for privacy engagements, telling customers, third parties, data subjects and others how to report a suspected privacy incident.
Steps that cite it
- KC-08 S2 What does the auditor get?
Evidence commonly asked for
- Customer-facing system description, service terms or trust page stating commitments
- Documented channel for customers to report incidents or complaints, with sample tickets
- Contracts or notices communicating confidentiality and privacy commitments to customers and vendors
- Board papers showing external audit or assessment results were reported
Accepted citation forms are listed on the answer format page.