workflow
SOC 2 Readiness & Evidence Collection
SOC 2 Readiness & Evidence Collection runs ON an already-opened Audit item — the SOC examination engagement record (audit_type readiness, or external_attestation) whose scope (report type and Type 1/Type 2), examination period (period_start/period_end), and CPA firm (external_firm) are already set. That Audit item is an INPUT: this workflow enriches it and attaches its run to it, never creating a duplicate engagement. It consumes the organization's own Control library — the Control items, framework tagged soc2/soc1 — and no upstream workflow feeds it. In scope: one SOC examination cycle end to end — map the Control library to each in-scope Trust Services criterion (Security always; Availability, Confidentiality, Processing Integrity, or Privacy only where a customer commitment requires it) and SOC 1 control objective, close readiness gaps, run the provided-by-client (PBC) evidence request list with QA, and coordinate the CPA firm through fieldwork and follow-ups. Named deliverables: the criteria-to-control mapping matrix and graded gap matrix, the owned PBC evidence request list, the QA'd evidence set, and the cross-referenced PBC response package — all attached to the anchor Audit and its workflow instance. Out of scope: the SOC report the CPA firm drafts and continuous control monitoring between examinations. No downstream workflow is declared; this run's next-cycle seed artifacts (the PBC list and control calendar) stay on the close step as the de facto handoff to the next examination.
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- soc2
- soc1
- sourceTemplateId
- workflow-library:controls-soc2-readiness-evidence-cycle
- releaseId
- sha256:d920e075c19078b746ed831d7f75f4a9e8054a66fbf25d0b682219e336491e65
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=controls-soc2-readiness-evidence-cycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-AUDIT-21
- UC-AUDIT-23
- UC-AUDIT-25
- UC-RISK-14
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- independence
- competence
- evidence
- recency
- reliance rationale
- nodeIds
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:d920e075c19078b746ed831d7f75f4a9e8054a66fbf25d0b682219e336491e65
Connections
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- SOC 2 Readiness & Evidence Collection oversees UC-RISK-14 — Track deficiencies to closure with remediation action plans
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-25 — Maintain quality records and information for internal control
- SOC 2 Readiness & Evidence Collection oversees UC-AUDIT-21 — Assess control effectiveness through testing and monitoring