CC4.1: Ongoing and separate evaluations
The company checks that its controls actually work, through routine monitoring (scans, reviews) and periodic separate checks such as a penetration test or internal audit.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC4 (Monitoring activities) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC4.1
The Policyseed crosswalk points CC4.1 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P01 Information Security Policy, section 8 (Review Cadence). Owner: Security Owner.
- P11 Vulnerability and Patch Management Policy, section 5 (Procedures). Owner: Engineering Lead.
- P17 Risk Assessment and Management Policy, section 5 (Procedures). Owner: Security Owner.
Evidence examples for CC4.1
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- Annual internal control self-assessment using the Evidence Checklist, signed by the Security Owner
- Most recent penetration test report and remediation tracker
- Vulnerability scan reports from the last quarter showing scan dates and findings
- Quarterly access review spreadsheet signed by the Security Owner
Related criteria in CC4 (Monitoring activities)
Previous: CC3.4 Changes that affect risk. Next: CC4.2 Communicating deficiencies. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.