CC5.3: Policies and procedures

Controls are written into approved policies and step-by-step procedures, staff know about them, owners are assigned, and the documents are reviewed on a schedule.

Category: Security (common criteria, required in every SOC 2 report) · Series: CC5 (Control activities) · TSC 2017 (2022 points of focus)

That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.

Policies that address CC5.3

The Policyseed crosswalk points CC5.3 at 2 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.

Evidence examples for CC5.3

Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.

  • Complete policy set with approver, version and effective date on every revision history table
  • Policy Review Calendar with owner and next review date for each policy
  • Signed policy acknowledgment forms for all staff
  • Record of the last annual policy review (meeting notes or approval email)

Related criteria in CC5 (Control activities)

Previous: CC5.2 Technology controls. Next: CC6.1 Logical access security. All 38 criteria are listed on the template index.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.