CC1.1
Control Environment — Integrity and Ethical Values
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Demonstrate that leadership defines, communicates, and acts consistently with standards of integrity and ethical conduct.
Points of focus
- Set behavioral standards for employees, executives, and contractors
- Evaluate adherence and address deviations consistently
- Ensure leadership actions reinforce stated expectations
Implementation notes
Publish a concise code of conduct inside the onboarding system, capture acknowledgements for employees and contractors, and route conflicts or suspected misconduct through a confidential, documented escalation path. Operationalize set behavioral standards for employees, executives, and contractors in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved code of conduct with workforce acknowledgements with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that executives bypass security or approval rules without documented accountability Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample approved code of conduct with workforce acknowledgements with dates and named reviewers. Be ready to walk through how you detect and correct: executives bypass security or approval rules without documented accountability
Evidence auditors typically request:
- Approved code of conduct with workforce acknowledgements
- Conflict-of-interest disclosures and investigation records
- Board or leadership minutes addressing ethics and conduct
Common gaps
- Executives bypass security or approval rules without documented accountability
- Contractors with production access never acknowledge conduct expectations
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC1.1 | This control |
| ISO 27001 | A.5.4, A.6.2 | A.5.4 management responsibilities reinforce ethical conduct. |
| GDPR | Article 5 | Accountability under Article 5 expects leadership tone on privacy. |
| HIPAA | §164.308(a)(1) | Security management process includes workforce compliance culture. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus