Skip to content
compliancebase
SOC 2CC1 — Control Environment — Integrity and Ethical Values

CC1.1

Control Environment — Integrity and Ethical Values

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Demonstrate that leadership defines, communicates, and acts consistently with standards of integrity and ethical conduct.

Points of focus

  • Set behavioral standards for employees, executives, and contractors
  • Evaluate adherence and address deviations consistently
  • Ensure leadership actions reinforce stated expectations

Implementation notes

Publish a concise code of conduct inside the onboarding system, capture acknowledgements for employees and contractors, and route conflicts or suspected misconduct through a confidential, documented escalation path. Operationalize set behavioral standards for employees, executives, and contractors in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved code of conduct with workforce acknowledgements with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that executives bypass security or approval rules without documented accountability Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample approved code of conduct with workforce acknowledgements with dates and named reviewers. Be ready to walk through how you detect and correct: executives bypass security or approval rules without documented accountability

Evidence auditors typically request:

  • Approved code of conduct with workforce acknowledgements
  • Conflict-of-interest disclosures and investigation records
  • Board or leadership minutes addressing ethics and conduct

Common gaps

  • Executives bypass security or approval rules without documented accountability
  • Contractors with production access never acknowledge conduct expectations

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC1.1This control
ISO 27001A.5.4, A.6.2A.5.4 management responsibilities reinforce ethical conduct.
GDPRArticle 5Accountability under Article 5 expects leadership tone on privacy.
HIPAA§164.308(a)(1)Security management process includes workforce compliance culture.

Primary sources

Frequently Asked Questions

Control Environment — Integrity and Ethical Values applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — set behavioral standards for employees, executives, and contractors — with evidence stored where auditors and customers can sample it.

Lead with approved code of conduct with workforce acknowledgements and pair it with conflict-of-interest disclosures and investigation records. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because executives bypass security or approval rules without documented accountability Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above