CC1.2
Board Independence and Oversight
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Provide independent governing-body oversight of internal control, management decisions, and the achievement of system objectives.
Points of focus
- Establish oversight responsibilities separate from day-to-day management
- Give the board or equivalent body sufficient expertise and information
- Challenge management and follow remediation to closure
Implementation notes
Give directors a quarterly control dashboard covering incidents, audit findings, uptime, vendor concentration, and overdue risk treatments, with named follow-ups captured in minutes rather than informal chat. Operationalize establish oversight responsibilities separate from day-to-day management in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain board charter and independence records with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the board receives only optimistic kpi summaries with no incidents or overdue risks Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample board charter and independence records with dates and named reviewers. Be ready to walk through how you detect and correct: the board receives only optimistic kpi summaries with no incidents or overdue risks
Evidence auditors typically request:
- Board charter and independence records
- Risk, security, and audit reporting packages supplied to directors
- Meeting minutes documenting challenge, decisions, and follow-up
Common gaps
- The board receives only optimistic KPI summaries with no incidents or overdue risks
- A founder-controlled board approves management assertions without independent challenge
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC1.2 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus