CC1.5
Accountability
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Hold individuals accountable for assigned internal-control responsibilities while balancing performance measures and incentives.
Points of focus
- Assign measurable control responsibilities to named people
- Evaluate performance and apply rewards or corrective action fairly
- Review incentives for pressure that could encourage control bypass
Implementation notes
Put recurring control tasks in the same planning system as product work, name a directly responsible individual, surface missed evidence deadlines, and include reliability and security outcomes in manager reviews. Operationalize assign measurable control responsibilities to named people in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain control-owner register with acceptance and review dates with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that control ownership is assigned to a team alias and no person answers for missed work Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample control-owner register with acceptance and review dates with dates and named reviewers. Be ready to walk through how you detect and correct: control ownership is assigned to a team alias and no person answers for missed work
Evidence auditors typically request:
- Control-owner register with acceptance and review dates
- Performance goals that include reliability and security outcomes
- Records of overdue-control escalation and corrective action
Common gaps
- Control ownership is assigned to a team alias and no person answers for missed work
- Delivery bonuses reward deployment speed while ignoring rollback and review failures
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC1.5 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus