Skip to content
compliancebase
SOC 2CC2 — Communicates Information Internally

CC2.1

Communicates Information Internally

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Obtain or generate relevant, quality information and communicate it internally so personnel can carry out control responsibilities.

Points of focus

  • Identify information needed by control owners and operators
  • Use reliable internal channels with appropriate timing
  • Enable upward communication of exceptions and concerns

Implementation notes

Publish role-based control dashboards, route material exceptions into owned tickets, and push architecture, vendor, incident, and policy changes to affected operators with acknowledgement where action is required. Operationalize identify information needed by control owners and operators in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain internal control dashboard and distribution records with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that control owners learn about architecture changes only when audit evidence is requested Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample internal control dashboard and distribution records with dates and named reviewers. Be ready to walk through how you detect and correct: control owners learn about architecture changes only when audit evidence is requested

Evidence auditors typically request:

  • Internal control dashboard and distribution records
  • Incident and risk escalation channels with response expectations
  • Policy-change notices and employee acknowledgements

Common gaps

  • Control owners learn about architecture changes only when audit evidence is requested
  • Security concerns are posted in chat but have no tracked escalation path

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC2.1This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Communicates Information Internally applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — identify information needed by control owners and operators — with evidence stored where auditors and customers can sample it.

Lead with internal control dashboard and distribution records and pair it with incident and risk escalation channels with response expectations. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because control owners learn about architecture changes only when audit evidence is requested Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above