CC2.3
Communicates Quality Information
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Communicate complete, accurate, timely information about system objectives, responsibilities, and performance to internal and external stakeholders.
Points of focus
- Define what information recipients need to make decisions
- Check information for completeness, accuracy, and timeliness
- Tailor communication to responsibilities and system commitments
Implementation notes
Give control metrics documented definitions, source queries, scope, owners, and freshness checks; version customer-facing reports and correct material inaccuracies through the same governed communication channel. Operationalize define what information recipients need to make decisions in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain data-quality checks for control and service reporting with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a security metric excludes subsidiaries or environments without disclosure Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample data-quality checks for control and service reporting with dates and named reviewers. Be ready to walk through how you detect and correct: a security metric excludes subsidiaries or environments without disclosure
Evidence auditors typically request:
- Data-quality checks for control and service reporting
- Owner-reviewed KPI definitions and dashboard lineage
- Corrected communications and root-cause records for reporting errors
Common gaps
- A security metric excludes subsidiaries or environments without disclosure
- Customer reports use stale data because dashboard refresh failures are not monitored
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC2.3 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus