CC3.4
Identifies and Analyzes Significant Change
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Identify and assess changes in the business, technology, leadership, or external environment that could materially affect internal control.
Points of focus
- Monitor external, business-model, and leadership changes
- Assess major technology and architecture changes before release
- Update controls and risk responses when change invalidates assumptions
Implementation notes
Add a control-impact checkpoint to architecture decisions, acquisitions, regional launches, and major vendor changes; explicitly test whether access, logging, backup, and evidence pipelines still operate afterward. Operationalize monitor external, business-model, and leadership changes in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain change-risk assessments for acquisitions, migrations, or major features with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a cloud migration preserves feature behavior but drops established logging coverage Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample change-risk assessments for acquisitions, migrations, or major features with dates and named reviewers. Be ready to walk through how you detect and correct: a cloud migration preserves feature behavior but drops established logging coverage
Evidence auditors typically request:
- Change-risk assessments for acquisitions, migrations, or major features
- Architecture review records tied to control updates
- Regulatory and leadership change monitoring logs
Common gaps
- A cloud migration preserves feature behavior but drops established logging coverage
- A major subprocessor or executive change never triggers a control reassessment
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC3.4 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus