CC4.1
Conducts Ongoing and Separate Evaluations
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Use ongoing monitoring and appropriately scoped separate evaluations to determine whether internal-control components are present and functioning.
Points of focus
- Combine continuous monitoring with periodic independent evaluation
- Adjust evaluation scope and frequency based on risk and change
- Use knowledgeable evaluators and objective evidence
Implementation notes
Continuously monitor high-signal configurations such as MFA, public storage, logging, and backup jobs, then supplement automation with periodic human sample testing that is independent of daily operation. Operationalize combine continuous monitoring with periodic independent evaluation in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain automated control-monitoring alerts and resolution history with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that dashboards report configuration state but nobody investigates failed checks Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample automated control-monitoring alerts and resolution history with dates and named reviewers. Be ready to walk through how you detect and correct: dashboards report configuration state but nobody investigates failed checks
Evidence auditors typically request:
- Automated control-monitoring alerts and resolution history
- Internal audit or independent assessment plans and reports
- Control test samples covering the review period
Common gaps
- Dashboards report configuration state but nobody investigates failed checks
- The same control owner designs, operates, and independently evaluates the control
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC4.1 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus