Skip to content
compliancebase
SOC 2CC4 — Conducts Ongoing and Separate Evaluations

CC4.1

Conducts Ongoing and Separate Evaluations

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Use ongoing monitoring and appropriately scoped separate evaluations to determine whether internal-control components are present and functioning.

Points of focus

  • Combine continuous monitoring with periodic independent evaluation
  • Adjust evaluation scope and frequency based on risk and change
  • Use knowledgeable evaluators and objective evidence

Implementation notes

Continuously monitor high-signal configurations such as MFA, public storage, logging, and backup jobs, then supplement automation with periodic human sample testing that is independent of daily operation. Operationalize combine continuous monitoring with periodic independent evaluation in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain automated control-monitoring alerts and resolution history with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that dashboards report configuration state but nobody investigates failed checks Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample automated control-monitoring alerts and resolution history with dates and named reviewers. Be ready to walk through how you detect and correct: dashboards report configuration state but nobody investigates failed checks

Evidence auditors typically request:

  • Automated control-monitoring alerts and resolution history
  • Internal audit or independent assessment plans and reports
  • Control test samples covering the review period

Common gaps

  • Dashboards report configuration state but nobody investigates failed checks
  • The same control owner designs, operates, and independently evaluates the control

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC4.1This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Conducts Ongoing and Separate Evaluations applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — combine continuous monitoring with periodic independent evaluation — with evidence stored where auditors and customers can sample it.

Lead with automated control-monitoring alerts and resolution history and pair it with internal audit or independent assessment plans and reports. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because dashboards report configuration state but nobody investigates failed checks Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above