CC4.2
Evaluates and Communicates Deficiencies
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Assess control deficiencies, communicate them promptly to responsible parties and oversight bodies, and track corrective action.
Points of focus
- Evaluate severity and aggregate related deficiencies
- Communicate issues to people able to remediate and oversee
- Monitor corrective actions until verified closure
Implementation notes
Centralize audit, incident, monitoring, and customer-reported deficiencies in one workflow; set severity-based escalation clocks and require independent retest evidence before closure. Operationalize evaluate severity and aggregate related deficiencies in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain deficiency register with severity, owner, due date, and status with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that audit findings are closed when a ticket is merged without retesting production behavior Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample deficiency register with severity, owner, due date, and status with dates and named reviewers. Be ready to walk through how you detect and correct: audit findings are closed when a ticket is merged without retesting production behavior
Evidence auditors typically request:
- Deficiency register with severity, owner, due date, and status
- Escalation records to executives or the board
- Retest evidence confirming remediation effectiveness
Common gaps
- Audit findings are closed when a ticket is merged without retesting production behavior
- Repeated low-rated exceptions are never aggregated into a systemic deficiency
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC4.2 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus