Skip to content
compliancebase
SOC 2CC5 — Policies and Procedures

CC5.3

Policies and Procedures

SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026

Objective

Deploy control activities through policies that set expectations and procedures that translate those expectations into repeatable action.

Points of focus

  • Document responsibilities and expected conduct in policies
  • Create procedures that are specific enough for consistent execution
  • Review and update documentation as operations evolve

Implementation notes

Keep policy concise and link each requirement to an operational runbook, workflow, or configuration; test procedures with the people who perform them and revise them after incidents or tooling changes. Operationalize document responsibilities and expected conduct in policies in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved policies with owners, versions, and review dates with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a policy mandates review but no procedure defines reviewer, population, or evidence Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample approved policies with owners, versions, and review dates with dates and named reviewers. Be ready to walk through how you detect and correct: a policy mandates review but no procedure defines reviewer, population, or evidence

Evidence auditors typically request:

  • Approved policies with owners, versions, and review dates
  • Runbooks linked to policy requirements
  • Samples showing personnel followed current procedures

Common gaps

  • A policy mandates review but no procedure defines reviewer, population, or evidence
  • Runbooks describe an obsolete deployment path after platform changes

Cross-Framework Mapping

FrameworkRequirementImplementation note
SOC 2CC5.3This control
ISO 27001A.5.1, A.5.2Organizational controls provide related governance evidence but are not equivalent criteria.
HIPAA164.308(a)(1)HIPAA administrative safeguards overlap where ePHI systems are in scope.
GDPRArticle 32GDPR accountability and security duties can reuse evidence when personal data is in scope.

Primary sources

Frequently Asked Questions

Policies and Procedures applies to the systems and commitments in your Trust Services Criteria scope. Translate the requirement into concrete operating workflows — document responsibilities and expected conduct in policies — with evidence stored where auditors and customers can sample it.

Lead with approved policies with owners, versions, and review dates and pair it with runbooks linked to policy requirements. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a policy mandates review but no procedure defines reviewer, population, or evidence Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • SOC 22017 TSC (2022 Revised Points of Focus)

Last verified: August 2026 · Primary sources linked above