CC5.3
Policies and Procedures
SOC 2 · 2017 TSC (2022 Revised Points of Focus) · Last verified August 2026
Objective
Deploy control activities through policies that set expectations and procedures that translate those expectations into repeatable action.
Points of focus
- Document responsibilities and expected conduct in policies
- Create procedures that are specific enough for consistent execution
- Review and update documentation as operations evolve
Implementation notes
Keep policy concise and link each requirement to an operational runbook, workflow, or configuration; test procedures with the people who perform them and revise them after incidents or tooling changes. Operationalize document responsibilities and expected conduct in policies in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain approved policies with owners, versions, and review dates with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a policy mandates review but no procedure defines reviewer, population, or evidence Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample approved policies with owners, versions, and review dates with dates and named reviewers. Be ready to walk through how you detect and correct: a policy mandates review but no procedure defines reviewer, population, or evidence
Evidence auditors typically request:
- Approved policies with owners, versions, and review dates
- Runbooks linked to policy requirements
- Samples showing personnel followed current procedures
Common gaps
- A policy mandates review but no procedure defines reviewer, population, or evidence
- Runbooks describe an obsolete deployment path after platform changes
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| SOC 2 | CC5.3 | This control |
| ISO 27001 | A.5.1, A.5.2 | Organizational controls provide related governance evidence but are not equivalent criteria. |
| HIPAA | 164.308(a)(1) | HIPAA administrative safeguards overlap where ePHI systems are in scope. |
| GDPR | Article 32 | GDPR accountability and security duties can reuse evidence when personal data is in scope. |
Primary sources
- AICPA Trust Services Criteria: AICPA TSP Section 100 — 2017 Trust Services Criteria with 2022 Revised Points of Focus