Zum Hauptinhalt springen
DocumentMS

Compliance

SOC 2 document management controls

SOC 2 is an attestation report describing how a service organisation meets the AICPA trust services criteria for security, availability, processing integrity, confidentiality and privacy. For a document management system it evidences access control, change management, monitoring and incident response over a defined observation period.

What a SOC 2 report actually is

SOC 2 is an attestation report produced by an independent accounting firm, describing how a service organisation meets the AICPA trust services criteria. It is not a certification and there is no pass mark — the report describes controls, tests them, and records any exceptions found. Reading the exceptions is the point; a buyer who only checks that a report exists has not used it.

Type I describes controls at a point in time. Type II tests whether they operated over a period, usually six or twelve months, and it is the one enterprise buyers ask for. A Type I report is a reasonable interim answer for a younger company and should be described as such rather than presented as equivalent.

Five trust services criteria exist: security, availability, processing integrity, confidentiality and privacy. Security is common to every report; the others are included by choice. A report covering security alone is normal, and a vendor should tell you which criteria are in scope rather than letting you assume all five.

What each criterion means for a document system

Why a buyer of document management should care about each, rather than the abstract definition.
Trust services criteria applied to document management
CriterionWhat it coversWhy it matters here
SecurityProtection against unauthorised access, disclosure and damageThe baseline. Covers access control, authentication, change management, monitoring and incident response — the controls that decide whether your documents stay yours.
AvailabilityThe system is available for operation and use as committedRelevant if you have an uptime commitment or if document retrieval is time-critical, such as answering a statutory disclosure deadline.
Processing integrityProcessing is complete, valid, accurate, timely and authorisedRelevant where documents are generated or transformed — OCR, template generation, AI extraction — and the output is relied upon.
ConfidentialityInformation designated confidential is protected as committedDirectly relevant. Most document repositories hold material that is confidential by contract as well as by policy.
PrivacyPersonal information is collected, used, retained and disposed of as committedRelevant where documents contain personal data, which for HR, healthcare, legal and education is almost all of them.

How to read a SOC 2 report properly

Most reports are received, filed and never opened. These are the parts worth an hour of someone’s time.
  • Section IV, the testing detail — this is where exceptions are recorded, and exceptions are the informative part of any report
  • The observation period, and whether it is current. A report covering a period that ended fourteen months ago tells you about a system that has since changed
  • The scope statement: which systems and which criteria are covered, and equally which are not
  • Complementary user entity controls — the things the report assumes you do. These are obligations transferred to you, and they are routinely ignored
  • Sub-service organisations, and whether they are carved out or included. A carve-out means their controls are not tested in this report
  • The auditor’s opinion: unqualified, qualified, adverse or disclaimer. A qualified opinion is not disqualifying but requires an explanation

FAQ

SOC 2 questions

Can we see your SOC 2 report?

No Type II report has been issued yet, so there is nothing to send and we will not imply otherwise. What we do share under a mutual NDA is the control matrix mapped to the Security and Confidentiality criteria, our most recent penetration test summary, and a completed CAIQ or your own questionnaire. Ask your account contact and the pack goes out within 2 business days.

Do you have a bridge letter?

Not applicable while no Type II report exists — a bridge letter covers the gap between a report’s observation window and the present, so there is no gap to bridge yet. Once a report is issued we will provide a bridge letter on request, which is the standard ask in any procurement running more than a few months after the report date.

Is SOC 2 better than ISO 27001?

They answer different questions. ISO 27001 certifies that a management system exists and is being run; SOC 2 describes and tests specific controls over a period and reports the exceptions. Many organisations require both. If you can only ask for one, ask for the one your own auditors understand best.

What if you do not have a report yet?

Then a credible answer is a stated intention with a date, plus evidence of the underlying controls — access reviews, change management records, incident response procedure, penetration test summary. Those are the substance a SOC 2 report describes, and a young vendor can show them directly.

Tell us which criteria your reviewers care about and we will tell you plainly what we can and cannot supply today.