SOC 1 (SSAE 18 / ISAE 3402)
Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

SOC 1 (SSAE 18 / ISAE 3402) C.4: SOC 1 C.4 Deviations investigated, explained and remediated, with fraud and noncompliance assessed for their effect

Where the auditor's tests find deviations the service organisation supplies the nature and cause, the expected rate and the compensating or other controls, so that the auditor can decide whether the testing still supports effective operation, whether more testing is needed or whether the control failed; deviations resulting from fraud, and any breach of law, fraud or uncorrected misstatement for which the organisation is responsible and which could affect user entities, are assessed for their effect on the assertion, the description, the objectives and the report, and all deviations are reported in the tests and results even where the objective is concluded achieved.

Maintained by Gerard BlokdykControl text last updated

Other controls in Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.