SOC 1 (SSAE 18 / ISAE 3402)
Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

SOC 1 (SSAE 18 / ISAE 3402) C.6: SOC 1 C.6 Internal audit reports and regulatory examination reports relating to the services made available

Where an internal audit function exists within the service organisation, its responsibilities and activities are described to the auditor, and internal audit and regulatory examination reports relating to the services and the scope are made available, because the auditor reads them, takes their findings into the risk assessment and may use internal audit work in testing, in which case the tests and results section describes that work.

Maintained by Gerard BlokdykControl text last updated

Other controls in Control objectives and controls: design, operation, deviations and change – SOC 1 (SSAE 18 / ISAE 3402)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.