ITGC evidence pack for SOC 1 audit
Scenario
KaizenMotors' external auditor arrives in 4 weeks for the annual SOC 1 audit. You need to prepare the ITGC evidence pack covering the 4 ITGC domains: (1) Access, (2) Change Management, (3) Computer Operations, (4) IT Governance.
Your role
You are preparing evidence for the SOC 1 audit.
Your task
Produce an evidence pack index: 1. For each of the 4 ITGC domains, list 5-8 evidence artifacts 2. Owner + collection method per artifact 3. As-of date / period covered per artifact 4. Cross-reference to relevant SOC 1 control objective 5. 'Known deficiencies' pre-emptive summary (top 3 things the auditor will find)
Deliverable format: Evidence pack index ~700-1000 words
Toolkit
- SOC 1 audit period: usually 12 months + 3 months look-back
- Common evidence gaps: missing terminated-employee access removal tickets, undocumented emergency changes, outdated DR test evidence
- Pre-emptive deficiency disclosure = shows control maturity (auditors love this)
- Cross-reference format: '5.2.3' style, tie to control objective number
Success criteria (what the AI grades against)
- All 4 domains covered with distinct evidence per domain
- 'Known deficiencies' section shows judgment (not zero, not 20)
- As-of vs period-covered dates correctly assigned
- Ownership realistic (spread across CISO, IT Ops, HR, Finance)
- Includes DR test evidence (often forgotten)
Log in to submit your deliverable for AI review.
Log in / Register