Day 18 of 22ITGC · SOC 1 / SOC 2· ~60 min

ITGC evidence pack for SOC 1 audit

Scenario

KaizenMotors' external auditor arrives in 4 weeks for the annual SOC 1 audit. You need to prepare the ITGC evidence pack covering the 4 ITGC domains: (1) Access, (2) Change Management, (3) Computer Operations, (4) IT Governance.

Your role

You are preparing evidence for the SOC 1 audit.

Your task

Produce an evidence pack index: 1. For each of the 4 ITGC domains, list 5-8 evidence artifacts 2. Owner + collection method per artifact 3. As-of date / period covered per artifact 4. Cross-reference to relevant SOC 1 control objective 5. 'Known deficiencies' pre-emptive summary (top 3 things the auditor will find)

Deliverable format: Evidence pack index ~700-1000 words

Toolkit

  • SOC 1 audit period: usually 12 months + 3 months look-back
  • Common evidence gaps: missing terminated-employee access removal tickets, undocumented emergency changes, outdated DR test evidence
  • Pre-emptive deficiency disclosure = shows control maturity (auditors love this)
  • Cross-reference format: '5.2.3' style, tie to control objective number

Success criteria (what the AI grades against)

  • All 4 domains covered with distinct evidence per domain
  • 'Known deficiencies' section shows judgment (not zero, not 20)
  • As-of vs period-covered dates correctly assigned
  • Ownership realistic (spread across CISO, IT Ops, HR, Finance)
  • Includes DR test evidence (often forgotten)

Log in to submit your deliverable for AI review.

Log in / Register