The SOC 2 Audit Checklist
The policies you need in writing, the evidence types an auditor will actually sample, and the mistakes that turn a routine audit day into a stressful one.
Schedule a Consultation →Policies You Need in Writing
Auditors expect these as living documents with a named owner and a review date, not a one-time template download.
Evidence Types Auditors Actually Sample
A policy states intent. Evidence proves the control ran. Type II auditors sample the latter, drawn from real dates inside the observation window.
Common Audit-Day Pitfalls
The policy exists, but nobody followed it
A beautifully written access-review policy with zero completed reviews on file is worse than no policy — it proves the control was known and skipped, not merely undocumented.
Evidence assembled retroactively
Type II evidence has to be generated during the observation window as a byproduct of real operations. Backdating a spreadsheet the week before fieldwork is exactly the kind of exception auditors are trained to catch.
Offboarding lag
A terminated employee whose access wasn’t revoked for days or weeks is one of the single most common exceptions auditors find, because it’s easy to check and easy to miss operationally.
Nobody owns the evidence trail
If no single person is responsible for collecting and organizing evidence as it’s generated, audit-day scrambling to reconstruct six months of history is the predictable result.
Scope creep mid-engagement
New systems, new vendors, or a new product line added after the observation window opens without updating the control inventory creates an evidence gap for anything added late.
Treating SOC 2 as a one-time project
Controls that run hard for the observation window and lapse right after produce a clean report and a much harder renewal audit next year.
Most of these gaps surface earliest in a SOC 2 readiness assessment — well before an auditor is in the room. See how that process works.
Don’t Let Audit Day Be the First Time You Find Out
Armorstack builds the evidence trail into daily operations, so audit day is a formality instead of a fire drill.