Which Trust Services Criteria do we actually need beyond Security?

Beyond the mandatory Security Trust Services Criteria (TSC), organisations must select additional criteria based on the nature of services provided and commitments made to customers. The optional TSCs include Availability, Processing Integrity, Confidentiality, and Privacy. The decision to include these depends on contractual obligations, the specific service offerings, and the risks associated with data handling and system operations. Each additional criterion expands the scope of the SOC 2 examination, requiring more extensive controls and evidence.

The Security TSC is foundational and mandatory for all SOC 2 reports, addressing the protection of information and systems against unauthorised access, use, disclosure, modification, or destruction. Organisations must then evaluate their service commitments and system design to determine the applicability of the other four optional TSCs. Availability is typically selected when uptime guarantees or service level agreements (SLAs) are critical to customers, such as for cloud hosting providers. Processing Integrity is relevant for services that involve complex data processing, ensuring data is complete, accurate, timely, and authorised, common in financial transaction processing or payroll services. Confidentiality is chosen when an organisation commits to protecting specific types of sensitive information, like intellectual property or trade secrets, from unauthorised disclosure. Privacy is distinct from Confidentiality and applies when an organisation collects, uses, retains, discloses, and disposes of personal identifiable information (PII) in accordance with its privacy notice and applicable privacy principles.

Practitioners frequently err by either over-scoping or under-scoping their SOC 2 reports. Over-scoping, by including unnecessary TSCs, leads to increased audit effort, cost, and potential findings for controls that are not truly material to the service. Conversely, under-scoping, by omitting relevant TSCs, can result in a report that does not adequately address customer concerns or contractual requirements, potentially diminishing its value or leading to customer dissatisfaction. The determination of which optional TSCs to include should be a deliberate process, driven by a thorough review of customer contracts, service descriptions, and an organisation's risk assessment, ensuring alignment between the report's scope and the actual service commitments and operational risks.

Sources

  • AICPA, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017)
  • AICPA, SOC 2® Reporting on an Examination of Controls Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy at a Service Organization (AT-C Section 205)

Related