How should my team answer questions in an auditor interview?
During CMMC and SOC 2 auditor interviews, teams must provide honest, factual, and concise answers directly related to their roles and responsibilities. Focus on demonstrating adherence to documented policies and procedures, supported by verifiable evidence. Avoid speculation or offering information outside your direct knowledge to maintain credibility and ensure the assessment accurately reflects the organisation's control environment.
Practitioners should prepare by reviewing relevant policies, procedures, and evidence before an interview. Understand the specific control or practice being discussed and how your role contributes to its implementation. Auditors are assessing whether the organisation 'says what it does, does what it says, and can prove it.' Therefore, answers should directly address the auditor's question, referencing documented processes and demonstrating practical application. Avoid guessing or speculating on areas outside your direct expertise; instead, offer to find the correct individual or documentation.
When an auditor asks a question for which you do not have direct knowledge, it is acceptable and professional to state, 'I do not know, but I can find that information for you' or 'That falls under [colleague's name/department's] responsibility.' Ensure consistency in responses across the team by adhering to established organisational narratives and documented evidence. Always be prepared to provide supporting documentation or demonstrate a process in real-time if requested, as this strengthens the credibility of verbal statements and is a key component of evidence collection for both CMMC and SOC 2 assessments.
Sources
- CMMC Assessment Process (CAP) Guide, Version 2.0, Section 3.2.1 (Assessment Methods: Examine, Interview, Test)
- AICPA Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy (2017), Common Criteria (CC1.1, CC2.1, CC3.1)