SOC 2 Type II policy template
Review this template's scope and control areas. Then, open it in the Verdictan console to adapt and test the configuration for your environment.
Prepare a control map for a SOC 2 Type II examination across a review period. The starter references the AICPA Trust Services Criteria and adds evidence fields for retention, change control, risk assessment, monitoring and AI security. It does not establish operating effectiveness or provide an audit opinion.
Use this template as a starting configuration and control map. It does not provide certification, legal advice or a compliance guarantee. Confirm your obligations, adapt the configuration and test every outcome before deployment.
Global
3 source references
8 mapped control areas
Regulated SaaS, Private cloud
Source frameworks, standards and obligations
Control areas mapped by this template
Deployment options
Adapt the template in three steps
Review the scope
Confirm that the regions, source references, control areas and deployment options fit your use case.
Adapt the configuration
Open the template in the Verdictan console. Set its policies, thresholds, routing and review requirements for your environment.
Test before deployment
Test each policy outcome. Confirm that allowed, redacted, blocked and reviewed requests behave as expected.
Explore more Compliance & Audit templates
SOC 2 Type I
Map point-in-time control design to the AICPA Trust Services Criteria with this SOC 2 starter.
ISO/IEC 27001
Map information security management, supplier, continuity and cloud privacy controls to ISO/IEC 27001.
ISO/IEC 42001
Map AI management, risk treatment, human oversight and data quality controls to ISO/IEC 42001.