SOC 2 Audit Evidence Evaluation Checklist
Use this checklist to assess and document the adequacy, quality, and coverage of audit evidence for SOC 2 audits.
Evidence Item Name or Reference
*
Describe the Evidence and Its Source
*
Which SOC 2 Trust Services Criteria are covered by this evidence?
*
Security
Availability
Processing Integrity
Confidentiality
Privacy
Type of Evidence
*
Document
System Configuration
Log File
Screenshot
Interview/Observation
Other
How would you rate the quality of this evidence?
*
1
2
3
4
5
Coverage and Gaps Evaluation
*
Rows
Fully Sufficient
Partially Sufficient
Insufficient
Not Applicable
Control Design
1
2
3
4
Control Operation
5
6
7
8
Period Coverage
9
10
11
12
Are there any gaps or issues identified with this evidence?
*
No gaps identified
Minor gaps (do not impact conclusion)
Significant gaps (may impact conclusion)
If gaps or issues were identified, please describe them
Overall Evaluation Outcome
*
Acceptable – evidence supports control
Acceptable with minor reservations
Not acceptable – further evidence required
Additional Reviewer Comments (optional)
Submit Evaluation
Should be Empty: