Skip to content
Ridgeline Compliance
Read this first. We are not a CPA firm, so we provide SOC 2 readiness, gap analysis and preparation consulting only. The formal SOC 2 examination and report are performed by a separate, licensed, independent CPA firm.

Guide

The SOC 2 internal audit, before the CPA firm arrives

A SOC 2 internal audit tests your controls the way the CPA firm will, but earlier. So exceptions surface while there is still time to fix them quietly.

  • Readiness, not the audit
  • An independent CPA firm signs
  • Written estimate, no call
Soc 2 internal audit: plan the review, sample and test and fix and record

What a SOC 2 internal audit is

It is an internal review of controls against your own SOC 2 control set. However, it is not the examination, and it produces no report for customers.

The criteria also expect monitoring activities. Therefore a periodic internal review supports the controls as well as preparing for fieldwork.

Who runs a SOC 2 internal audit

Independence matters. So the reviewer should not test controls they operate themselves.

OptionNote
Internal audit or risk teamIndependent, if one exists
A peer from another teamWorkable for small companies
Outside readiness consultantKnows what CPA firms sample

SOC 2 internal audit readiness check

Tick what you have done this year.

Your result appears here as you tick, so you can see what is still open.

What a SOC 2 internal audit should test

Mirror the CPA firm's approach. For example, pick samples from the period, not the best examples.

  • Access reviews and leaver removals
  • Change approvals in the code repository
  • Vendor reviews
  • Incident records
  • Backup restore tests

Turning the review into evidence

Record what you sampled, what you found and how you fixed it. Also keep dates, because a Type II report covers a period. As a result, the review becomes part of your monitoring evidence.

In addition, share results with leadership. The criteria expect oversight, so a short summary helps.

How Ridgeline helps

We run readiness reviews that mirror CPA firm sampling, then help fix what we find. Readiness sits inside our fixed fee of $5,000 to $40,000. We are not a CPA firm, so we prepare and a licensed firm examines. The criteria are in the AICPA Trust Services Criteria.

SOC 2 internal audit questions

Is a SOC 2 internal audit required?

Not as a separate report. However, monitoring is part of the criteria, and a review supports it.

When should a SOC 2 internal audit happen?

Before fieldwork, early enough to fix issues and show the fix operating.

Can a SOC 2 internal audit replace the CPA firm?

No. Only a licensed CPA firm issues a SOC 2 report.

How large should samples be?

Large enough to be representative, chosen across the whole period.

Related guides

Plan your SOC 2 internal audit

Answer four scoping questions. We reply in writing with a scope and a price range, usually the same working day. Also tell us your planned fieldwork date, because timing decides how much fixed evidence can build up. So the review lands when it helps most.

See if we can help