SOC 2 for identity: the controls that actually matter
What auditors test in identity
SOC 2 isn't prescriptive, it tests controls you've defined against the Trust Services Criteria. For identity, the controls auditors expect to find are:
- Access provisioning tied to a documented process (HR ticket or workflow)
- Access reviews on a defined cadence (typically quarterly for sensitive systems)
- Deprovisioning that completes within a defined window (often 24 hours for terminations)
- MFA enforcement on all production systems and admin accounts
- Privileged access controls with logging
- Logical access logs retained for the audit period
Evidence the audit needs
- Provisioning tickets with approval trail
- Access review records with reviewer attestation
- Deprovisioning logs showing time-to-revoke for sample terminations
- MFA enforcement evidence (config screenshots, policy exports)
- Sample audit log entries for privileged actions
- Background check records for new hires (if your controls include them)
Vendor capabilities that pay off at audit
SCIM provisioning with audit trail. Access certification campaigns built into the IGA tool. Reports of "who has access to what" exportable on demand. Audit log retention configurable to match audit period. MFA enforcement reports per app and per user.
Common pitfalls
- "Manual deprovisioning checklist" as a control, auditors find the misses
- Access reviews done in a spreadsheet, not in the IGA tool
- MFA exceptions for executives that are never documented
- Audit logs that exist but can't be exported in a usable format
- Production access by engineers without ticket-tied approval
The pragmatic path
If you're pre-SOC 2 and want to build for it without overengineering:
- Pick an IdP and IGA combination (or all-in-one) that can produce the evidence above
- Wire HR-driven joiner/leaver flows from day one
- Run a quarterly access review even when you have 20 employees
- Document your controls in a single page; refine over time
The Type 1 audit tests design. The Type 2 audit tests that you actually did the thing for 6-12 months. The latter is what tells you whether your controls hold up.
Related on Start with Identity
- ArticleIAM Metrics and KPIs That Actually Matter
A practical guide to IAM metrics and KPIs, which ones to track, how to build dashboards, and how to report IAM value to leadership with operational and strategi
- GuideGDPR for identity systems: what the regulation actually requires
GDPR confers user rights (access, rectification, erasure, portability, object). Identity systems are usually where those requests are routed because they hold t
- GuideIAM Audit Preparation Guide: SOX, SOC 2, and HIPAA Readiness
Prepare for identity and access management audits with complete evidence collection, access review documentation, and compliance frameworks for SOX, SOC 2, and
- GuideIdentity Controls for DORA
The EU Digital Operational Resilience Act (DORA) applies to financial entities and their critical ICT providers, and it makes strong identity and access managem
- GlossarySOC 2
A report issued by an auditor against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). Type 1 is a po
- GlossaryAML
Anti-Money Laundering. The set of regulations and processes used to detect and report suspicious financial activity. AML programs sit on top of KYC and include