SOC 2 Type 2 Evidence
A Professional and Enterprise module for tracking AICPA Trust Services Criteria (TSC) across your SOC 2 Type 2 audit period. Pre-mapped to RAIC's existing AI governance registers — policies, risks, incidents, suppliers, monitoring — so most evidence assembles itself.
Enabling the module
- An OrgAdmin opens
Admin → Org Settingsand toggles Enable SOC 2 Type 2 Evidence. - The 61-row TSC catalog is seeded automatically on first enable.
- A new SOC 2 Type 2 Evidence entry appears in the sidebar under Regulatory Frameworks at
/governance/soc2.
The module is triple-gated: tier (Pro/Ent) + per-org toggle + (optional) platform feature flag. Disabling the toggle hides the module without deleting any data.
Trust Services Criteria catalog
The canonical 61-row catalog covers:
- Common Criteria (CC1–CC9) — 33 rows (control environment, communication, risk, monitoring, control activities, logical/physical access, system operations, change management, risk mitigation).
- Availability (A1) — 3 rows.
- Confidentiality (C1) — 2 rows.
- Processing Integrity (PI1) — 5 rows.
- Privacy (P1–P8) — 18 rows.
Each row carries status (not_started, in_progress, met, not_met, na), owner, last-reviewed date, and free-text notes.
Evidence & backfill
Per-control evidence uploads use server-side SHA-256 hashing with the canonical 5-minute signed-URL download chokepoint. The one-click Backfill panel auto-links existing RAIC artifacts — policies, risks, incidents, suppliers, monitoring plans, attestations — to the 28 mappable TSCs so OrgAdmins start the audit with most evidence already attached.
The Evidence Pack panel assembles approved evidence into a branded ZIP for the external auditor, mirroring the Recertification Pack and Trust Portal evidence patterns.
Exports
CSV and branded DOCX exports follow the canonical filename convention RhindonCyber_SOC2-ControlRegister_<slug>_<YYYY-MM-DD>. MSP-managed tenants with the White-Label add-on inherit the partner firm's branding automatically through the platform's white-label canonicals (e.g. AcmeCyberCo_SOC2-…).
Audit trail
Every action emits an audit code to both the org Activity Log and the Platform Audit Log under the soc2 family, including:
- SOC2_MODULE_TOGGLED
- SOC2_CONTROL_STATUS_CHANGED
- SOC2_EVIDENCE_UPLOADED / _DOWNLOADED / _DELETED
- SOC2_EVIDENCE_LINKED / _UNLINKED
- SOC2_BACKFILL_RUN
- SOC2_EVIDENCE_PACK_BUILT / _DOWNLOADED
- SOC2_REGISTER_EXPORTED
