SOC 2: awareness, training & the human layer of your controls

If you sell software or services to enterprises — especially in fintech, SaaS or outsourcing — sooner or later a customer's procurement team asks for your SOC 2 report. SOC 2 examinations are performed by a CPA firm against the AICPA Trust Services Criteria, and a meaningful slice of those criteria is about people: whether your staff are competent, informed of their security responsibilities, and demonstrably operating your policies. This page explains where the human layer sits in the criteria, and how AfriPhish produces the evidence your auditor will sample.

What the Trust Services Criteria require of your people

CC1 — the control environment. The CC1 series adapts the COSO principles: the organisation demonstrates a commitment to integrity and ethical values, and holds individuals accountable for their internal control responsibilities. Most directly, CC1.4 requires a demonstrated commitment to competence — attracting, developing and retaining competent individuals in alignment with objectives. "Developing" is the operative word: auditors expect a training programme with records, not a hiring filter alone.

CC2.2 — internal communication. The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control. In practice this is where security awareness lives in a SOC 2 examination: staff must know the security policies that apply to them, their own responsibilities under those policies, and how to report failures, incidents and concerns. New hires are a classic test point — was security communicated to them at onboarding, and can you prove it?

CC2.3 — communication with external parties. Contractors, vendors and other external users of your systems also need to be informed of their security responsibilities. If contractors touch production or customer data, your awareness and policy-acknowledgement evidence has to cover them too — a gap auditors find often.

Personnel policies in practice. Across the criteria, auditors expect the standard personnel controls to operate: an information security policy and acceptable-use rules that staff acknowledge at hire and periodically thereafter, security awareness training on a defined cadence, and sanctions or follow-up when people do not comply.

The Type II reality: evidence is sampled across the whole period. A Type I report assesses design at a point in time; a Type II report tests operating effectiveness over a period, typically many months. The auditor selects samples — new hires from March, leavers from July, the annual training population — and asks for the record in each case. A control that operated "mostly" produces exceptions in the report your customers read. Continuous, automatically captured evidence is what keeps a Type II clean.

The criteria AfriPhish helps you evidence

Trust Services criterionAfriPhish moduleEvidence produced
CC1.4 — commitment to competenceRole-aware training library, incl. a dedicated IT/SecOps trackPer-user completion records, quiz scores, assignment dates
CC2.2 — internal communication of responsibilitiesAwareness training + policy distributionCompletion logs tied to named policies and versions
CC2.3 — external users informedTraining and policy assignment covering contractorsAcknowledgement and completion records for non-employees
Policy acknowledgement at hire and periodicallyPolicy management with e-signature attestationVersioned, timestamped signature registers per person
Awareness effectiveness verifiedPhishing simulations across realistic scenario familiesClick, credential-submission and report rates per campaign
Operation across the audit periodScheduled campaigns and training seriesA dated, continuous activity history for any period

Because every event is timestamped in one data model, period-scoped sampling is painless: pick any month in the audit window and the completion, acknowledgement and simulation records for that month are already there.

What SOC 2 auditors typically request

Fieldwork requests for the human layer are highly predictable. Expect:

  • A population of hires during the period, and for a sample of them, evidence each completed security awareness training within your stated onboarding window.
  • Annual training completion logs for the full workforce, with follow-up evidence for anyone who missed the deadline.
  • Policy acknowledgement registers — signatures against the current version of the information security and acceptable-use policies, for employees and in-scope contractors.
  • Phishing test results — an increasingly standard request, as simulations are the cheapest way for an auditor to corroborate that awareness controls actually operate.
  • Evidence of communication channels — how staff are told about incidents, changes to policy, and how to report concerns.
  • Exception handling — what happened when someone failed the training deadline or repeatedly clicked; auditors look for the loop to close.

All of the above export directly from AfriPhish, scoped to your examination period.

See where your organisation stands

Before your readiness assessment — or your first Type II window opens — gap-check the human layer. Take the free 4-minute Human Risk Maturity Assessment: it benchmarks your programme against what CC1.4 and CC2.2 evidence requests actually look like, and highlights where an auditor would raise an exception.

Working with a CPA firm or a readiness consultant? Book a demo and we will show you the exact exports that answer a SOC 2 evidence request list.