SOC 2 Trust Services Criteria

SOC 2 Processing Integrity Criterion

Processing integrity means system processing is complete, accurate, timely, and authorised. It is most relevant for organisations that process data on behalf of others (payment processors, data processors).

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILSOC 2 Processing Integrity EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Common control areas

Input validation and processing

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Output verification

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Error handling

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Reconciliation procedures

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Data quality checks

Define the owner, operating process, sample evidence, exception handling, and review cadence before the audit period starts.

Evidence to keep

  • Control owner and review cadence
  • Policy or procedure approved by management
  • System export, ticket, report, or log sample
  • Exception record and remediation evidence

Processing Integrity policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Back to all SOC 2 criteria, or open the SOC 2 template pack.