Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

ComplianceFree Safe

soc2-audit-prep

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when preparing a SOC 2 Type II audit: scoping, mid-observation checkpoints, month-10 pre-field-test readiness, scope changes, or post-incident review mid-cycle.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: soc2-audit-prep
description: Use when preparing a SOC 2 Type II audit: scoping, mid-observation checkpoints, month-10 pre-field-test readiness, scope changes, or post-incident review mid-cycle.
category: Compliance
version: 1.0.0
tools: []
---

# SOC 2 Type II Audit Prep — Six Forcing Questions

Pressure-test any SOC 2 work with six observation-period-disciplined questions before a Type II cycle.

## When to Run

- Pre-observation period (months 1-2 of the cycle)
- Mid-observation period (month 6 checkpoint)
- Pre-field-test (month 10)
- Post-report (planning the next cycle)
- After a scope change (adding a TSC category)
- After a major incident during the observation period

## The Six SOC 2 Type II Questions

### 1. What's the scope, and which TSC categories are in?
Security is always required under the Common Criteria (CC1-CC9); the rest are elective based on customer ask: Availability (A1) for SaaS with SLA commitments, Processing Integrity (PI1) for transactional/financial data, Confidentiality (C1) for proprietary/confidential data, Privacy (P1-P8) for personal data (overlaps GDPR). The AICPA AT-C 205 description of system must be complete, accurate, with clear boundaries.

### 2. Did any control skip a cycle during the observation period?
Type II requires consistent operation — a single skipped cycle is likely an exception. Quarterly controls (e.g., access reviews) need all 4 quarters covered; monthly controls (e.g., vulnerability scans) need every month covered; continuous controls (e.g., logging) need no gaps; annual controls (e.g., BCP exercises, training) must complete within the period.

### 3. Show the change-management evidence for any control implemented mid-period.
Mid-period changes are high audit risk. New controls implemented during observation need documented change-management; modified controls need rationale, effective date, and impact on prior samples; removed controls need rationale and customer-impact assessment. Strategy: avoid mid-period changes and defer to the next cycle.

### 4. Where's the exception log, and what's the materiality assessment?
Exceptions must be logged in real time, not retroactively — for each: what, when, impact, remediation, owner. Assess whether the exception affects overall control operation. Audit-firm threshold is typically 1-2 exceptions per control acceptable; 3+ is a finding.

### 5. Show sample evidence from each TSC criterion in the first month of observation, not the last week.
Audit firms sample across the full observation period. Front-loaded evidence demonstrates operational discipline; evidence concentrated in the last 30 days signals scrambling. Sample IDs should be reproducible from operational systems.

### 6. What's the cross-walk to ISO 27001, and which evidence reuses?
The canonical pair, with roughly 75% control overlap. Map HIGH-confidence overlap themes so each shared artefact is cited by both audits from one collection. Coordinate the audit calendar with the ISO 27001 auditor and avoid producing duplicate evidence files for the same control.

## Method

Run scoping and gap analysis before the observation period starts, build a control matrix with the ISO 27001 cross-walk, track evidence continuously through the 12-month period, and run a mock audit before the month-10 field test.

## Output

Produce a readiness report covering: the decision being made (scoping / pre-observation / observation-status / pre-field / report-response); TSC scope (Security, Availability, Processing Integrity, Confidentiality, Privacy — included or not); observation period status (months elapsed of 12, % controls operated consistently, cycle skips, mid-period changes and whether each has change-mgmt documentation); exception log (total exceptions, per-control max against the 1-2 tolerance, material exceptions, remediation status); sample evidence coverage by quarter (months 1-3, 4-6, 7-9, 10-12); ISO 27001 cross-walk reuse (HIGH-confidence overlap themes, shared artefacts, % duplicate-evidence savings); and audit-firm readiness (scoping discussion, AT-C 205 description of system, walkthrough rehearsal, sample preparation). Close with a verdict — ON-TRACK, NEEDS-ATTENTION, or MATERIAL-RISK — and the top 3 actions with owner and observation-period timing.

## Routing

Escalate to a multi-framework compliance-readiness view, an ISO 27001 audit prep for the 75%-overlap cross-walk, a GDPR audit for Privacy TSC overlap, or an executive cybersecurity strategy review.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/soc2-audit-prep/SKILL.md

Open Source Link
Compliance

Related Skills