SOC 2 Control Narrative Examples
Narratives in a six-part format that names the mechanism, plus the evidence register that dates every artifact before you write a word about it.
Free download · No account needed
Evidence Register
One row per artifact an auditor will look at, and the day it stops existing
The artifact, and the system it comes out of
Not "the cloud" or "our logs". The specific service whose console or API holds the record, because retention is a property of that service and not of your control.
Reconstructable, in three values
Yes at any time, for the current access list or the current configuration, which is the easy class and evidences nothing about the period. Yes within a retention window, which is the work. Or no, for a review held in a meeting with no minutes.
Retention, as documented, beside Retention (days)
The vendor's own sentence transcribed word for word, then the number your arithmetic uses. Two columns because one cannot hold both readings. A platform whose audit log runs 180 days and whose repository push events run seven has written both numbers in the same paragraph, and the small one governs your change control.
Evidence Deadline and Unrecoverable Days
The period start plus the retention window, and how much of the period that source can no longer reach as of today. Neither is a judgement. Both are subtraction, and both are available on the first day of a readiness project rather than in the week before fieldwork.
Instances held, longest gap, owner
How many instances you actually have against the population the frequency implies, and the longest stretch inside the period with none at all. A quarterly control on a twelve-month period needs four, and no amount of December produces the one that was due in March.
A Type 2 opines on operating effectiveness across a period, so an auditor samples dated instances from throughout it. Those instances live in systems whose retention was set by somebody not thinking about your audit. A cloud provider's default history covers the past 90 days of management events, and a code platform's audit log runs 180 days while it retains Git events for seven. Multiply those two facts and a change-management control has a deadline eight days into January.
So the Evidence Register carries the vendor's retention sentence transcribed word for word beside the number your arithmetic uses, because that GitHub sentence holds two figures and the small one governs pushes. From those it derives the evidence deadline, which is the period start plus the window, and the days of the period a source can no longer reach. Chat approvals get the same treatment: on the free plan you choose 90 days or one year, so an approval's lifetime was a billing decision.
Ashgrove Systems, a fictional SaaS company, mapped 34 controls to the AICPA trust services criteria and then dated the evidence on the first day rather than in the last fortnight. Twenty-one had gaps nothing would close, two had expired on 8 January, and shortening the period to 212 days cleared seven of them for nothing. It sits beside the vulnerability register an auditor samples for CC7, and the retest evidence they ask for alongside it.
What's in the pack
Evidence Register
One row per artifact, with its source system, that system's retention word for word, and the resulting deadline.
Control Register
Every control mapped to its criterion, with a frequency the sheet accepts and the population that frequency implies.
Readiness Status
Instances expected against instances held per control, with one of four responses recorded against every gap it finds.
How Evidence Expires
The arithmetic behind all of it: populations, retention windows, deadlines, and the three classes of reconstructable evidence.
Evidence Guidance
Artifact by artifact, what an auditor wants and how to capture it so it survives to fieldwork.
Control Narrative
The six-part format annotated, then one production access control written out in full, exclusions included.
Gap Remediation Note
The page that turns a gap into a decision, ruling out three of the four responses explicitly.
Worked Readiness Assessment
One first Type 2 end to end, from 34 controls to a shorter period and eleven disclosed exceptions.
How to use it
- 1
Open in River, or take it blank
Claim the pack in River and give it your period and your systems, or take the blank registers and narrative format and work through them yourself.
- 2
Fix the period, then name the systems
Where approvals, access changes, reviews and deployments actually happen. The systems are the time-sensitive part, and the control list is not.
- 3
Date every artifact
Source system, its own retention sentence, the deadline that follows, and how much of the period each source can no longer reach as of today.
- 4
Decide the gaps, then write
One of four responses per gap, including shortening the period. Narratives come last, for the controls that can still be tested.
Frequently asked questions
Is this template free?
Yes, with no account, card or email needed for the download. Edit with AI is the optional half and the one that does the arithmetic: it reads your period and your systems and returns the deadlines. The rest of the template library works the same way.
What format are the downloaded files?
The five documents come as .docx and the three registers as .csv, in one zip. That opens in Word or Google Docs and in Excel, Numbers or Sheets, with nothing to import and nothing to convert. The registers arrive carrying a worked row for every state each column can hold.
Our compliance platform already collects evidence. Why this?
A platform collects what its integrations reach, from the day you connected it. It does not tell you that the log behind one control retains push events for seven days, or that a review held in a meeting has no source system at all. Those are dates and absences, not integrations. The quarterly access review is the clearest case of the second.
We start readiness two months before fieldwork. Is that a problem?
It depends entirely on one number per system, which is why the register computes it first. Any source whose retention window is shorter than the elapsed part of your period has already lost the earliest instances, and no amount of collection effort brings a deleted log back.
What do we do about a gap we genuinely cannot close?
Four responses, and the pack rules three of them in or out per gap. Turn on durable capture, which fixes the next period. Perform a late instance and disclose the date. Accept the exception and get it written into the report. Or start the period later, which is usually cheapest.
Does it write the narratives too?
Yes, in a six-part format naming the mechanism rather than the intention, with the exclusions written out. It writes them after the evidence register, deliberately: a narrative for a control whose evidence expired is careful work that changes nothing about the report. The customer-side controls a narrative discloses are what a vendor SOC 2 review extracts from the other end.
Our configuration and log exports cannot leave our network. Can we still use this?
Then run it inside a private AI workspace, where control descriptions, system names and log exports stay in your own tenancy. The registers and the deadline arithmetic behave exactly as they do here, and the questionnaire answers that follow the report run in the same place.
Date the evidence before you write the narratives
Start from the blank registers, or give River your period and your systems and get the deadline for every artifact an auditor will ask for.
Edit with AI