River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

SOC 2 Control Narrative Examples

Narratives in a six-part format that names the mechanism, plus the evidence register that dates every artifact before you write a word about it.

Free download  ·  No account needed

Evidence Register

One row per artifact an auditor will look at, and the day it stops existing

Filled in before the narratives, not after. A narrative for a control whose evidence expired in January is careful work that changes nothing about the report.

The artifact, and the system it comes out of

Not "the cloud" or "our logs". The specific service whose console or API holds the record, because retention is a property of that service and not of your control.

Reconstructable, in three values

Yes at any time, for the current access list or the current configuration, which is the easy class and evidences nothing about the period. Yes within a retention window, which is the work. Or no, for a review held in a meeting with no minutes.

Retention, as documented, beside Retention (days)

The vendor's own sentence transcribed word for word, then the number your arithmetic uses. Two columns because one cannot hold both readings. A platform whose audit log runs 180 days and whose repository push events run seven has written both numbers in the same paragraph, and the small one governs your change control.

Evidence Deadline and Unrecoverable Days

The period start plus the retention window, and how much of the period that source can no longer reach as of today. Neither is a judgement. Both are subtraction, and both are available on the first day of a readiness project rather than in the week before fieldwork.

Instances held, longest gap, owner

How many instances you actually have against the population the frequency implies, and the longest stretch inside the period with none at all. A quarterly control on a twelve-month period needs four, and no amount of December produces the one that was due in March.

A Type 2 opines on operating effectiveness across a period, so an auditor samples dated instances from throughout it. Those instances live in systems whose retention was set by somebody not thinking about your audit. A cloud provider's default history covers the past 90 days of management events, and a code platform's audit log runs 180 days while it retains Git events for seven. Multiply those two facts and a change-management control has a deadline eight days into January.

So the Evidence Register carries the vendor's retention sentence transcribed word for word beside the number your arithmetic uses, because that GitHub sentence holds two figures and the small one governs pushes. From those it derives the evidence deadline, which is the period start plus the window, and the days of the period a source can no longer reach. Chat approvals get the same treatment: on the free plan you choose 90 days or one year, so an approval's lifetime was a billing decision.

Ashgrove Systems, a fictional SaaS company, mapped 34 controls to the AICPA trust services criteria and then dated the evidence on the first day rather than in the last fortnight. Twenty-one had gaps nothing would close, two had expired on 8 January, and shortening the period to 212 days cleared seven of them for nothing. It sits beside the vulnerability register an auditor samples for CC7, and the retest evidence they ask for alongside it.

Twenty-one of 34 controls, gapped on day one

The Evidence Register's deadlines, the Control Register's populations, and Readiness Status.

Computed on 1 September, five months before fieldwork

Ashgrove Systems, a fictional B2B SaaS company. First Type 2 over calendar 2026, 34 controls, fieldwork booked for 18 January 2027. Readiness started on 1 September, by which point 243 of the 365 days had elapsed.

Source systemRetention, as documentedDaysDeadline for a 1 Jan periodUnrecoverableControls
Code platform audit logthe last 180 days18030 Jun 202663 days4
Code platform Git eventsretains Git events for seven days78 Jan 2026236 days2
Cloud provider activity historythe past 90 days of management events901 Apr 2026153 days5
Chat tool, free plan at 90 daysretain data for 90 days or one year901 Apr 2026153 days3
ReconstructableControlsWhat it means for the report
Yes, at any time13The current state of the world. Producible any day, and evidences nothing about the period. Where every readiness project starts.
Yes, within a window14Exists in a system until it is deleted. Has a computable deadline, and nine of these had already passed one.
No7Captured at the moment or not at all. The control operated and cannot be shown to have operated.

Twenty-one of 34 controls had evidence gaps on 1 September that no additional effort would close. Nine of them were in the half of the register somebody had already marked green, because the artifact existed when they checked and the check was in August.

The two Git-event controls expired on 8 January, 236 days before anybody looked. The first pass at the register recorded 180 days, because that is the number in the first half of the vendor's sentence. The second half of the same sentence says seven days, and it governs pushes and merges, which is what a change-management control is evidenced by.

Every figure in this table was available on the first day. None of it requires a tool, a vendor, or a control list.

Population is frequency times period

A Type 2 samples instances from across the period, so every control has a population and it is multiplication rather than opinion.

FrequencyPopulation over 365 daysWhat a late start costs
continuous, automated1 configurationNothing, if change history reaches the start of the period.
daily365Nothing, if the log reaches the start of the period. The strongest position available.
monthly12One instance per missed month, and each one is a dated absence.
quarterly4Starting in September leaves two. March and June are not recoverable by any amount of December.
annual1Lowest population, hardest to fix. Perform it late and the date is on the artifact, with no second instance to sample instead.
event-drivenhowever many eventsKnowable only from the source system, which is fine until that system keeps the events for a week.

The quarterly access review came out at two of four. It happened in Q3 and Q4. Q1 and Q2 were a standing item in an engineering meeting with no minutes and no sign-off, so the gap between the instances that exist is 182 days. That is subtraction in a cell in September rather than a discovery in fieldwork in January.

A control described as operating periodically has no population. So the register refuses the word, along with regularly and as needed. Without a frequency there is no expected count, without an expected count there is no test plan, and the auditor supplies one anyway.

Expected against held, per control. A missing instance in a closed quarter is not a documentation task.

What to do, including the option nobody offers

One of four responses per gap, recorded with the date it was decided and why the other three do not apply.

ResponseWhen it appliesWhat it does not do
Turn on durable captureAlways worth doing. A trail to object storage, a log stream, a longer retention setting. About a day of engineering.Touch a single elapsed day. Record it as a remediation with a start date, not as a gap closed.
Perform late, disclose the dateWhile the instance is still due inside the period. Produces an exception rather than a gap, which is a better position.Help once the quarter has closed. A review performed in October is the Q4 instance whatever it is labelled.
Accept and discloseAn instance in a closed period. Goes in the report with a date, a cause and the fix already made.Need to be hidden. Buyers read exceptions and accept them far more often than a readiness vendor expects.
Move the period startWhen most gaps share one cause and one date. Ashgrove moved to 3 June, which every 90-day source still reached, giving a 212-day period.Get suggested by anybody, because it reads as failure and is arithmetic.

Seven of the 21 gapped controls became clean on the shorter period. Their only problem was a deadline that had passed for January and had not passed for June. The report went out over 212 days with eleven disclosed exceptions instead of over 365 with twenty-one, and the customer's security team said it read better.

The one response that is never available is producing an artifact dated earlier than the day it was made. It converts a missing-evidence finding into a different and worse one, and file metadata outlives the intention. The pack says so in the space rule rather than leaving it implied.

Six days of work changed this report. Two on the criteria mapping, four on the evidence register and the retention research. The rest of the five weeks went on narratives and gap notes, which changed the next report rather than this one.

A gap disclosed by the organisation reads differently from a gap discovered by the auditor, and the difference costs nothing except deciding early.

What's in the pack

01

Evidence Register

One row per artifact, with its source system, that system's retention word for word, and the resulting deadline.

02

Control Register

Every control mapped to its criterion, with a frequency the sheet accepts and the population that frequency implies.

03

Readiness Status

Instances expected against instances held per control, with one of four responses recorded against every gap it finds.

04

How Evidence Expires

The arithmetic behind all of it: populations, retention windows, deadlines, and the three classes of reconstructable evidence.

05

Evidence Guidance

Artifact by artifact, what an auditor wants and how to capture it so it survives to fieldwork.

06

Control Narrative

The six-part format annotated, then one production access control written out in full, exclusions included.

07

Gap Remediation Note

The page that turns a gap into a decision, ruling out three of the four responses explicitly.

08

Worked Readiness Assessment

One first Type 2 end to end, from 34 controls to a shorter period and eleven disclosed exceptions.

How to use it

  1. 1

    Open in River, or take it blank

    Claim the pack in River and give it your period and your systems, or take the blank registers and narrative format and work through them yourself.

  2. 2

    Fix the period, then name the systems

    Where approvals, access changes, reviews and deployments actually happen. The systems are the time-sensitive part, and the control list is not.

  3. 3

    Date every artifact

    Source system, its own retention sentence, the deadline that follows, and how much of the period each source can no longer reach as of today.

  4. 4

    Decide the gaps, then write

    One of four responses per gap, including shortening the period. Narratives come last, for the controls that can still be tested.

Frequently asked questions

Is this template free?

Yes, with no account, card or email needed for the download. Edit with AI is the optional half and the one that does the arithmetic: it reads your period and your systems and returns the deadlines. The rest of the template library works the same way.

What format are the downloaded files?

The five documents come as .docx and the three registers as .csv, in one zip. That opens in Word or Google Docs and in Excel, Numbers or Sheets, with nothing to import and nothing to convert. The registers arrive carrying a worked row for every state each column can hold.

Our compliance platform already collects evidence. Why this?

A platform collects what its integrations reach, from the day you connected it. It does not tell you that the log behind one control retains push events for seven days, or that a review held in a meeting has no source system at all. Those are dates and absences, not integrations. The quarterly access review is the clearest case of the second.

We start readiness two months before fieldwork. Is that a problem?

It depends entirely on one number per system, which is why the register computes it first. Any source whose retention window is shorter than the elapsed part of your period has already lost the earliest instances, and no amount of collection effort brings a deleted log back.

What do we do about a gap we genuinely cannot close?

Four responses, and the pack rules three of them in or out per gap. Turn on durable capture, which fixes the next period. Perform a late instance and disclose the date. Accept the exception and get it written into the report. Or start the period later, which is usually cheapest.

Does it write the narratives too?

Yes, in a six-part format naming the mechanism rather than the intention, with the exclusions written out. It writes them after the evidence register, deliberately: a narrative for a control whose evidence expired is careful work that changes nothing about the report. The customer-side controls a narrative discloses are what a vendor SOC 2 review extracts from the other end.

Our configuration and log exports cannot leave our network. Can we still use this?

Then run it inside a private AI workspace, where control descriptions, system names and log exports stay in your own tenancy. The registers and the deadline arithmetic behave exactly as they do here, and the questionnaire answers that follow the report run in the same place.

Date the evidence before you write the narratives

Start from the blank registers, or give River your period and your systems and get the deadline for every artifact an auditor will ask for.

Edit with AI