Standards / Information security, privacy and AI
SOC 2 Trust services criteria
An auditor's report on security, availability, confidentiality, processing integrity, and privacy controls.
Core documents AMS builds
- System description
- Control matrix
- Security policies
- Risk assessment
- Vendor management records
Drafted from your actual processes and systems, then kept under version control with review dates.
The path to SOC 2
Six steps from first conversation to SOC 2. AMS and our consultants handle each one with you.
- 1Scope
Define which sites, teams, processes and systems SOC 2 will cover.
- 2Gap assessment
Compare what you do today with every SOC 2 requirement and list what is missing.
- 3Documents
Write the policies, procedures and records SOC 2 expects, starting with the system description.
- 4Implement and collect evidence
Put the processes into daily work and capture proof that they run, on a schedule.
- 5Internal review
Check readiness with an internal audit or self-assessment, and close the findings.
- 6Independent audit
A licensed CPA firm tests your controls and issues the report, either at a point in time (Type 1) or over a period (Type 2).
SOC 2 questions
Planning SOC 2? Talk to our team
How long does SOC 2 implementation take?
Most organizations need about 8–16 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.
What documents does SOC 2 require?
Core documents usually include: system description, control matrix, security policies, risk assessment, vendor management records. AMS drafts them from your actual processes and keeps them under version control.
Can SOC 2 be combined with other standards?
Yes. SOC 2 is often run together with ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 27701. AMS maps shared requirements, so one record can count toward several standards.
How does AMS help with SOC 2?
AMS runs the full SOC 2 program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your auditor.