SOC2Prep

SOC 2 control owner mapper

Auditors ask who owns a control before they ask to see it. This maps the twenty areas a first audit turns on to the roles you actually have, and names the ones left with nobody.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

The first question in most audit kickoff calls is not about a control. It is about a person. Who approves changes, who runs the access review, who decides a vendor is acceptable. A company of twenty-five people usually has good answers for six of those and an uncomfortable silence for the rest, and the silence is where the exceptions come from.

Tell this tool which roles exist in your company and how a few specific functions are handled. It returns a responsibility map: every common criteria area matched to a named role, the roles carrying the heaviest load, the areas nobody owns, and the places where one person holds two duties an auditor expects to see separated.

The map appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Which of these roles exist in your company?

Tick a role only if a specific person holds it today. A title on a hiring plan is not an owner. One person can hold several, and that is normal below fifty people.

Who runs the production infrastructure?

Who handles hiring, onboarding and departures?

Who decides a new vendor is acceptable?

Not who signs the invoice. Who looks at what the vendor would hold and says yes.

Where do people work?

How many people work there?

When does the observation window open?

Responsible and accountable are different answers

The person who runs the quarterly access review and the person who answers for it when it was not run are often two different people, and a first audit will ask for both. The map below names a responsible role for each area, an accountable executive who is the same person across most of the list, and the roles that have to be consulted for the work to be correct.

That distinction matters most in a company where one founder is the accountable party for everything. That is a defensible position at twenty people. It stops being defensible when the accountable party is also the only person who performs the control, because there is then nobody who could notice it had stopped happening. The usual fix is not a hire. It is moving the performing role one seat sideways and leaving the accountability where it is.

The two duties auditors look at hardest

Two pairs come up in nearly every small-company audit. The first is change management: the person who writes a change, the person who approves it and the person who deploys it should not all be the same person on every change. The second is access: the person who requests production access and the person who grants it. Neither is fatal in a ten-person engineering team, and auditors know that. What they want to see is that you noticed, wrote down the compensating control, and can show it operated. An undocumented overlap reads as an oversight. A documented one reads as a decision.

If you want the underlying criteria rather than the role map, the common criteria page walks through CC1 to CC9, and SOC 2 without a security team covers how the work distributes when nobody holds a security title.

Common questions

Does every control need a different owner?

No. A twenty-person company routinely has four or five owners across the whole list, and that is expected. What an auditor tests is whether each control has a named person who can describe how it works, not whether the names are distinct. The problem to avoid is a control with no name against it, because that control is the one that quietly stops running.

Can we name a fractional or part-time person as an owner?

Yes, and it is common for the security lead role. The test is whether that person performs or supervises the control on a schedule and can be interviewed about it. A contract that buys advice but nobody who actually runs the access review has not filled the gap, it has renamed it.

What if a managed service provider runs our infrastructure?

Then they perform work inside your control, and you still own the control. You need a named internal person who reviews what they do, an agreement that sets out the security obligations, and evidence that the review happened. The provider also becomes one of your more significant vendors, so they land in your vendor register as well.

How often should the ownership map be revisited?

At least annually, and after any departure or reorganisation. The most common cause of a failed control in a second-year audit is that the owner left and the responsibility went with them. Reviewing the map is also one of the easier things to evidence, because a dated document with approvals on it satisfies the monitoring criteria at the same time.

Want a second opinion on the gaps

Send the map and your scope, and Canadian firms that do this work can tell you which of the unowned areas will actually cost you an exception.

Get matched