In the first year of a SOC 2 Type II audit, one sampled quarterly access review has no evidence — how is the sample handled, and what should the team do?
answer
- population, sample, exception
- never recreate old evidence
- isolated or systemic
- what happened during the gap
- extend testing if reliance fails
basics
~20 sThe missing review is an exception: that instance of the control did not operate. The team must not recreate backdated evidence; it discloses the gap, performs the review now with a true date, checks what access changed during the gap and fixes the cause.
solid answer
~50 sAn auditor samples from the **complete population** of control instances in the period - for a quarterly review there are few, so most or all are usually examined - and the population must come without the auditee steering the selection. A missing review is an **exception**: that instance did not operate. The auditor then asks whether it is **isolated or systemic**, may **extend testing** (PCI DSS's sampling guidance, for example, tells assessors to increase the sample when controls relied on are not operating effectively), and weighs whether other controls address the same risk. The team must **not** recreate evidence with the old date; that is falsification. It should perform the review now and date it truthfully, check whether any access that should have been removed during the gap was misused, fix the root cause (owner, reminder, backup reviewer) and give a factual management response for the report.
go deeper
Recall what a population, a sample and an exception are, and that missing evidence cannot be recreated after the fact.
Explain why the auditor selects samples across the whole period and how an exception is evaluated as isolated or systemic.
Show how you would handle the missed review: truthful late performance, a look-back over the gap, root cause, process fix and a factual management response.
Discuss how to design periodic controls with backups and tracking so a single departure cannot create an audit exception.
## The vocabulary of sampling Audit evidence requests revolve around four terms: - **Population** - every instance of the control in scope and period: every quarterly review, every new hire, every production change. - **Sample** - the instances the auditor selects to examine. - **Exception** (or deviation) - a sampled instance where the control did not operate as designed. - **Evidence request** - the auditor's list of the population and then the specific records for each sampled item. PCI DSS v4.0.1's section on sampling sets out principles that are widely recognizable across audit regimes: 1. The assessor selects the sample **from the complete population without influence** from the assessed entity. 2. Samples must be **representative** of all variants and **large enough** to give assurance across the population. 3. For periodic controls, the sample should **represent the entire period** covered. 4. Different samples are chosen for each assessment; testing the same items every year lets unknown variations hide. 5. If controls relied on to size the sample turn out **not to be operating effectively**, the assessor should **increase the sample size**. 6. The rationale for the technique and size is **documented**. For a quarterly control there are very few instances in a year, so an auditor commonly examines most or all of them. Losing one of four is a large share of the population. ## The scenario A company is in its first period-based SOC 2 examination. One control is a **quarterly user access review**. For one quarter there is no evidence: no sign-off, no ticket, no list of changes. The owner left mid-quarter and nobody picked the task up. ## How the auditor treats it | Step | What happens | |---|---| | Record the exception | The instance did not operate; it is a deviation in the test results | | Assess nature | One missed instance with a clear cause, or evidence of a broader failure? | | Extend testing if needed | If the auditor had relied on consistency, reliance is weaker and more testing may follow | | Consider related controls | Did other controls, such as removal of access at termination, still address the risk in that quarter? | | Conclude | Decide the effect on whether the relevant criterion was met, and describe the exception in the report | Whether the exception changes the overall conclusion is the auditor's judgment; the company's job is to give accurate facts and a credible remediation. ## What the team should do 1. **Do not recreate evidence.** Producing a review record dated in the missed quarter is falsification and destroys trust in all other evidence. 2. **Perform the review now**, dated truthfully, and remove any inappropriate access found. 3. **Look back over the gap**: were leavers' accounts disabled on time? Did any account that should have been removed log in during the quarter? 4. **Find the root cause**: single owner, no reminder, no backup reviewer, no ticket to track completion. 5. **Fix the process**: assign a backup, create a recurring tracked task, and escalate when overdue. 6. **Write a factual management response**: what happened, what was checked, what changed. ## Preventing a repeat The lasting fix is structural. Periodic controls that depend on one person are fragile, so each should have a named backup, a tracked recurring task with a due date, an escalation when it slips, and evidence stored where the auditor can see it without asking the original owner. Some teams also run an internal check of each periodic control shortly after its due date, so a missed instance is caught within weeks rather than at fieldwork. ## What not to argue - "It is just paperwork" - the evidence *is* how the control proves it ran. - "Let us swap it for another quarter" - the entity does not choose samples. - "Remove the control from the description for that quarter" - changing the description to hide a failure misstates the system. A strong answer defines population, sample and exception, explains how an auditor evaluates and may extend testing, and gives an honest remediation that includes looking at what happened during the gap.
- Why does the auditor select the sample rather than the company?So the sample is unbiased. PCI DSS's sampling guidance, for example, requires the assessor to select from the complete population without influence from the entity; letting the auditee choose would let it show only its best instances.
- How can other controls soften the impact of a missed access review?If controls such as prompt removal of access at termination operated during the gap, the risk the review addresses may still have been managed. The auditor weighs that when deciding the exception's effect, though the missed review is still reported.
saying these in an interview costs you the question
- Recreates the missing review with the original quarter's date
- Asks the auditor to replace the failed sample with another
- Believes one exception automatically means the audit fails
- Removes the control from the system description after it fails
- Checks nothing about access changes during the missed quarter