SOC 2 Control Implementation Guide

Governance / Workforce

Standards of Conduct and Accountability for SOC 2

Personnel and contractors follow documented standards of conduct, acceptable use, confidentiality, privacy, and security responsibilities; deviations are reported and addressed.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Employees and contractors understand expected conduct, acceptable use, confidentiality, privacy, and security duties, while the organization can show that concerns and violations are handled consistently.

First SOC 2 program

A credible starting point

Publish a concise code of conduct and acceptable-use rules, collect a signed acknowledgment during onboarding, and give people a confidential way to raise a concern. The founder or designated people lead should document how each reported issue was assessed and resolved.

As the company scales

Make it repeatable

Use the workforce system to automate acknowledgments for employees and contractors, run annual recertification, manage investigations in a restricted case system, and periodically reconcile completion against the active workforce roster.

How to implement Standards of Conduct and Accountability

  1. 1

    Define the covered population

    Identify employees, temporary workers, interns, and contractors who can access company systems or information and decide which rules apply to each group.

    You should end up with: A population definition that can be reconciled to current workforce and contractor records.

  2. 2

    Publish clear conduct rules

    Document expected behavior, acceptable use, confidentiality, privacy, security reporting, conflicts of interest, consequences, and protection against retaliation.

    You should end up with: Approved, versioned standards that personnel can access.

  3. 3

    Collect acknowledgments

    Make acknowledgment part of onboarding and repeat it after material updates or on the chosen annual cadence.

    You should end up with: Dated acknowledgment records tied to individual personnel records and the policy version accepted.

  4. 4

    Provide reporting routes

    Offer at least one confidential channel, explain when to use it, and assign trained people to receive and triage reports.

    You should end up with: Published reporting instructions and an access-controlled intake log.

  5. 5

    Investigate and resolve consistently

    Record the allegation, scope the investigation, preserve relevant facts, determine the outcome, and apply corrective or disciplinary action through the appropriate leaders.

    You should end up with: A restricted case record showing dates, reviewers, findings, decisions, and closure.

  6. 6

    Reconcile coverage

    Compare acknowledgment completion with the active workforce and contractor list, follow up on exceptions, and report unresolved gaps to management.

    You should end up with: A dated completion report with documented follow-up for missing acknowledgments.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Policy / design artifacts

Documents that define the control, its scope, ownership, and expected way of working.

Code of conduct/acceptable use policy

  • Confirm what the record proves

    The organization communicated enforceable conduct, acceptable-use, confidentiality, privacy, security-reporting, and consequence expectations to the covered workforce.

  • Include this context

    policy version

  • Include this context

    effective date

  • Include this context

    covered population

  • Include this context

    required conduct and reporting duties

  • Include this context

    approver

Weak evidence to avoid

A generic internet-use document with no confidentiality duties, incident-reporting route, covered contractor population, approver, or effective date.

Approval / review evidence

Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

acknowledgments

  • Confirm what the record proves

    Covered personnel affirmatively received and accepted the applicable conduct rules at onboarding, annual recertification, or policy change.

  • Include this context

    person identifier

  • Include this context

    worker type

  • Include this context

    policy version

  • Include this context

    acknowledgment date

  • Include this context

    completion status

Weak evidence to avoid

A completion total of 96 percent with no person-level records, contractor population, policy version, or way to identify the missing four percent.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

ethics/whistleblower records

  • Confirm what the record proves

    Reported concerns entered a confidential intake process, received appropriate triage and investigation, and reached a documented outcome while sensitive details remained restricted.

  • Include this context

    case identifier

  • Include this context

    received date and channel

  • Include this context

    issue category

  • Include this context

    assigned investigator

  • Include this context

    status and resolution date

  • Include this context

    restricted evidence location

Weak evidence to avoid

An email stating that a concern was handled with no case identifier, intake date, investigator, documented disposition, or restricted case record.

disciplinary action evidence

  • Confirm what the record proves

    Confirmed conduct deviations resulted in a reviewed, authorized, and consistently documented corrective or disciplinary response.

  • Include this context

    case or deviation identifier

  • Include this context

    substantiated finding

  • Include this context

    decision authority

  • Include this context

    action and effective date

  • Include this context

    completion confirmation

Weak evidence to avoid

A manager message saying an employee was spoken to, without the related finding, decision authority, action date, or completion record.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

The current approved conduct and acceptable-use rules, current reporting channels, acknowledgment workflow configuration, and point-in-time acknowledgment reconciliation as of the examination date. If a conduct concern exists, include a current case record showing the configured intake, investigation, decision, and closure path; if none exists, include a complete zero-result query across every reporting channel and the restricted case system plus a walkthrough of a representative concern through that same path.

Type 2

Evidence across the review period

All employees, contractors, interns, and temporary workers subject to acknowledgment during the review period, plus all ethics or conduct reports received and all resulting disciplinary actions during that period.

Completeness check

Reconcile acknowledgment records to dated employee and contractor rosters, then reconcile reporting-channel intake logs to restricted case records and any disciplinary actions, documenting legitimate exclusions and privacy-preserving identifiers.

Build the record set from

  • human resources information system
  • policy acknowledgment service
  • contractor roster
  • confidential case-management system

Keep these fields for each record

  • person or case identifier
  • worker type or case category
  • hire, engagement, or received date
  • policy version and acknowledgment date
  • case investigator and disposition
  • disciplinary decision and effective date
  • current or termination status

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Employees and contractors understand expected conduct, acceptable use, confidentiality, privacy, and security duties, while the organization can show that concerns and violations are handled consistently.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (Executive Management / HR Owner), then compare dated records with the stated cadence: Upon hire, annually, and as needed.

  • Establish the complete audit record set

    Reconcile acknowledgment records to dated employee and contractor rosters, then reconcile reporting-channel intake logs to restricted case records and any disciplinary actions, documenting legitimate exclusions and privacy-preserving identifiers.

  • Prepare the as-of-date evidence for a Type 1 engagement

    The current approved conduct and acceptable-use rules, current reporting channels, acknowledgment workflow configuration, and point-in-time acknowledgment reconciliation as of the examination date. If a conduct concern exists, include a current case record showing the configured intake, investigation, decision, and closure path; if none exists, include a complete zero-result query across every reporting channel and the restricted case system plus a walkthrough of a representative concern through that same path.

  • Prepare period evidence for a Type 2 engagement

    All employees, contractors, interns, and temporary workers subject to acknowledgment during the review period, plus all ethics or conduct reports received and all resulting disciplinary actions during that period.

  • Inspect the policy / design artifacts

    Documents that define the control, its scope, ownership, and expected way of working.

    • Inspect Code of conduct/acceptable use policy

      For each selected record, confirm it demonstrates The organization communicated enforceable conduct, acceptable-use, confidentiality, privacy, security-reporting, and consequence expectations to the covered workforce.

      • policy version
      • effective date
      • covered population
      • required conduct and reporting duties
      • approver
  • Inspect the approval / review evidence

    Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

    • Inspect acknowledgments

      For each selected record, confirm it demonstrates Covered personnel affirmatively received and accepted the applicable conduct rules at onboarding, annual recertification, or policy change.

      • person identifier
      • worker type
      • policy version
      • acknowledgment date
      • completion status
  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect ethics/whistleblower records

      For each selected record, confirm it demonstrates Reported concerns entered a confidential intake process, received appropriate triage and investigation, and reached a documented outcome while sensitive details remained restricted.

      • case identifier
      • received date and channel
      • issue category
      • assigned investigator
      • status and resolution date
      • restricted evidence location
    • Inspect disciplinary action evidence

      For each selected record, confirm it demonstrates Confirmed conduct deviations resulted in a reviewed, authorized, and consistently documented corrective or disciplinary response.

      • case or deviation identifier
      • substantiated finding
      • decision authority
      • action and effective date
      • completion confirmation
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • Contractors with production or customer-data access are omitted from the acknowledgment process.
  • A signature is retained without the version or effective date of the rules that were accepted.
  • Completion reports cannot be reconciled to the workforce population as of the report date.
  • Reporting channels exist, but ownership, confidentiality, and escalation expectations are unclear.
  • Investigation and disciplinary records are scattered across email and cannot show consistent handling.

Before you call this control ready

  • Can a new employee find the conduct rules and explain how to report a concern?
  • Can the latest acknowledgment report be reconciled to all active employees and covered contractors?
  • Does each acknowledgment identify the person, date, and policy version?
  • Are case records restricted to authorized reviewers and retained under a defined schedule?
  • For a reported deviation, can management show intake, investigation, decision, and closure without exposing unnecessary personal information?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC1.1
  • CC1.5
  • CC2.2
  • CC5.3

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.