SOC 2 Control Implementation Guide

Workforce Security

Workforce Competency and Performance Review for SOC 2

Management periodically evaluates personnel competency and performance for security, confidentiality, privacy, customer commitments, and control ownership.

Use this guide to put the control into operation, decide what records to retain, and check that an auditor can trace the evidence back to the work your team performed.

Maintained by GreenHat Security · Reviewed August 21, 2026

What this control should accomplish

Management periodically confirms that personnel can perform their assigned security, confidentiality, privacy, customer-commitment, and control responsibilities, and addresses material skill or performance gaps.

First SOC 2 program

A credible starting point

Add clear security and control expectations to existing role goals and annual performance conversations. For key roles, use practical signals such as completed training, peer review, incident participation, or successful execution of assigned controls rather than creating a separate bureaucracy.

As the company scales

Make it repeatable

Maintain role-based competency expectations, connect them to learning and performance cycles, and give managers a consistent way to record assessment, development actions, role changes, and follow-up while protecting sensitive personnel information.

How to implement Workforce Competency and Performance Review

  1. 1

    Define role expectations

    For roles that operate controls or handle sensitive data, state the knowledge, decisions, and recurring activities the role should be able to perform.

    You should end up with: A competency matrix mapped to security-relevant roles.

  2. 2

    Choose assessment signals

    Select proportionate evidence such as manager observation, completed learning, work review, exercise participation, certification, or control execution history.

    You should end up with: Documented assessment criteria for each scoped role family.

  3. 3

    Perform the review

    Have the manager assess performance and competency during the established review cycle, including the person’s assigned control responsibilities where applicable.

    You should end up with: A dated, access-restricted performance or competency review record.

  4. 4

    Address material gaps

    Assign coaching, training, supervision, adjusted access, or a role change when the assessment identifies a gap that could affect service or control operation.

    You should end up with: A development or remediation action with owner and target date.

  5. 5

    Confirm follow-through

    Review completion of agreed actions and record whether the person can now perform the responsibility or needs further support.

    You should end up with: A closure note or updated action plan approved by the manager.

  6. 6

    Reconcile completed reviews

    Compare the scoped active population with completed assessments and explain new hires, leave, or other valid exclusions.

    You should end up with: A cycle completion report with documented exclusions and follow-up.

Evidence to keep, and what it should prove

Build the evidence set in three layers: what defines the control, who approved or reviewed it, and what proves it operated. Collect operating records when the work happens so they remain dated, attributable, correctly scoped, and traceable to the underlying activity.

Before sharing, remove unrelated personal or customer data, never expose passwords, tokens, or secret values, preserve enough source context to authenticate the record, and use the secure exchange approved for the engagement.

Approval / review evidence

Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

Performance review records

  • Confirm what the record proves

    Shows that a manager evaluated a named person during the established cycle and addressed the security or control responsibilities material to that role.

  • Include this context

    person and role

  • Include this context

    review period

  • Include this context

    manager and completion date

  • Include this context

    security-relevant expectation

  • Include this context

    assessment or outcome

Weak evidence to avoid

A completion percentage or generic rating with no person, role responsibility, manager, or review date.

competency assessments

  • Confirm what the record proves

    Shows how capability for a scoped responsibility was assessed and whether coaching, training, supervision, or another response was needed.

  • Include this context

    person and competency

  • Include this context

    assessment method

  • Include this context

    assessor

  • Include this context

    assessment date

  • Include this context

    result

  • Include this context

    required follow-up

Weak evidence to avoid

A manager’s unsupported statement that the team is qualified, with no role criteria or individual assessment result.

Operating / technical evidence

Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

role change records

  • Confirm what the record proves

    Shows that a promotion or transfer changed documented expectations and triggered assessment, development, supervision, or access action appropriate to the new responsibility.

  • Include this context

    person identifier

  • Include this context

    prior and new role

  • Include this context

    effective date

  • Include this context

    new competency requirements

  • Include this context

    manager approval

  • Include this context

    assessment or action status

Weak evidence to avoid

An HR title update with no link to changed control ownership, competency expectations, or follow-up action.

Which records should you prepare for the audit?

Type 1

Evidence at the as-of date

Current competency expectations for scoped roles, the latest completed reviews for people in those roles, and all open development or remediation actions on the examination date.

Type 2

Evidence across the review period

Every scheduled performance or competency review due for active personnel in scoped security, privacy, confidentiality, customer-commitment, and control-owner roles during the review period, plus every role change that introduced a new scoped responsibility.

Completeness check

Join active scoped personnel and period role changes from HR to control-owner assignments and scheduled reviews; reconcile every due assessment to a completed restricted record or documented exclusion, then trace every material gap to an owned follow-up status.

Build the record set from

  • HR information system
  • performance management platform
  • learning management system
  • control owner register

Keep these fields for each record

  • person identifier
  • role and scoped responsibility
  • review cycle or trigger
  • due and completion dates
  • manager or assessor
  • assessment result
  • follow-up owner and status

How an auditor may test this control

Use this checklist to prepare for procedures an auditor may perform. The exact steps and sample selection depend on your engagement scope and the service auditor's professional judgment.

  • Confirm the intended control outcome

    Determine whether the control is designed to achieve this result: Management periodically confirms that personnel can perform their assigned security, confidentiality, privacy, customer-commitment, and control responsibilities, and addresses material skill or performance gaps.

  • Confirm ownership and operating cadence

    Compare the documented owner with the intended role (HR Owner / IT / CISO), then compare dated records with the stated cadence: Upon hire/change/termination; annual as applicable.

  • Establish the complete audit record set

    Join active scoped personnel and period role changes from HR to control-owner assignments and scheduled reviews; reconcile every due assessment to a completed restricted record or documented exclusion, then trace every material gap to an owned follow-up status.

  • Prepare the as-of-date evidence for a Type 1 engagement

    Current competency expectations for scoped roles, the latest completed reviews for people in those roles, and all open development or remediation actions on the examination date.

  • Prepare period evidence for a Type 2 engagement

    Every scheduled performance or competency review due for active personnel in scoped security, privacy, confidentiality, customer-commitment, and control-owner roles during the review period, plus every role change that introduced a new scoped responsibility.

  • Inspect the approval / review evidence

    Records showing that an accountable person reviewed, approved, challenged, or accepted the work.

    • Inspect Performance review records

      For each selected record, confirm it demonstrates Shows that a manager evaluated a named person during the established cycle and addressed the security or control responsibilities material to that role.

      • person and role
      • review period
      • manager and completion date
      • security-relevant expectation
      • assessment or outcome
    • Inspect competency assessments

      For each selected record, confirm it demonstrates Shows how capability for a scoped responsibility was assessed and whether coaching, training, supervision, or another response was needed.

      • person and competency
      • assessment method
      • assessor
      • assessment date
      • result
      • required follow-up
  • Inspect the operating / technical evidence

    Dated proof that the control actually ran, such as tickets, logs, settings, exports, reports, and test results.

    • Inspect role change records

      For each selected record, confirm it demonstrates Shows that a promotion or transfer changed documented expectations and triggered assessment, development, supervision, or access action appropriate to the new responsibility.

      • person identifier
      • prior and new role
      • effective date
      • new competency requirements
      • manager approval
      • assessment or action status
  • Trace the control from design to operation

    Use the categories that apply to this control: connect any policy or design artifact to its approval or review record, then trace a selected operating record through execution, result, and any exception or remediation.

Common implementation and evidence gaps

  • Generic performance reviews do not address assigned security or control responsibilities.
  • Control owners are named without assessing whether they understand the activity or evidence expected.
  • A skill gap is documented, but the development action is never followed to closure.
  • Sensitive review details are copied into broadly accessible compliance systems.
  • Contractors or newly promoted personnel in key roles are omitted from assessment.

Before you call this control ready

  • Can each security-relevant role be linked to defined competency expectations?
  • For sampled control owners, does the latest review address their actual responsibilities?
  • Are material gaps paired with owned, dated actions and follow-up results?
  • Does the completed-review population reconcile to active scoped personnel?
  • Are detailed personnel records restricted while still allowing completion to be evidenced?

Trust Services Criteria references

These identifiers help you navigate related Trust Services Criteria. They do not reproduce the criteria or prove that this control fully addresses them in your environment.

  • CC1.4
  • CC1.5

Confirm final scope, mappings, and testing expectations with your service auditor. SOC 2® is an AICPA trademark; GreenHat Security is not affiliated with or endorsed by AICPA.