Skip to main content
Category: Audit Process

Audit Criteria

Also known as: Audit Standards, Suitable Criteria, Evaluation Criteria
Simply put

Audit criteria are the benchmarks or standards that an auditor uses as a reference point when examining an organization's policies, procedures, and controls. The auditor compares the evidence they gather against these criteria to determine whether the organization meets the expected requirements. In practice, the specific criteria depend on the type of engagement and the framework being applied.

Formal definition

Audit criteria are the policies, procedures, or requirements against which audit evidence is compared during an examination or verification activity. They serve as the defined reference points that auditors use to assess conformity, and may be drawn from internal documents (such as an organization's own policies and processes) or from external frameworks and regulatory requirements, depending on the scope and objectives of the engagement. In attestation and certification contexts, the selection of suitable criteria is a scoping decision that shapes what the audit evaluates; the criteria applied to a SOC 2 examination (the Trust Services Criteria) differ from those applied to an ISO/IEC 27001 certification (the ISMS requirements in clauses 4-10 and the Annex A reference controls selected via the Statement of Applicability), so criteria are not interchangeable across frameworks.

Why it matters

Audit criteria are the foundation of any credible examination or certification because they define exactly what "passing" means. Without clearly established criteria, an auditor has no objective reference point to compare evidence against, and the resulting conclusions become subjective and difficult to defend. In compliance engagements, the choice of criteria determines the scope of what is evaluated and what falls outside it, which is why the selection of suitable criteria is treated as a deliberate scoping decision rather than a formality.

The distinction matters most when organizations pursue different frameworks. A SOC 2 examination evaluates evidence against the Trust Services Criteria, while an ISO/IEC 27001 certification evaluates conformity against the ISMS requirements in clauses 4 through 10 and the Annex A reference controls selected through the Statement of Applicability. Because these criteria are not interchangeable, satisfying one framework does not automatically satisfy the other, and mapping between them is only partial. Misunderstanding which criteria apply can lead an organization to prepare for the wrong benchmarks and receive findings it did not anticipate.

Criteria also define the boundaries of what an audit outcome actually asserts. A SOC 2 report speaks only to the controls and criteria within its defined scope over the period covered, and an ISO 27001 certificate covers only the ISMS scope certified against the applicable requirements. Recognizing that criteria bound the conclusion helps stakeholders avoid over-reading a report or certificate as a broader guarantee than it provides.

Who it's relevant to

Compliance and GRC Managers
These professionals must confirm which criteria apply before an engagement begins, since the selected criteria determine what evidence needs to be prepared and what will be evaluated. Understanding that SOC 2 and ISO 27001 rely on different criteria helps them avoid preparing against the wrong benchmarks.
Auditors and Assessors
Auditors depend on clearly defined criteria as the reference point against which they compare gathered evidence during an examination or verification activity. Selecting suitable criteria and applying them consistently is central to producing conclusions that can be objectively supported and defended.
Security Engineers and Control Owners
Those responsible for implementing and operating controls benefit from knowing the specific criteria their work will be measured against, whether those are internal policies and processes or external framework requirements. This clarity helps them align controls with the benchmarks that will actually be evaluated.
Executives and Stakeholders Reviewing Outcomes
Leaders who rely on a SOC 2 report or an ISO 27001 certificate should understand that the criteria define the boundaries of what the outcome asserts. A report or certificate speaks only to the criteria and scope covered and does not extend to matters outside those defined benchmarks.

Inside Audit Criteria

Defined Criteria Set
The specific benchmark against which an engagement is evaluated. For a SOC 2 examination, this is the applicable Trust Services Criteria, with Security (the Common Criteria) required and Availability, Processing Integrity, Confidentiality, and Privacy included depending on scope. For ISO 27001, the criteria are the ISMS requirements in clauses 4 through 10, supported by the reference controls in Annex A selected via the Statement of Applicability.
Scope Boundaries
The system, services, locations, and time frame the criteria are applied to. Audit criteria are only meaningful within a defined scope; a SOC 2 report covers only the controls and period examined, and an ISO 27001 certificate covers only the defined scope of the ISMS.
Evaluation Basis
How the criteria are assessed. A SOC 2 Type I evaluates the suitability of design of controls at a point in time, while a Type II evaluates both design and operating effectiveness over a defined review period whose length is set by scoping decisions. ISO 27001 evaluates whether the ISMS conforms to the standard's requirements.
Source Authority
The standard-setting body behind the criteria. SOC 2 criteria derive from the AICPA Trust Services Criteria, examined by a licensed CPA firm under the SSAE 18 attestation standard. ISO 27001 criteria derive from the ISO/IEC 27001 standard, assessed by an accredited certification body, with Annex A controls elaborated in ISO/IEC 27002.
Selection and Justification Records
Documentation showing which optional criteria or controls were included and why. In SOC 2 this reflects the choice of Trust Services categories based on scope; in ISO 27001 this is captured in the Statement of Applicability and informed by the risk assessment, noting that Annex A was restructured in the 2022 revision.

Common questions

Answers to the questions practitioners most commonly ask about Audit Criteria.

Are the audit criteria for SOC 2 and ISO 27001 the same set of controls?
No. SOC 2 examinations are evaluated against the Trust Services Criteria defined by the AICPA, where Security (the Common Criteria) is required and Availability, Processing Integrity, Confidentiality, and Privacy are optional categories selected based on scope. ISO 27001 is assessed against the ISMS requirements in clauses 4 through 10, with Annex A serving as a set of reference controls selected via a Statement of Applicability. These are distinct frameworks with different criteria structures, and they should not be conflated even where their subject matter overlaps.
Does meeting the audit criteria for one framework mean the criteria for the other are automatically satisfied?
No. While mapping between SOC 2 and ISO 27001 criteria is possible, it is only partial. Satisfying the Trust Services Criteria in a SOC 2 examination does not automatically satisfy the ISMS requirements or the selected Annex A controls for ISO 27001, and the reverse is equally true. Each framework has its own criteria, evaluation approach, and outcome, so overlap in coverage does not equate to equivalence.
How do I determine which audit criteria apply to my engagement?
For a SOC 2 examination, the applicable criteria depend on scoping decisions: Security (the Common Criteria) applies in all engagements, while the additional categories are included only where relevant to the services and commitments in scope. For ISO 27001, the ISMS requirements in clauses 4 through 10 apply, and the Annex A reference controls that are relevant are identified through the risk assessment and documented in the Statement of Applicability. In most cases the applicable criteria are settled during scoping with the service auditor or certification body.
Where are the audit criteria formally documented for each framework?
For SOC 2, the Trust Services Criteria are published by the AICPA and the examination is conducted under the SSAE 18 attestation standard by a licensed CPA firm. For ISO 27001, the certifiable requirements are set out in clauses 4 through 10 of the standard, with reference controls listed in Annex A; the selection and justification of those controls is captured in the organization's Statement of Applicability. When citing Annex A control counts, specify the version, since the 2022 revision restructured the controls differently from the 2013 edition.
Do audit criteria differ between a SOC 2 Type I and a Type II?
The underlying Trust Services Criteria are the same, but how they are evaluated against those criteria differs. A Type I assesses the suitability of the design of controls at a point in time, while a Type II assesses both the design and the operating effectiveness of controls over a defined review period. The length of that period varies and is set through scoping decisions rather than being fixed.
What do the audit criteria not cover?
The criteria define what is evaluated, but the resulting outcome is bounded by scope. A SOC 2 report attests only to the controls and the period covered and does not guarantee freedom from breaches. An ISO 27001 certificate covers only the defined scope of the ISMS. Criteria for related standards such as SOC 1, SOC 3, ISO 27002, ISO 27017, and ISO 27018 are separate, so meeting the criteria for one engagement does not extend assurance beyond its stated boundaries.

Common misconceptions

Meeting the audit criteria for SOC 2 automatically satisfies ISO 27001, and vice versa.
The frameworks use different criteria and processes. SOC 2 is an attestation examination resulting in a report, while ISO 27001 is a certification against a management system standard. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
Audit criteria are a fixed, universal checklist applied identically to every organization.
Criteria depend on scope and selections. For SOC 2, only Security is required and the other Trust Services categories are chosen based on scope; for ISO 27001, Annex A controls are selected through the Statement of Applicability and informed by risk assessment, so the applied criteria vary between engagements.
Passing against the audit criteria guarantees the organization is free from security breaches.
A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of the ISMS. Criteria establish evaluation benchmarks, not an assurance of absolute security.

Best practices

Confirm the exact criteria set before the engagement begins, distinguishing the applicable Trust Services Criteria for SOC 2 from the clause 4 through 10 requirements and selected Annex A controls for ISO 27001.
Document the scope precisely, including systems, services, and the review period, since the criteria only apply within these defined boundaries.
Record which optional criteria or controls were included and the rationale, using the Statement of Applicability for ISO 27001 and the selected Trust Services categories for SOC 2.
Specify the standard version when referencing ISO 27001 Annex A control counts, since the 2013 and 2022 editions differ.
Clarify with stakeholders that criteria establish evaluation benchmarks over a covered period or point in time and do not guarantee freedom from breaches.
When pursuing both frameworks, treat any mapping between SOC 2 and ISO 27001 as partial and validate each set of criteria independently rather than assuming equivalence.