They look for continuous indicators such as completed access reviews, logged approvals, timely remediation of exceptions, and control evidence that updates as operations change. A readiness assessment helps, but continuous monitoring is the stronger test because it shows whether controls still operate after the audit rehearsal ends. If evidence only appears near audit time, the programme is not yet stable.
How to tell whether SOC 2 controls are operating, not just documented
SOC 2 control effectiveness is less about whether a policy exists and more about whether evidence shows the control is used consistently in normal operations. The best signal is operational proof: access reviews completed on schedule, approvals logged before changes, exceptions remediated within a defined window, and evidence that continues to update after the audit period ends. That is the difference between design and operation.
One practical way to read this is to compare control artefacts over time. A control that only produces clean evidence during audit preparation is usually being assembled, not continuously run. Mature programmes leave a repeatable trail in logs, tickets, review records, and exception tracking that matches how the business actually works, including change activity, staff movement, and system updates.
Continuous monitoring also matters because SOC 2 evidence is strongest when it reflects current state, not a past snapshot. That is why teams often pair manual review with automated logging, workflow records, and periodic testing: the control must keep functioning as conditions change, not merely pass a point-in-time inspection. For the control criteria themselves, the SOC 2 Trust Services Criteria (AICPA) define the assurance lens auditors and security teams are trying to satisfy.
What evidence usually separates a working control from an audit-only one
The strongest evidence is behaviour-based, not narrative-based. If access reviews are real, they show named reviewers, dated decisions, follow-up on outliers, and closure of exceptions. If approvals are real, they appear in the workflow before the change took place. If remediation is real, it produces tickets, owners, deadlines, and proof of closure rather than a post hoc explanation.
Control evidence should also be internally consistent across systems. A good test is whether the same event can be seen in the control record, the system log, and the operational ticketing trail. When those sources align, the control is more likely to be functioning as part of daily operations. When they do not, the programme may be relying on manual reconstruction, which is weaker and easier to fake or forget.
That is why readiness activity is only a rehearsal. A readiness assessment can uncover gaps, but it does not prove sustained operation. For that, you need evidence that survives normal churn: new users, changed roles, exceptions, vendor access, configuration drift, and routine operational pressure. Controls that keep producing evidence through those changes are the ones you can trust.
Why continuous monitoring is the better test than audit-time proof
Continuous monitoring tells you whether the control is still active after the compliance spotlight moves away. It is the stronger test because real operating conditions are where controls fail: reviews are skipped, approvals become informal, exceptions linger, and stale evidence is reused. A system that only looks clean near audit time may have the right paperwork but the wrong operating model.
In practice, this means looking for time-based signals, not just presence signals. You want to know whether the control is executed on cadence, whether deviations are logged quickly, and whether follow-up happens before the issue becomes structural. That gives you a better view of control health than a one-time sample of evidence.
Risk and Threat Considerations
When SOC 2 controls are only evidenced at audit time, the organisation can miss real exposure between review cycles. The risk is not limited to compliance failure, it also includes undetected access creep, unapproved changes, and control drift that weakens trust in the service overall.
Failure mechanism: teams produce point-in-time artefacts that satisfy an audit sample, but the control is not anchored to the operational workflow, so exceptions, approvals, and reviews stop being reliable indicators of current behaviour.
Impact: the organisation may believe controls are working when the underlying process is stale, which increases the chance of unauthorised access, unremediated exceptions, and audit findings when evidence cannot be reproduced consistently.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
SOC 2 (AICPA) provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | SOC 2 control effectiveness here depends on evidence that access controls operate continuously. |
| CC4.1 — Monitoring Activities | Continuous monitoring is central to proving controls still function after audit preparation ends. | |
| CC7.2 — Change Management | Timely approvals and remediation depend on change control operating as designed. | |
| Recommendation — Verify access review evidence and approval trails to show the control works in normal operations. Track ongoing control signals and exceptions so evidence reflects current operating state. Require logged approvals and closure evidence for changes and exceptions before signoff. | ||
Practitioner Guidance
What to prioritise: start with controls whose failure would create silent exposure, especially access reviews, exception handling, and change approval trails. These are the areas where audit-quality evidence and operational reality diverge first.
What to verify: confirm that evidence is generated by normal workflow, not manually reconstructed. A useful test is whether a reviewer, approver, or remediator can produce the same trail without building a special audit package from scratch.
What good looks like: the control leaves a current, repeatable record that changes when the environment changes. If the evidence set stays static while users, systems, or permissions move, the control is probably lagging behind operations.
Practitioner takeaway: treat SOC 2 as an operating-state question, not a documentation exercise, because stable controls are proven by continuous evidence that tracks real work, not by polished audit-time samples.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org