Evidence collection — the analyser owns the binder the CPA firm samples at audit. The audit-period binder (access-review screenshots, change-tickets, MDM reports, the quarterly access-review output, the SIEM retention report) is what the auditor pulls first; map each Trust Service Criterion row to the artifact that satisfies it: Security CC6.1 (logical access) ↔ the access-review output; Availability A1.2 ↔ the uptime SLA report and the incident-response runbook; Confidentiality C1.1 ↔ the data-classification inventory and the signed NDAs for every vendor that touches confidential data; Processing Integrity PI1.1 ↔ the input/output reconciliation report; Privacy P1.1 ↔ the privacy notice backed by the Art. 30 / RoPA-aligned record-of-processing row. A binder keyed to the Common Criteria one row at a time is the most common difference between a Type II with a clean opinion and one with a sampling exception.
Control mapping — pair each Trust Service Criterion row to the controls the organisation already runs, so the Type II attestation is also a control-inheritance story. The artifact: a mapping spreadsheet that names for each CC row the underlying control instance (the TSC ↔ ISO 27001 Annex A marriage, the TSC ↔ HIPAA §164.308–§164.312 overlap, the TSC ↔ PCI Reqs 7/8/10 mapping, the TSC ↔ GDPR Art. 32 technical safeguards), the evidence owner, and the audit-window the sample covers. The mapping is what the auditor opens in the planning call; it is the single document that turns the SOC 2 attestation from a one-off report into a continuous control-running exercise, and a clean mapping is the difference between a Type II with no findings and one with operating-effectiveness exceptions.
Audit support — the point-of-contact role during the auditor walk. The analyst schedules the weekly check-ins with the CPA firm, prepares the evidence-pull queue, routes auditor questions by Trust Service Criterion, and owns the findings log through remediation. A typical Type II run produces a findings list (operating-effectiveness exceptions, sampling exceptions, scope-clarification items, the carve-out disputes over Availability and Confidentiality scope) and the analyst owns pairing each finding with an owner, a remediation date, and a verification step before the report issues. A Type II that closes its findings inside the audit window, with a verification step the CPA firm accepts, lands clean; one that leaves findings open at issue flags the engagement in the next surveillance cycle.