Screenata

SOC 2 Evidence Collection

What are the 4 types of tests of controls?

September 14, 20263 min read

What are the 4 types of tests of controls?

The four types of tests of controls are inquiry, observation, inspection, and reperformance. They are the procedures an auditor uses to decide whether a control was designed properly and operated effectively, in SOC 2 examinations, SOX audits, and internal audit alike. Inquiry alone is never enough under auditing standards, so every conclusion rests on inquiry combined with at least one of the other three.

The four tests, with SOC 2 examples

TestWhat the auditor doesSOC 2 exampleEvidence strength
InquiryAsks the control owner how the control worksInterviews the CTO about how production access is grantedLowest; never sufficient alone
ObservationWatches the control being performedWatches an engineer request and receive production accessPoint in time only
InspectionExamines records, documents, or configurationsReviews access request tickets, approvals, and the IAM configurationStrong, if the population is complete
ReperformanceIndependently executes the controlPulls the user list from the identity provider and compares it with the reviewed listStrongest

Observation has a known limit: it proves the control operated while the auditor was watching. For a Type II report covering a 3 to 12 month window, auditors lean on inspection of samples drawn across the whole period, because observation cannot reach backward in time.

How auditors choose which test to use

The choice depends on how the control operates. A manual control that leaves no record, such as a physical walkthrough, pushes the auditor toward observation. A control that produces tickets, approvals, or logs is tested by inspection of a sample. An automated control, such as a password configuration, is often tested once by inspection or reperformance, because a system setting behaves the same way every time it runs.

Sample sizes follow frequency. A control that runs daily yields a larger sample than one that runs quarterly, and the auditor draws the sample from the full population your team provides. That is why the population itself gets scrutiny: a sample drawn from an incomplete list proves nothing about the missing items.

What this means for the evidence you collect

Every test type maps to an artifact you can prepare. Inquiry needs a named control owner who can explain the process. Inspection needs complete, timestamped records for the whole period. Reperformance needs the auditor to be able to reach the source data, or an export whose provenance they can trust.

The weak point in most programs is inspection evidence assembled after the fact: screenshots taken the week before fieldwork, or exports with no record of when or how they were produced. Evidence captured at the time the control ran, with a timestamp and a record of the source, holds up under inspection and makes reperformance easier. For how auditors treat different evidence formats, see why auditors reject CSV exports as evidence.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.