Beyond SOC 2
What are the 5 C's of internal audit?
What are the 5 C's of internal audit?
The 5 C's of internal audit are Criteria, Condition, Cause, Consequence, and Corrective action. They are the structure of a single audit finding rather than a description of a program: what should be true, what is actually true, why the gap exists, what it puts at risk, and what will be done about it. A finding missing any of the five is usually sent back for rework before it can be reported.
The five, with an example
| C | The question it answers | Example |
|---|---|---|
| Criteria | What should be happening? | Policy requires access reviews each quarter |
| Condition | What is actually happening? | Two of the last four quarters have no review record |
| Cause | Why does the gap exist? | No owner was assigned after the previous owner left |
| Consequence | What does it put at risk? | Departed employees may retain access; SOC 2 CC6.2 would fail |
| Corrective action | What will be done, by whom, by when? | Ownership assigned to the CTO, reviews scheduled, first one completed by 30 September |
Why the structure exists
An audit finding has to survive two audiences. The person who has to fix it needs to know exactly what is wrong and what to do. The person who has to accept the risk needs to know what happens if nobody does. The five C's force both into a single paragraph.
The structure is also what makes findings comparable across an audit. Ten findings written to the same shape can be ranked, tracked, and closed. Ten findings written as prose cannot.
The one that gets skipped
Cause. It is the hardest to establish and the easiest to leave out, and leaving it out is why findings recur. A missed access review whose cause is recorded as "the review was not performed" produces a corrective action of "perform the review." A missed access review whose cause is recorded as "no owner after a departure, and no process reassigns compliance tasks when someone leaves" produces a corrective action that prevents the next one.
Consequence is the second weak point, usually because it is written as a restatement of the condition. "Access reviews were not performed" is a condition. "Terminated employees may retain production access for a full quarter" is a consequence.
Where this shows up in SOC 2 and ISO 27001
External auditors use the same shape. A SOC 2 exception describes the criterion tested, the deviation observed, and its effect on the control objective. ISO 27001 nonconformities carry a required root cause analysis and corrective action, which is the same idea with the cause step made mandatory rather than optional.
Writing internal findings in this structure means they translate directly when an external auditor asks what you already knew and what you did about it.