Screenata

Beyond SOC 2

What are the 5 C's of internal audit?

August 18, 20263 min read

What are the 5 C's of internal audit?

The 5 C's of internal audit are Criteria, Condition, Cause, Consequence, and Corrective action. They are the structure of a single audit finding rather than a description of a program: what should be true, what is actually true, why the gap exists, what it puts at risk, and what will be done about it. A finding missing any of the five is usually sent back for rework before it can be reported.

The five, with an example

CThe question it answersExample
CriteriaWhat should be happening?Policy requires access reviews each quarter
ConditionWhat is actually happening?Two of the last four quarters have no review record
CauseWhy does the gap exist?No owner was assigned after the previous owner left
ConsequenceWhat does it put at risk?Departed employees may retain access; SOC 2 CC6.2 would fail
Corrective actionWhat will be done, by whom, by when?Ownership assigned to the CTO, reviews scheduled, first one completed by 30 September

Why the structure exists

An audit finding has to survive two audiences. The person who has to fix it needs to know exactly what is wrong and what to do. The person who has to accept the risk needs to know what happens if nobody does. The five C's force both into a single paragraph.

The structure is also what makes findings comparable across an audit. Ten findings written to the same shape can be ranked, tracked, and closed. Ten findings written as prose cannot.

The one that gets skipped

Cause. It is the hardest to establish and the easiest to leave out, and leaving it out is why findings recur. A missed access review whose cause is recorded as "the review was not performed" produces a corrective action of "perform the review." A missed access review whose cause is recorded as "no owner after a departure, and no process reassigns compliance tasks when someone leaves" produces a corrective action that prevents the next one.

Consequence is the second weak point, usually because it is written as a restatement of the condition. "Access reviews were not performed" is a condition. "Terminated employees may retain production access for a full quarter" is a consequence.

Where this shows up in SOC 2 and ISO 27001

External auditors use the same shape. A SOC 2 exception describes the criterion tested, the deviation observed, and its effect on the control objective. ISO 27001 nonconformities carry a required root cause analysis and corrective action, which is the same idea with the cause step made mandatory rather than optional.

Writing internal findings in this structure means they translate directly when an external auditor asks what you already knew and what you did about it.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.