Repeated findings are useful only when they stay accurate. The SOC 2 Security Default Findings Engine lets an authorized team leader or admin save a reusable starting point against a canonical control criterion. It reduces repeated typing while leaving the actual observation, evidence, scope, and validation inside each project finding.
What this solves
Teams commonly repeat access-review, MFA, logging, vendor-risk, policy, change-control, incident-response, and backup evidence gaps. Free-form wording can blur the difference between a missing control, an operating exception, and missing evidence. That makes ownership and readiness reporting less reliable.
Before you begin
- Sign in as a team leader or team admin with access to the local engine.
- Confirm that SOC 2 Security is the correct Library for the work.
- Choose a recurring issue pattern, not one client-specific finding.
- Remove names, URLs, selectors, credentials, personal data, dates, and evidence from the reusable wording.
- Keep the official AICPA Trust Services Criteria - Security Common Criteria scope and terminology available for reference.
Step-by-step
- Confirm the system boundary, report target, and selected Trust Services Categories.
- Open the Security local engine and locate the most precise Common Criterion.
- Name the reusable gap without claiming that every organization has the same control design.
- Describe the evidence or operating condition that would demonstrate the gap.
- Add remediation that identifies the desired control outcome and accountable process.
- Use the template in a project, then add population, sample, evidence, owner, and period details.
What the default saves
A local default can save the summary, description, remediation guidance, severity behavior, and canonical control criterion mapping. When a reviewer selects it from New Finding, voiqq prefills those values. The new finding still starts Open with Pending validation and must be changed to match the real observation.
Good patterns to predefine
- Periodic access reviews are incomplete, late, or unsupported by retained approval evidence.
- MFA coverage excludes an in-scope identity population or privileged access path.
- Change records do not demonstrate approval, testing, segregation, or deployment evidence.
- Security events are not reviewed or escalated according to the documented process.
- Third-party risk assessments are missing, overdue, or disconnected from remediation.
Check your result
- Separate evidence gaps from control design or operating gaps.
- Do not prefill populations, samples, dates, or management responses.
- Keep attestation conclusions out of readiness templates.
- Confirm the criterion mapping and evidence request support the same issue.
- Require validation before closing the finding.
