Resources

Compliance Glossary: SOC 2, ISO 27001 and Audit Terms

By the Auditious Compliance TeamLast updated: July 17, 2026

Quick answer

This glossary gives plain-English definitions of the compliance and security audit terms you will meet while pursuing SOC 2 and related frameworks, from Trust Services Criteria and evidence to Type I vs Type II reports and risk registers. Use it as a quick reference alongside our SOC 2 guide and documentation.

Compliance and security audit terms

Definitions are listed alphabetically. Each term links back to the concepts it relates to.

AICPA
The American Institute of Certified Public Accountants, the body that created and maintains the SOC reporting framework.
Attestation
A formal engagement in which a licensed CPA firm examines and reports an opinion on a company's controls. SOC 2 is an attestation, not a certification.
Audit
An independent examination of a company's controls against a defined set of criteria, resulting in a report.
Auditor
The independent, licensed CPA firm that tests a company's controls and issues the SOC report.
Availability
A Trust Services Criterion covering whether a system is operational and accessible in line with its commitments and SLAs.
Common Criteria
The mandatory Security criteria that every SOC 2 report must cover, regardless of which optional criteria are added.
Confidentiality
A Trust Services Criterion covering the protection of information designated as confidential, such as business secrets.
Control
A safeguard or process that reduces risk, such as enforcing multi-factor authentication or reviewing access quarterly.
DPDPA
India's Digital Personal Data Protection Act, which governs how personal data is collected and processed.
EU AI Act
The European Union's risk-based regulation for AI systems, setting obligations that scale with a system's risk tier.
Evidence
Proof that a control operates, such as configuration exports, access lists, logs, or tickets. Auditors test controls by reviewing evidence.
Gap assessment
A review that compares your current controls against a framework's requirements to identify what is missing before an audit.
GDPR
The EU General Data Protection Regulation, which sets rules for protecting the personal data of people in the EU.
HIPAA
A US law that sets requirements for protecting sensitive healthcare information.
Inherent risk
The level of a risk before any controls are applied to reduce it.
Integration
A connection between a compliance platform and another tool that lets the platform pull evidence automatically through an API.
ISO 27001
An international standard for building and operating an information security management system (ISMS).
Penetration test
A simulated attack used to find security weaknesses. It is often expected as part of a SOC 2 program.
Privacy
A Trust Services Criterion covering how personal information is collected, used, retained, and disposed of per a privacy notice.
Processing integrity
A Trust Services Criterion covering whether system processing is complete, accurate, timely, and authorized.
Residual risk
The risk that remains after controls have been applied to reduce the inherent risk.
Risk assessment
The process of identifying and evaluating risks to your systems and data. It is a required control for SOC 2 and ISO 27001.
Risk register
A living record of identified risks, including each risk's owner, score, treatment, and the controls that address it.
Security
The mandatory Trust Services Criterion covering protection against unauthorized access, disclosure, and misuse. Also called the Common Criteria.
SOC 1
A SOC report on controls at a service organization that are relevant to its clients' financial reporting.
SOC 2
A SOC report on controls for security, availability, processing integrity, confidentiality, and privacy. The common security standard for B2B SaaS.
SOC 3
A short, general-use version of a SOC 2 report that can be shared publicly as a trust seal.
SSAE 18
The attestation standard under which SOC audits are performed by CPA firms.
Trust Services Criteria (TSC)
The five categories SOC 2 is scoped around: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Only Security is mandatory.
Type I
A SOC report on whether controls are suitably designed at a single point in time.
Type II
A SOC report on whether controls operated effectively over a period, usually 3 to 12 months.
Vendor risk
The risk introduced by third-party vendors and subprocessors that handle your data or systems.

Frequently asked questions

More resources

4.8/5 from Auditors100+ IntegrationsAudit Included

Compliance shouldn't
be a deal blocker.

Auditious automates evidence collection, enforces controls, and keeps you audit-ready 24/7.

  • Trust Center live in a day
  • AI agents that collect evidence while you build
  • Policies that write, version, and enforce
  • Expert compliance support when you need it
  • 100+ integrations. Zero manual chasing.

One program. Multiple frameworks. Zero extra work.

Compliance framework certifications

See your compliance timeline.

Get a personalized readiness report in 15 minutes, tailored to your stack and team size.

Quick callQuote emailed afterNo contract to sign

By submitting, you agree to our Terms and Privacy Policy.