Trust Service Criteria (TSC)
Definition
The five criteria used to evaluate controls in a SOC 2 engagement: Security, Availability, Processing Integrity, Confidentiality, and Privacy. The criteria are defined in the AICPA's 2017 Trust Services Criteria publication and updated periodically.
- Number of criteria
- Five
- Criteria
- Security, Availability, Processing Integrity, Confidentiality, Privacy
- Source
- AICPA 2017 Trust Services Criteria publication
- Update status
- Updated periodically
- Used in
- SOC 2 engagements
Common questions
Does every SOC 2 report cover all five Trust Service Criteria?+
No, Security is the only mandatory criterion and is often called the common criteria. An organisation scopes the engagement to include only the additional criteria relevant to its service, such as Availability for a hosting provider.
Why would a forensic or fraud examiner care about TSC when reviewing a vendor?+
A SOC 2 report scoped against these criteria gives independent evidence of what controls a third-party vendor actually had in place during a period, which is useful when tracing whether a breach or data-handling failure stemmed from a control gap on the vendor's side.
Related terms
- Complementary User Entity Controls (CUECs)
- Controls that the service organisation's system design assumes the user entity will implement. Listed in the SOC 2 report. If the user...
- SOC 1 (SSAE 18)
- A report on controls at a service organisation that are relevant to user entities' financial statements. Governed by Statement on Standards for...
- SOC 2
- A report on controls relevant to the AICPA's Trust Service Criteria. Produced under the AT-C 205 attestation standard. Covers Security (mandatory) plus...
- Type I Report
- An attestation report that provides an auditor's opinion on whether controls are suitably designed to meet the stated control objectives, assessed at...
- Type II Report
- An attestation report that provides an auditor's opinion on both the suitability of design and the operating effectiveness of controls over a...