SOC 2 CC1.1: Commitment to Integrity and Ethical Values

The choices people make under pressure

A customer sends a security questionnaire late on Friday, asking whether every production change receives an independent review. The standard process requires that review, while emergency changes follow a separate procedure. With a sales deadline approaching, the team faces pressure to provide a simple answer that may leave out an important qualification.

Who is responsible for validating the response, and how should the team resolve an instruction to provide information it knows is inaccurate? The answers reveal whether ethical expectations influence decisions when commercial interests are at stake.

SOC 2 CC1.1 addresses these expectations within the control environment, the organizational foundation supporting internal controls. Controls are policies and procedures designed to manage risk and help the organization achieve its objectives.

The AICPA Trust Services Criteria state the core requirement: “The entity demonstrates a commitment to integrity and ethical values.” Organizations demonstrate that commitment through leadership behavior, communicated standards, and consistent responses when conduct falls short.

The related points of focus address leadership’s example, standards of conduct, evaluation of adherence, and timely responses to deviations. Relevant expectations extend to contractors and vendor personnel. These points help organizations interpret the criterion without prescribing a single set of policies or tools.

This is the first article in our SOC 2 Guide, which examines the common criteria used for the Security category in a SOC 2 Type 2 examination. The fictional company examples illustrate possible approaches rather than mandatory implementations.

Make the rules clear

A useful code of conduct connects ethical expectations to situations employees and contractors encounter in their work. Assign an owner, obtain approval from the appropriate leader, and make the current version readily accessible. Define who is covered and how the expectations apply to people working on the organization’s behalf.

The standards might require people to:

  • Represent the organization’s security practices accurately.
  • Use customer data only for authorized purposes and within approved tools.
  • Report errors promptly, including their own.
  • Raise concerns when instructions conflict with established expectations.
  • Disclose personal interests that could influence business decisions.

Select topics relevant to the business, and involve HR or legal advisers when wording concerns employment rights or legal obligations.

Leadership decisions should reinforce these standards. Rewarding a misleading sales response because it secured a contract undermines the stated expectation of honesty. Employees judge the organization’s priorities through the conduct it recognizes, tolerates, and corrects.

Show people how to use the rules

In the questionnaire example, the person preparing the response should consult the owner of the change-management process. That owner can verify how the standard and emergency procedures operate and identify the qualifications needed for an accurate answer.

When a yes-or-no response would create a misleading impression, the team should ask the customer how to provide explanatory context. If an earlier response was inaccurate, arrange a correction through the appropriate customer contact.

Use realistic scenarios during onboarding and when expectations change. Ask participants to explain their decisions and identify the appropriate escalation contact. A policy acknowledgment records receipt or acceptance; a discussion provides additional insight into whether personnel understand how to apply the standard.

Give concerns a clear path

Establish a primary reporting contact and an alternative route for concerns involving that person. Both contacts should understand their responsibilities and have the authority or access needed to initiate an appropriate response.

Assign responsibility for receiving each report, selecting the appropriate reviewer, and monitoring follow-up through completion. Store case information in a restricted location, with access limited to people who need it for their responsibilities.

Distinguish confidentiality from anonymity. A small organization may be able to restrict disclosure while being unable to conceal a reporter’s identity. Describe these limitations accurately and make only commitments the process can support.

Communicate protection against retaliation for good-faith reporting. Assess the facts before determining a response, recognizing that unclear expectations, inadvertent errors, and deliberate misconduct may require different corrective actions. Apply the standards consistently, including to senior personnel.

Document the reviewer, conclusions, and resulting actions. Involve HR, legal, or security specialists when the nature of the concern requires their expertise.

What this could look like at 5 people

The founder could approve a concise code of conduct and lead a discussion of two realistic scenarios. Dated acknowledgments could be maintained in a policy tool or a simple record, including contractors subject to the same expectations.

Identify an alternative contact for concerns involving the founder, such as another owner, a board member, or an outside adviser. Confirm that the person accepts the responsibility and understands how to respond before presenting them as a reporting contact.

A restricted spreadsheet may be sufficient to record concerns, decisions, and outstanding actions. Establish coverage for periods when the responsible person is unavailable.

Evidence to keep: the approved code, dated acknowledgments, discussion notes, designated reporting contacts, and records of actual concerns and follow-up.

A small headcount can coexist with significant exposure to sensitive data. Simple tools are appropriate only when the process remains adequate for the organization’s risks.

What this could look like at 100 people

As the organization grows, the founder may no longer participate in every onboarding session or receive every concern. Defined responsibilities across HR, management, and security help maintain consistency without relying on informal communication.

Include conduct standards in onboarding, track acknowledgment of the current version, and follow up on omissions. Reconcile completion records against the employee and contractor population that should be covered. Equip managers to receive concerns and direct them to the appropriate reviewer.

Maintain a restricted case register with an accountable owner for each issue, and review recurring patterns. Repeated misuse of customer data, for example, may indicate unclear expectations or a lack of suitable approved tools.

Evidence to keep: onboarding records, complete employee and contractor populations, acknowledgment reports, documented follow-up on missed steps, manager guidance, and case records showing decisions and actions.

A final completion rate of 100% can conceal acknowledgments obtained after the required deadline. Retain sufficient history to demonstrate when each activity occurred.

What this could look like at 1,000 people

A larger organization may need to maintain consistent expectations across business units, countries, and reporting structures. A common code of conduct can provide the foundation, supported by local guidance or translations where appropriate.

Define how HR, legal, security, and compliance teams coordinate case handling. Establish which serious or recurring concerns require escalation to senior leadership or the board, with clear responsibility for ensuring that escalation occurs.

Provide consistent guidance to case handlers and restrict access to detailed files. Leadership reporting can focus on patterns, overdue actions, and decisions requiring oversight while limiting unnecessary disclosure of personal information.

Evidence to keep: approved standards and local guidance, training and acknowledgment records, case-handling procedures, and documented leadership reviews and follow-up.

Low reporting volumes require careful interpretation. They may reflect a healthy environment, limited awareness of reporting routes, or reluctance to raise concerns. Evaluate the figures alongside other evidence about how the process operates.

Choose controls that fit the business

These examples illustrate differences in implementation rather than headcount-based requirements. CC1.1 does not automatically require a hotline, a particular application, or annual training at a specified company size.

Consider the services provided, data handled, workforce arrangements, and commitments made to customers. Assign ownership and an appropriate frequency to recurring activities, balancing risk exposure with a process the organization can perform reliably.

Determine how relevant conduct expectations are communicated to contractors and vendor personnel working on the organization’s behalf. Their communication and acknowledgment processes may differ from employee onboarding; document the approach and retain evidence of its operation.

Keep evidence through the audit period

A SOC 2 Type 2 examination addresses the suitability of control design and operating effectiveness over a specified period. The AICPA SOC 2 guide explains the examination framework.

Retain evidence as activities occur, including relevant policy versions, acknowledgment dates, review records, and corrective-action follow-up. Collecting documents at the end of the period cannot establish that an activity occurred when it was actually missed.

If no concerns were reported, document that fact accurately rather than creating artificial cases. Retain evidence, where applicable to the control, that the reporting channel was available and reviewed by the responsible person.

Agree with the auditor on an appropriate method for providing sensitive case information. Limit disclosure to the detail needed, restrict access, and apply suitable retention arrangements.

The auditor determines the testing procedures and evidence necessary for the examination. These implementation examples do not guarantee a particular audit opinion.

Start with one useful discussion

Select a realistic situation your team could encounter this week. Ask participants to identify the responsible decision-maker, the information needed, and an alternative escalation route if their manager is involved in the concern.

Document any gaps, assign responsibility for corrective action, and verify the outcome. This creates a practical starting point and evidence of how the organization applies its ethical expectations.

Need help with CC1.1?

Genius GRC helps organizations establish practical controls and organize supporting evidence for SOC 2. To identify an approach suited to your business, discuss your SOC 2 needs with us.

Visit the SOC 2 Guide for the full series. The next article will examine CC1.2 and oversight of internal control.

This article provides general guidance. Adapt the examples to your examination scope and obligations with your advisers and auditor.

More Posts

Get the House In Order: Say It, Show It, Prove It with ISO 42001 Internal Audits

As AI regulation accelerates, ISO 42001 offers a blueprint for responsible governance — and internal audits are where that blueprint meets reality. If you’re working towards your ISO 42001 certification, you are well aware of the fact that an internal audit is a key component of the process. Unlike an

Five Considerations When Selecting a vCISO Firm: The Right Partnership Matters

More than Checking a Box In today’s world, it’s very common for startups to outsource key roles that are essential for business operations but don’t justify a permanent spot on the org chart. For many organizations, a vCISO (virtual Chief Information Security Officer) is a more cost-effective way to provide

How to Conduct an AI Impact Assessment: The Path to ISO 42001 Certification

A key component of ISO 42001 certification is conducting an Artificial Intelligence Impact Assessment (AIIA).  This assessment helps your organization identify how your AI program creates both opportunities and risks to relevant stakeholders and society at large. This assessment is vital to determine what resources are needed to address negative