一位前德勤审计员通过其创业公司Chiaro开源了完整的SOC 2审计方法论,旨在提高合规行业的透明度[1]。该开源项目包含86项控制、355个测试属性、61项信任服务标准、22个证据来源、498个校准示例和完整的测试流程文档[1]。其中498个校准示例中,303个用于纠正AI过于严苛的判断,195个用于纠正AI过于宽松的判断[1]。该项目采用知识共享许可证(CC BY 4.0)发布[1]。
企业可以使用相同的审计框架进行自我评估和正式审计[1]。仅持证CPA事务所可签署SOC 2意见书[1]。用户可以访问app.chiarohq.com平台使用该方法论[1]。
A former Deloitte auditor has released a comprehensive SOC 2 audit methodology as open-source software through their startup Chiaro, aiming to democratize compliance processes for organizations seeking security certifications.[1] The open-source framework encompasses 86 controls, 355 test attributes, and 61 Trust Services Criteria, providing enterprises with a standardized auditing approach they can apply for both self-assessment and formal audit procedures.[1]
The release includes extensive supporting materials designed to improve audit consistency and reduce bias in the evaluation process.[1] The methodology incorporates 498 calibrated examples—303 instances where the framework corrected overly stringent AI assessments and 195 cases correcting assessments that were too lenient—along with documentation of 22 evidence sources and complete testing workflows.[1] The entire project is licensed under Creative Commons BY 4.0, making it freely accessible to the public.[1]
While the open-source framework enables broader access to SOC 2 audit standards, the issuance of official SOC 2 attestation opinions remains restricted to CPA firms holding the appropriate credentials.[1] The platform is available at app.chiarohq.com.[1]