SOC 2 internal auditor reviewing cybersecurity and data security compliance procedures in a corporate environment

Overview

Certified SOC 2 Internal Auditor Training is designed to provide professionals with the knowledge and skills required to audit SOC 2 controls effectively and support organisational compliance.

The course covers SOC 2 fundamentals, Trust Services Criteria (TSC), COSO framework, risk assessment, documentation, and audit processes. Participants will gain practical understanding of how to plan, conduct, and report SOC 2 internal audits while evaluating control effectiveness and identifying compliance gaps.

This programme is suitable for professionals involved in compliance, risk management, IT governance, and auditing who aim to develop SOC 2 internal auditing expertise.

Curriculum

This programme consists of eleven structured learning sessions designed to develop practical competence in SOC 2 internal auditing and compliance processes.

Session 1: Overview of SOC 2 and its Advantages
Session 2: COSO Framework for SOC 2 Compliance
Session 3: Risk Assessment Methodology for SOC 2
Session 4: SOC 2 Requirements and Controls
Session 5: SOC 2 Documentation (TSC Policies, Procedures, Evidence)
Session 6: Steps for SOC 2 Implementation in a Service Organisation
Session 7: SOC 2 Audit Process
Session 8: Performing an Audit (Auditor’s Perspective)
Session 9: SOC 2 Terms and Definitions
Session 10: SOC 2 and ISO 27001 Mapping
Session 11: SOC 2 Internal Audit Records

Course Delivery

This programme is delivered through a combination of structured learning materials and assessment activities designed to support practical understanding and application.

• Video lectures with audio-visual presentations
• Downloadable handouts and supporting documentation
• Practical templates, audit checklists, and reference materials
• Session-based assessments and a final examination

Programme Outcomes

• Understand SOC 2 concepts, Trust Services Criteria, and COSO framework
• Conduct SOC 2 risk assessments and evaluate control effectiveness
• Understand SOC 2 documentation and evidence requirements
• Develop skills to plan, conduct, and report internal audits
• Identify nonconformities and control weaknesses
• Understand SOC 2 and ISO 27001 integration

Who Should Attend

This programme is designed for professionals involved in compliance, governance, and internal auditing.

• Internal auditors and compliance officers
• IT security and governance professionals
• SOC 2 implementation teams
• Consultants supporting SOC 2 or ISO 27001 projects
• Risk management and assurance professionals
• SaaS and cloud service providers

Prerequisites

• No prior SOC 2 auditing experience required
• Basic understanding of IT or information security is beneficial

Faculty & Facilitators

This programme is delivered by Qualified Skills Development Facilitators (SDFs) who are certified Lead Auditors and industry-experienced professionals. Our facilitators bring practical auditing expertise and real-world implementation experience, ensuring that training remains relevant, applied, and aligned with current industry standards.

Assessment & Certification

Each programme includes structured module summaries designed to reinforce key learning outcomes and support assessment preparation. Participants are required to complete a final online assessment to demonstrate competency. Upon successful completion of the assessment requirements, a formal course certificate is issued. Certificates are available for download and may be independently verified using the issued certificate reference number.

Programme Snapshot

Duration:
Delivery Mode:
Accreditation:

How It Works

1. Enrol Online
2. Receive Instant Access
3. Study at Your Own Pace
4. Complete Online Assessment
5. Receive Your Certificate

Enquire Now

Explore Related Courses

IT service management auditor reviewing service delivery and operational compliance procedures in a corporate environment
ISO/IEC 20000-1:2018 Lead Auditor Training providing practical knowledge of IT service management system auditing and certification processes.
IT service management professionals reviewing service delivery and support procedures in a corporate environment
ISO/IEC 20000-1:2018 Awareness Training providing essential knowledge of IT service management system requirements and certification processes.
Information security professionals reviewing cybersecurity and data protection procedures in a corporate office environment
ISMS Foundation Training ISO/IEC 27001:2022 providing essential knowledge of ISMS requirements, documentation, and certification processes.
Cart (0 items)

To Lead Our Clients To Better Performance

Contact Info

Mon - Fri : 8:00 -16:30
+27 31 020 2248
admin@m-theory.co.za

Office Address

First Floor Building 2
Gleneagles Office Park
10 Flanders Drive
Mount Edgecombe
Durban
Kwa-Zulu Natal
4302