System Boundary Definition
Define precisely which services, infrastructure, software, people, procedures and data comprise the system being examined, and what sits outside it, including the treatment of subservice organizations.
Trust Services Category Selection
Select the categories to be examined - security and, where commercially relevant, availability, confidentiality, processing integrity or privacy - based on customer expectation and the commitments the organization actually makes.
System Description Preparation
Prepare management’s description of the system so it accurately presents infrastructure, software, people, procedures and data, along with commitments, system requirements and the complementary controls expected of user entities.
Control Design Suitability
Assess each control for whether its design, if operating as intended, would actually achieve the criterion it addresses - the specific question a Type I examination asks.
Control-to-Criteria Mapping
Map controls to the applicable Trust Services Criteria and identify criteria with no supporting control, weak coverage, or controls mapped optimistically to criteria they do not really satisfy.
Governance Documentation
Prepare the governance, policy and risk documentation the control environment relies on, including the risk assessment process that underpins the common criteria.
Control Owner Preparation
Brief control owners on what they will be asked, what evidence they must produce, and how to describe their control accurately rather than aspirationally.
Point-in-Time Evidence
Assemble the evidence demonstrating that controls are in place and designed as described as of the specified date, and confirm it can be produced on request.
Design Gap Remediation
Close design gaps identified during preparation - missing controls, controls that do not address their criterion, and undocumented processes the description depends on.
Examination Preparation
Prepare the organization for fieldwork: request handling, evidence delivery, walkthrough logistics and a single coordination point for the service auditor.