During a SOC 1 or SOC 2 Type II audit, the independent auditor tests your controls over a historical observation period. If they select a sample of 25 items and find even a single instance where the control did not operate as defined, they must record an exception (also referred to as a control deviation) in the final report.

Discovering an exception is stressful, but it is not a reason to panic. Many organizations receive reports containing exceptions and still satisfy their customers’ security questionnaires.

Here is how to manage, remediate, and explain SOC exceptions.


What is a SOC Exception?

An exception means a control failed to operate consistently during the testing period. Common examples include:

  • Access Control: A developer was terminated on May 10, but their database credentials were not disabled until May 17, violating the policy’s 24-hour termination window.
  • Change Management: Out of a sample of 25 software updates, 1 code change was deployed without a documented peer review approval.
  • Operations: Centralized backups ran daily, but management missed documenting one of the required quarterly backup restoration drills.

How to Manage Exceptions

When an auditor flags a control exception, follow these three steps:

1. Validate the Finding

Before accepting the exception, verify the auditor’s data. Check if there was a misunderstanding (e.g. they tested a staging account assuming it was a production user, or missed a compensatory control log that was filed in a separate directory).

2. Identify the Root Cause

If the exception is valid, determine why the failure happened. Was it a manual oversight, a software glitch in your provisioning tool, or an unrealistic policy window?

3. Draft a “Management Response” (Section 5)

A SOC report allows you to include a formal response (typically in Section 5) to explain the exception to readers. This is your opportunity to demonstrate control ownership. A strong response should:

  • Acknowledge the exception neutrally.
  • State the root cause clearly without making excuses.
  • Detail the concrete remediation steps implemented to ensure the issue does not recur.

Strategic Management Response Example

Exception Finding: Out of a sample of 25 employees hired during the review period, two did not complete security awareness training within the required 30-day onboarding window.

Management Response: Management acknowledges this exception. The two referenced employees completed their training on Day 34 and Day 38 respectively. To remediate this issue, management has integrated the security training platform with our HR onboarding software (Gusto), which now automatically locks accounts if training is not completed within the 30-day policy window. No similar exceptions occurred after this integration.


Common Exceptions and Remediation Strategies

Exception FlagRoot CauseRemediation Strategy
Delayed Termination deactivationManual ticketing delayAutomate de-provisioning via identity provider (Okta/Entra) triggers.
No peer approval logMerge restrictions bypassedEnforce branch protection configurations programmatically in GitHub/GitLab.
Missed Backup Restore drillScheduling oversightPut recurring calendar triggers and assign specific ownership to a lead engineer.

Strategic CTA for Compliance Teams

Managing exceptions is much easier when you identify control gaps during a mock audit phase. Working with an experienced readiness team helps you surface operational issues and fix them before formal fieldwork begins.

Learn how we help you design, monitor, and remediate controls: Expert Insights SOC 2 Compliance Services.