Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon

Browse

33 controls

CC5.3Deploys control activities through policies and proceduresSOC 2Control Activities

Official Requirement

COSO Principle 12: Management deploys control activities through policies that establish what is expected and procedures that put policies into action.

Source: AICPA Trust Services Criteria (2017), incorporating COSO principles

In Plain English

Every significant control in your program traces back to a policy that requires it. The policy says what must happen; the procedure says how to do it; the evidence confirms it was done. This is the criterion that auditors use when they test your policy library, not just whether policies exist, but whether they are current, acknowledged, and enforced through actual operating procedures.

Help us build what matters.

Vote for the next framework, subscribe for updates, and let us know if you'd contribute.

The Trust Services Criteria referenced in this tool are published by the American Institute of Certified Public Accountants (AICPA) and incorporate principles from the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Criteria descriptions are reproduced for reference purposes. All implementation guidance, evidence recommendations, and control language are original work by Truvo Cyber. ISO 27001 and ISO 42001 are standards published by the International Organization for Standardization (ISO). Framework and standard names are the property of their respective owners. This tool is not affiliated with, endorsed by, or certified by AICPA, COSO, or ISO.

© 2026 Truvo Cyber. All rights reserved.

On-premises implementation and evidence

Comprehensive policy library with annual review and management approval

Implementation steps

  1. Maintain all policies in a version-controlled repository (shared drive or intranet) with clear naming conventions: policy name, version number, effective date
  2. Set calendar reminders for annual policy review 60 days before the expiry date, do not let policies expire unreviewed during an audit period
  3. For each policy, document the procedure that implements it: the policy says 'access reviews must be conducted quarterly'; the procedure describes how to run the access review, what tool to use, and how to document it
  4. Management sign-off on policies is required annually; retain the signed approval email or document as evidence

Tools / systems

Evidence artifacts

Evidence frequency: Annual policy review; acknowledgements collected within 30 days of policy publication