Requests for Evidence or Samples from the Auditor
Last updated: March 9, 2026
In the world of SOC 2 compliance, the "Trust Services Criteria" aren't just suggestions—they require proof. An RFE (Request for Evidence) is essentially an auditor’s way of saying, "Show your work." While your automated controls provide the foundation, auditors often need to "sample" specific events to ensure your policies are actually being followed in practice.
Why RFEs Happen
During a SOC 2 audit, auditors select specific instances from your audit period to verify consistency.
Small Teams: Can often bypass heavy RFE cycles by being hyper-proactive with evidence uploads.
Enterprise Teams: Due to the sheer volume of data and complex workflows, RFEs are a standard (and often unavoidable) part of the process.
Common RFE Scenarios
Auditors typically zoom in on areas where human intervention is required. You can expect requests for:
Employee Movement: Evidence of onboarding (background checks, signed NDAs) and offboarding (revoked access logs) for specific individuals hired or terminated during the period.
Code Planning & Changes: Proof that a specific feature followed your development practices around code planing, testing and deployment in segregated environments.
Incident & Disaster Response: If an incident occurred, auditors want to see the "paper trail" showing you followed your own Disaster Recovery or Incident Response plans.
Data Subject Rights (DSR): Documented proof that a user's request to be "forgotten" or to access their data was handled within your defined SLAs.
How Mycroft Simplifies the Process
We know that hunting down screenshots and logs is a productivity killer. Mycroft transforms RFE management from a manual burden into a managed service.
Hands-on Support: For customers on Success Packages or currently in Onboarding, Mycroft handles the heavy lifting of RFE fulfillment.
Value-Add Service: We act as the bridge between you and the auditor, helping to interpret requests, gather the necessary artifacts, and ensure they meet the auditor's rigor.
Proactive Strategy: We help you organize your evidence library early so that when the auditor comes knocking, you’re already holding the keys.
The Bottom Line: You focus on building your product; Mycroft focuses on proving your compliance.