COSO Principle 5 — The entity holds individuals accountable for their internal control responsibilities.
Also written as CC 1.5, TSC CC1.5, SOC2 CC1.5, SOC 2 Type 2 CC1.5.
Accountability for internal control is one of 5 criteria in the Control Environment (CC1) series of the Security (Common Criteria) category. COSO Principle 5 — The entity holds individuals accountable for their internal control responsibilities. CC1 criteria come from the COSO framework rather than from security practice, so the evidence is governance paperwork — charters, minutes, signed acknowledgements — and it usually lives with HR, legal, or the board rather than with the security team.
When preparing for a SOC 2 audit against CC1.5, gather artefacts such as:
CC1.5 corresponds to the following ISO 27001:2022 Annex A control(s): A.5.2, A.5.4, A.5.36, A.6.4. If you already run an ISO 27001 ISMS, map your existing evidence for these controls to CC1.5 rather than duplicating work.
All CC1 Control Environment criteria →
Yes. CC1.5 sits in the Common Criteria, which apply to every SOC 2 engagement regardless of which additional categories you scope in — there is no SOC 2 report that omits them.
In a Type 1 report the auditor assesses design only — does a control exist at a point in time that would meet CC1.5 if it operated. In a Type 2 report they also test operating effectiveness by sampling evidence from across the review period, typically 3 to 12 months. That difference is why Type 2 evidence has to be continuous rather than assembled the week before fieldwork.
A control that fails becomes an exception, which the auditor describes in the report along with management's response. Exceptions do not automatically make a report "failed" — a SOC 2 report is an opinion, not a pass/fail certificate — but a qualified opinion is what customers notice, so remediate and re-test before fieldwork closes where you can.
Yes — CC1.5 aligns with ISO 27001:2022 Annex A control(s) A.5.2, A.5.4, A.5.36, A.6.4. If you already run a certified ISMS, re-point that evidence rather than building a parallel set; the underlying control is the same and only the reporting format differs.