Soc 2 Type IiCompliance AuditTrust Services CriteriaVendor AssessmentCef Security

SOC 2 Type II Compliance for Church Extension Funds

By 15 min read
SOC 2 Type II Compliance for Church Extension Funds

A board meeting ends with a familiar assignment: provide evidence that the systems handling investor notes, church loans, payment records, and personal information are secure and consistently controlled. The finance team has policies, spreadsheets, approval emails, and application logs scattered across different systems. Someone asks for a SOC 2 Type II report, and the organization discovers that having controls on paper isn't the same as proving they operated throughout an audit period.

For Church Extension Funds, this matters beyond a technology questionnaire. Your organization accepts investments from church members and congregations, lends those funds for construction and land projects, manages sensitive borrower information, and operates under state securities requirements rather than FDIC insurance. SOC 2 Type II compliance gives boards, investors, auditors, and partner organizations an independent view of how controls were designed and whether they worked over time.

The right approach isn't to collect more policies for a binder. It's to build disciplined daily operations that produce reliable evidence while your fund continues serving its ministry mission.

Why Your Board Is Asking About SOC 2 Type II

A CEF CFO may first encounter the request in a vendor questionnaire. A bank, denominational partner, technology provider, or institutional investor asks whether the fund has a SOC 2 Type II report, which Trust Services Criteria were included, and whether the report covers the systems that process loans and investor notes. The question can feel disproportionate to the size of the organization, especially when the finance team is already managing reconciliations, 1099 reporting, escrow activity, and construction draws.

The request has become normal because financial operations now depend on interconnected systems and external service providers. A weakness in access management, change approval, payment processing, or monitoring can affect investor records and borrower data even when the underlying mission is charitable. Faith-based institutions aren't exempt from operational risk because they serve churches. Their stewardship obligations make reliable controls more important, not less.

SOC 2 reporting traces back to 2010, when the AICPA announced an attestation standard that later evolved into the SOC reporting suite, including SOC 2 for Security, Availability, Processing Integrity, Confidentiality, and Privacy (quality guidance on SOC 2 history and Type II assurance). The framework became a recognized way to demonstrate sustained control operation, rather than merely asserting that procedures exist.

The business reason for taking the request seriously

The board isn't asking for a technology badge. It wants confidence that management can identify risk, assign responsibility, preserve evidence, and respond when a control fails. Investors want assurance that their records are handled carefully. Auditors need a dependable trail for transactions and access decisions. Partner organizations want to understand whether your controls are compatible with their own risk requirements.

That broader environment includes frameworks such as enterprise DORA security, which reflects how financial organizations increasingly evaluate operational resilience and technology risk across their providers. The frameworks differ, but the governance lesson is consistent: management must know which systems matter, who can change them, and how the organization proves that safeguards operate.

A practical first step is to document the systems supporting the general ledger, loan servicing, investor notes, cash operations, reporting, and customer records. CEFs can also review their governance, risk, and compliance services to clarify ownership before an auditor or board committee asks for evidence.

Board perspective: A Type II report doesn't replace sound judgment. It gives the board a structured, independent basis for asking better questions about operational discipline.

Type I vs Type II and Why the Difference Matters

A SOC 2 report can look reassuring while leaving a practical question unanswered: do employees follow the documented controls every time the process runs? SOC 2 Type I evaluates whether controls are suitably designed at a particular point in time. SOC 2 Type II evaluates whether those controls operated effectively over a defined observation period (SOC 2 audit timeline guidance).

For a CEF, a Type I examination may confirm an access review policy, an approval workflow, and a documented backup process on the examination date. Type II examines the operating record. Did staff complete access reviews, follow approvals, and maintain backups throughout the period? That distinction exposes the gap between an intended process and a process that people and systems execute consistently.

Type I vs Type II Comparison

Aspect Type I Type II
Primary question Are controls suitably designed? Did controls operate effectively?
Testing approach Review at a specific point in time Test dated evidence across an observation window
What it reveals Whether the control structure exists Whether people and systems followed the structure consistently
Best practical use Early readiness, a defined procurement checkpoint, or a newly established control environment Enterprise procurement, customer assurance, and sustained operational trust
Evidence expectation Design documentation and point-in-time support Logs, approvals, reviews, tickets, and records covering the full period
Risk shown A control may look appropriate but remain untested in practice Exceptions and execution gaps can surface through repeated samples

Type I still has a practical role. A newly formed technology function can use it to identify weaknesses before starting a longer examination. A buyer may accept it temporarily when the service is low risk or the relationship is still under review. That decision should be explicit, documented, and tied to the actual service scope.

For systems that process investor transactions or maintain loan records, Type II provides stronger assurance because it tests operating effectiveness over time. The observation period is commonly at least three months and often six to twelve months, according to neutral quality guidance. A Type II examination therefore requires more than policies and screenshots. It requires dated logs, approvals, access reviews, tickets, and other records that remain available across the full window.

The operational burden is easy to underestimate. One missed review, late approval, or incomplete ticket can create an exception during sampling. Finance and operations leaders should assign evidence owners, define collection dates, and review gaps before the auditor requests samples. Continuous evidence management matters more than assembling a polished folder at the end.

A Type I report has a narrower conclusion, indicating design suitability without testing operating effectiveness. When a vendor can provide only Type I, ask what changed after the report date, when the Type II period will begin, and whether management can provide current control evidence between examinations.

The Five Trust Services Criteria Explained

SOC 2 uses five named Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy (Trust Services Criteria overview). Security is foundational. The other criteria should reflect the services provided and the commitments made to customers.

A diagram illustrating the five SOC 2 trust services criteria: security, availability, processing integrity, confidentiality, and privacy.

Security

Security asks how the organization protects systems and information from unauthorized access, alteration, or destruction. For a CEF, that includes role-based access to loan servicing, investor note administration, the general ledger, cash management, and reporting.

Auditors may examine user provisioning, termination procedures, privileged access, authentication, encryption, vulnerability management, incident response, and monitoring. The finance team should be able to identify who approved access, which role was assigned, and whether access was removed when responsibilities changed.

Availability

Availability concerns whether systems remain accessible for their intended operational use. It reaches beyond uptime. A CEF should connect availability controls to payment processing, investor statements, loan schedules, cash visibility, and disaster recovery.

Evidence can include backup records, recovery testing, incident tickets, capacity monitoring, continuity plans, and documented service commitments. A backup policy without proof that backups completed and recovery procedures were tested leaves a material gap.

Processing Integrity

Processing Integrity addresses whether transactions are complete, accurate, timely, and authorized. This criterion is especially relevant to daily interest accrual, amortization, payment application, investor note balances, fee calculations, and general ledger postings.

Control examples include reconciliations, exception reports, maker-checker approvals, validation rules, and review of scheduled jobs. A control may be well designed yet still fail if staff can't show that someone reviewed rejected payments or investigated an unexpected balance.

Confidentiality

Confidentiality protects information designated as sensitive. Loan applications, financial statements, investor records, bank details, and internal board materials may fall within this category depending on the system and commitments in scope.

The practical controls include least-privilege access, encryption, data classification, retention rules, secure transmission, and restrictions on exports. Finance leaders should ask where confidential files are stored and whether downloads, shared folders, and external transfers create uncontrolled copies.

Privacy

Privacy governs the collection, use, retention, and disclosure of personal information. Investor notes often involve individual investors, while borrower files may contain contact, tax, and financial information.

A privacy program should define what information the organization collects, why it uses it, how long it retains it, and who can disclose it. The internal controls framework can help finance and operations leaders connect these technology expectations to the broader control environment.

The criteria aren't a checklist to select without thought. Scope should follow the services and risks that matter to investors, churches, employees, and partner organizations.

Audit Timeline and Evidence Requirements

The operational burden of SOC 2 Type II is continuity. A typical engagement includes readiness work followed by an observation period that may last several months. The audit tests whether controls operated across the stated period, not whether the organization assembled convincing files at the end.

The sequence should be managed as an operating process:

  1. Scope and readiness: Management defines the systems, services, criteria, control owners, and evidence sources.
  2. Control operation: Staff perform each control according to its approved cadence from the observation period's first day.
  3. Evidence collection: Systems and control owners preserve dated artifacts as work occurs.
  4. Audit fieldwork: The CPA firm tests design and operating effectiveness.
  5. Reporting: The auditor issues an opinion on the controls and the stated period.

A visual timeline infographic detailing the stages and requirements for a SOC 2 Type II compliance audit.

Day one sets the baseline

Controls introduced halfway through the observation period cannot establish performance for the missed months. Financial platforms should generate evidence from the first day, including system logs, access approvals, review sign-offs, change records, incident documentation, and reconciliation support (Type II controls and full-period evidence).

Periodic controls create a frequent failure point. A quarterly access review needs a complete cycle within the reporting period so the auditor can sample dated artifacts and verify remediation (SOC 2 compliance timeline guidance). A late review, missing sign-off, or undocumented exception follow-up leaves the organization with a policy but weak evidence that the policy operated.

Practical rule: Design evidence collection around the control cadence, not around the date the auditor sends the request list.

Incomplete evidence across the observation period causes avoidable delays. Access reviews, change management, vendor risk, incident response, and monitoring logs require support throughout the window, not a final folder assembled before fieldwork (guidance on passing a SOC 2 Type II audit).

CEFCore should assign one accountable owner to each control, define where evidence resides, and review exceptions monthly or quarterly according to the control's cadence. The owner must know what acceptable evidence looks like and what happens when a control is missed.

Board committees do not need every log. They do need reporting on overdue reviews, unresolved exceptions, material changes, and remediation status. For legal and operational context around cloud controls, the guide from By Design Law Firm supplements the auditor's technical requirements.

Preparing Your Organization and Evaluating Vendors

Preparation starts with scope, not software. Identify the services that support investor notes, church loans, payment processing, cash operations, the general ledger, reporting, and customer records. Then document the control objective for each risk, the responsible person, the evidence produced, and the escalation path when the control doesn't operate as planned.

Internal preparation

Use a readiness review to identify gaps before the formal examination. Pay particular attention to controls that are easy to describe but hard to execute consistently:

  • Access reviews: Confirm that reviewers examine actual user access, record approval, and remove or escalate inappropriate permissions.
  • Change management: Preserve requests, testing results, approvals, implementation records, and post-change review.
  • Vendor risk: Maintain due diligence, contracts, service descriptions, reports, and follow-up for exceptions.
  • Incident response: Record alerts, decisions, communications, containment actions, and lessons learned.
  • Processing controls: Reconcile subledgers to the general ledger and document review of exceptions, failed jobs, and unusual transactions.

Legacy spreadsheets often create evidence ambiguity. A spreadsheet can calculate a balance, but it may not show who changed a formula, who approved the result, or whether the same process was followed each period. If spreadsheets remain in use, protect the files, restrict editing, preserve version history, and require documented review.

A graphic outlining steps for internal preparation and a vendor assessment checklist for SOC 2 compliance.

Vendor assessment questions

A vendor's SOC 2 report only helps if it covers the service you're buying. Request the report, not just a marketing summary, and ask these questions:

  • Scope match: Does the report cover the application, environment, and services used by your CEF?
  • Criteria relevance: Were the criteria tested relevant to confidentiality, availability, processing integrity, or privacy in your use case?
  • Period coverage: What observation period does the report cover, and how current is it?
  • Exceptions: Did the auditor identify exceptions, and did management explain remediation?
  • Customer responsibilities: Does the report identify controls your organization must operate?
  • Opinion: Did the CPA firm issue an unqualified opinion, or are there qualifications that affect reliance?

A report ending six months ago isn't automatically useless, but it needs current context. Ask for a bridge letter where appropriate, evidence of material changes, and the date of the next report. Use a structured vendor selection criteria framework so procurement, finance, compliance, and IT evaluate the same facts.

For an additional visual reference when organizing third-party reviews, the Freeform Company vendor guide can complement your internal checklist. The decision should still rest on scope, evidence, exceptions, and operational fit, not on the presence of a logo.

Beyond the Audit and Ongoing Governance

A SOC 2 Type II report is a foundation. It isn't the entire compliance program, and it doesn't remove management's responsibility after the report is issued. A 2025 compliance benchmark reported that SOC 2 has shifted from a competitive differentiator to a baseline expectation, while the vast majority of organizations recognize that SOC 2 alone isn't sufficient for the current regulatory environment (A-LIGN compliance benchmark coverage).

That conclusion has practical consequences for CEF leadership. State securities obligations, IRS 1099 reporting, GAAP financial reporting, privacy requirements, contractual commitments, and third-party risk don't disappear because a CPA has tested a SOC 2 scope. Each framework answers different questions, and the organization should map overlapping controls rather than operate separate programs that duplicate work.

Build an evidence operating rhythm

The strongest post-audit program treats evidence as a normal operating output. Management should review access changes, incidents, vendor status, exceptions, reconciliations, and system changes on the cadence each control requires.

Cloud logging, zero-trust expectations, and AI governance considerations are also shaping security programs, according to the benchmark commentary cited above. A CEF doesn't need to adopt every new concept at once. It does need a process for assessing whether new technology changes the risk to investor information, borrower data, payment operations, or financial reporting.

A useful governance package for the board includes:

  • Control status: Which controls operated, which were late, and which had exceptions.
  • Risk register: What risks changed, who owns them, and what remediation remains open.
  • Vendor oversight: Which providers support critical services and whether current assurance is available.
  • System change review: What changed in loan, note, cash, or reporting workflows and how management tested the change.
  • Mission impact: Whether control investments protect stewardship while preserving affordable lending and responsive service to churches.

Microsoft describes SOC 2 Type 2 for some services as a rolling 12-month run window (Microsoft SOC 2 documentation). That model reinforces the operational point: compliance should be maintained continuously, not rebuilt before each board presentation or audit request.

Common Misconceptions and Strategic Considerations

More controls don't automatically create better audit readiness. A large control catalog can overwhelm a small finance and IT team, especially when nobody owns the evidence or staff can't complete the required reviews. Reliable execution beats impressive documentation.

SOC 2 Type II also isn't a one-time destination. The report describes controls and operating effectiveness over the stated period, and the organization must continue monitoring changes, access, vendors, incidents, and processing after the auditor leaves. A report is valuable assurance, but it isn't a guarantee that every future transaction or system change will be handled correctly.

Not every SOC 2 report provides the same assurance. Scope, criteria, observation period, exceptions, customer responsibilities, and the auditor's opinion all affect what a board or vendor can reasonably conclude. A report for a hosted application may not cover the separate payroll system, custom database, or spreadsheet process your CEF relies on.

The strategic question is how to invest in controls without diverting resources from ministry. Start with risks that could harm investors, borrowers, financial reporting, or the fund's ability to lend. Consolidate duplicated workflows where possible, use approvals that fit actual authority levels, and make evidence collection part of daily operations rather than an annual administrative project.

For mission-driven finance: Stewardship includes protecting the information and systems entrusted to the organization, not just balancing the ledger.

A board should expect management to explain what SOC 2 Type II proves, what it excludes, which exceptions remain open, and how the program supports state securities compliance, IRS reporting, GAAP reporting, and responsible service to churches. That is a more useful conversation than asking whether the organization has "done SOC 2."


CEFCore brings loan management, investor notes, general ledger, cash and ACH operations, reporting, and audit-ready controls into one financial platform for Church Extension Funds. If your team is ready to replace fragmented evidence trails with structured workflows and clearer oversight, visit CEFCore to review the platform and discuss your operational requirements.

CEF

CEF Core Editorial Team

Written and reviewed by CEF Core's treasury, fund-accounting, and compliance team — the people who build the financial management platform purpose-built for Church Extension Funds. Learn more about CEF Core.