Skip to content

SOC 2 Type 2 Interview Prep

Field Value
Version 0.14
Created 2026-08-12
Updated 2026-08-17
Owner CEO (Takayuki KIKUCHI)
Classification Internal — audit preparation
Source agenda Checklist_SOC 2 Type 2.docx
Authoritative locale Japanese page is the working master for confirmation updates

How to use

Draft answers and evidence pointers for the auditor interview. Distinguish policy, implementation, and evidence. Do not invent facts for items marked Confirm.

Status legend

Tag Meaning
Ready Answerable from policy / implementation / management confirmation
Policy ready — confirm execution Policy exists; fine-tune dates / artifacts if needed
Confirm Still fact-open; do not invent

Consistent framing

Topic Statement Evidence
Legal entity Rendering Consulting Inc. Policies / whitepaper
System name (external) AuditnQ Security whitepaper §2
Internal repo name VMS (RenderingConsulting/VMS) Change management procedure
Delivery model SaaS (TPRM / vendor audit) Whitepaper §2
Cloud Microsoft Azure (Japan East / Japan West) Whitepaper §5
IdP Auth0 (Okta); customer enterprise SSO via SAML 2.0 Whitepaper §8 / VMS SSO-MFA design
Security & compliance owner CEO (Takayuki KIKUCHI) Roles and Responsibilities
Headcount 1 (CEO / sole operator) Management confirmation 2026-08-13
Board Same single individual; no multi-member board Management confirmation
Observation Window 2026-09-01 to 2026-11-30 Management confirmation
TSC in report Security only Management confirmation
Compliance ops Vanta (ongoing access reviews, etc.) Management confirmation
Website https://ren-con.jp/ Whitepaper §17

Whitepaper alignment

Public whitepaper 1.3 now states that the SOC 2 Type II engagement is Security-only. Keep EL, System Description, and interview answers on the same scope. Availability, Confidentiality, and Privacy are out of scope (DC8). Mentions of high availability in BCP or contractual confidentiality/availability are not TSC-scope claims.


1. Audit Information

Item Draft answer Evidence Status
Company Website https://ren-con.jp/ Whitepaper §17 Ready
Trust Service Criteria Security only Management confirmation; align EL/SD Ready
Platform AuditnQ SaaS on Microsoft Azure; Auth0 for identity Whitepaper §2, §5, §8 Ready
Observation Window 2026-09-01 – 2026-11-30 Management confirmation / EL Ready
Externally imposed deadlines / Expectation (customer / ISO / commercial deadlines, or none beyond audit timeline) Management Confirm
Fraud, security breach or uncorrected error in past 12 months None. Also: formal customer product offering has not started yet Management confirmation / IR / DC4 Ready
System Description SaaS for vendor audit & compliance Whitepaper §2 Ready
Service Type SaaS / application service organization Same Ready
Remote or Physical Office Physical locked suite; no on-prem production data; cloud-centric IT; single-person / remote-capable operations; DR = work from home Physical Security / BCP-DR / headcount=1 Ready
People 1 (Takayuki KIKUCHI). Keep SD headcount consistent Management confirmation Ready
Board Sole director / CEO; no multi-member board. Independent oversight primarily via ISO 27001 and this SOC 2 Management confirmation / Roles Ready
Board Meeting Minutes No multi-person board cadence; material decisions recorded as sole-director decisions (show via Vanta / internal records as needed) Management confirmation Policy ready — confirm execution
Cloud Provider / Infrastructure Microsoft Azure: SWA, Functions, PostgreSQL Flexible Server, ADLS Gen2, Application Insights Whitepaper §5.1 Ready
SSO / Identity Provider Auth0; customer SAML SSO; password path closed after SSO; break-glass available Whitepaper §8 / VMS SSO docs Ready
Penetration Testing In progress. Vendor Cacilian. At the interview, describe it as ongoing testing. Do not promise a completion date, report, or material findings. Vanta Penetration test report / remediation = Needs remediation Management confirmation 2026-08-17 / Vanta Ready (in progress)
BCP/DR Test Completed 2026-06-22. Evidence: 2026-Tabletop disaster recovery exercise PDF. Vanta Tabletop disaster recovery exercise is OK. Adequate as a BCP tabletop Management confirmation / BCP-DR Plan / PDF / Vanta Ready
Incident Response Test Dedicated IR tabletop completed 2026-08-16 and re-uploaded to Vanta “Test of incident response plan.” Record: 2026-08-16 Incident Response Tabletop Exercise Documentation.pdf (author KIKUCHI Takayuki). Separate from the BCP DR tabletop PDF. IR plan is approved. No material incidents Management confirmation 2026-08-16 / PDF / Vanta / IRP Ready
Risk Assessment Policy: at least annually. Latest register update 2026-06-22 (Vanta Risk scenarios Last updated; material Inherent-8 scenarios Approved that day) Risk Management / Vanta / management confirmation 2026-08-15 Ready
Access Review Policy: semiannual. Practice: ongoing via Vanta Access Control / Vanta Ready
Code Changes GitHub PR review/approval and automated deploy; prod/non-prod separation; follow change-management procedure (explain single-person review path factually) Secure Development / change-mgmt Ready
Hire/Retire Checklist/Process Policy in place; limited hire/exit activity at headcount=1 HR / Access Control Ready (policy)
Vendor Assessment Diligence + written agreements; annual review of critical vendors; Azure, Auth0, Sentry; tracking may use Vanta Third-Party Management / Whitepaper §14 Ready (policy)
Vulnerability Scan Completed / remediated as applicable (show Vanta / scan evidence). Policy: at least quarterly for internet-facing prod; Dependabot weekly; do not overstate CodeQL automation Management confirmation / Ops / Dependabot Ready
Policy Layered ISMS policies; management approval; at least annual review docs/policies/* Ready
Performance Evaluations Annual per policy; at headcount=1 may be self-assessment / goals / Vanta task completion HR Security Policy ready — confirm execution
Whistle-blower Process Public channel; no retaliation AUP / CoC / Whistleblower Ready
Device Compliance Devices under AUP; approved remote access with MFA; confirm MDM details if asked AUP Policy ready — confirm execution
MFA Required for privileged prod access; Auth0 TOTP for AuditnQ when enforced; SSO MFA via customer IdP; break-glass always MFA Access/Ops / VMS MFA design Ready
Communication channel preferred Email with the audit team. Internal day-to-day is Slack (not Teams) Management confirmation 2026-08-17 Ready

2. Interview Questions

| Question | Why the auditor asks | Draft answer | Evidence | Status | | --- | --- | --- | --- | | How are ethical expectations communicated? | Control environment (CC1): ethics are documented and actually communicated | At start via CoC, confidentiality, security policies; public whistleblower channel; annual awareness + policy review | CoC / HR / AUP | Ready | | Describe a recent ethics violation | Tests whether the code of conduct operates, not just exists. “None” is acceptable if true | None — “No recent ethics violations to report.” | Management confirmation | Ready | | Who provides independent oversight? | Who provides objective challenge (board / external audit) when the operator is also management | Single CEO owns security/compliance in-house; external independent assurance via ISO 27001 and this SOC 2 Type II | Headcount=1 / Roles / Whitepaper §15 | Ready | | How often is security discussed? | Whether security is an ongoing management topic, not a once-a-year ritual | Not a multi-person standing committee; handled via annual risk/policy cadence, ad hoc on incidents/changes, and ongoing Vanta tasks | Vanta / headcount=1 | Ready | | Who owns security/compliance? | Accountability (CC1.3); avoids ownerless programs | CEO (Takayuki KIKUCHI) | Roles | Ready | | What happens on control failure? | Escalation for exceptions, violations, and incidents is defined and usable | Prior written CEO approval for exceptions; access revocation/discipline possible; IR lifecycle for incidents | Policies / IR Plan | Ready | | How do you ensure employee competence? | People controls (CC1.4): only suitable personnel reach production | Hiring assessments, role clarity, onboarding acknowledgments, annual review; founder performs engineering + security | HR / headcount=1 | Ready | | Is training role-based? | Higher-risk roles get more than generic awareness | Onboarding + at least annual awareness; additional training for sensitive-data roles per policy | HR Security | Ready | | How are policies enforced? | Operation, not design: technical and organizational enforcement | Technical controls + organizational enforcement including Vanta-driven access reviews | Access / Secure Dev / Vanta | Ready | | Show corrective actions taken | Core Type 2 question: defects are found and fixed. Preventive examples OK; do not invent | No incident-driven corrective actions. Formal customer offering has not started; no security incidents or detections. Preventive remediation is ongoing: Dependabot (and similar) PRs are reviewed regularly and merged per the dependency triage policy. Orally: “No post-incident corrective cases. Steady-state work is Dependabot / vuln-scan follow-up.” Evidence: Dependabot PRs and dependency-triage-policy.md | Management confirmation 2026-08-15 / Dependabot / triage policy | Ready | | How do you enforce code of conduct violations? | Discipline and non-retaliation actually operate | Progressive discipline; no retaliation; possible immediate access suspension | CoC / AUP / HR | Ready | | What are your top 3 risks this quarter? | Risk assessment is live; oral answers must match the register | From Vanta Inherent 8 (residual 4, Mitigate / Approved): (1) R-3 malware breach/corruption/unavailability; (2) R-5 unauthorized access via weak physical security or social engineering; (3) R-10 breach via compromised credentials. R-9 (natural disaster) is also Inherent 8; Security-only interview uses the three above | Vanta Risk register (updated 2026-06-22) | Ready (oral selection; swappable) | | How are risks tracked to remediation? | Identification is not enough; treatment and residual risk are tracked (CC3) | Vanta Risk scenarios track inherent/residual, treatment, and approval. Owner is CEO. Latest register update 2026-06-22. Annual review per policy; vuln SLAs in Ops | Risk / Ops / Vanta | Ready | | How do you approve critical vendors? | Third-party risk (CC9) before access to prod / customer data | Diligence before access; written agreements | Third-Party Management | Ready | | How do you monitor vendors post onboarding? | Ongoing oversight after contract, not one-time onboarding | At least annual review; reassess on material change | Third-Party Management | Ready | | Who approves security policies? | Policies have management authority, not shop-floor-only drafts | CEO | Roles | Ready | | How often are policies updated? | Policies are not stale; annual plus ad hoc updates | At least annually; ad hoc on material change | Whitepaper §3.1 | Ready | | When was your last incident and what changed? | DC4 and IR effectiveness; oral story must match the description | No significant incidents. Also pre–formal customer offering. Align DC4 | Management confirmation | Ready | | What metrics do you review monthly? | Monitoring (CC4): can you notice failure? A monthly meeting is not mandatory | No monthly executive dashboard (headcount=1). Primary: (1) Vanta Tests pass/fail, items needing attention, due dates; (2) Dependabot / GitHub dependency vulnerability PRs, reviewed regularly. App Insights / Sentry only on errors or incidents. No monthly availability-SLA rollup or routine Auth0 failure-rate review. Orally: continuous Vanta + Dependabot, not a monthly metrics meeting | Management confirmation 2026-08-15 / Vanta / Dependabot | Ready | | Who approves privileged access? | Logical access (CC6): privilege is approved, least-privilege, MFA | System/data owner (CEO today); documented approval; MFA for privileged prod; limited population at headcount=1 | Access Control | Ready |


3. System Description Questions

# Topic Why the auditor asks Draft answer Evidence Status
1 Delivery model Fixes the service type; SaaS vs MSP changes the control boundary SaaS Whitepaper §2 Ready
2 System name Identifies the in-scope system; avoids internal vs external name mix-ups AuditnQ Whitepaper / change-mgmt Ready
— EL vs SD mismatch Scope mismatches become report issues; period, TSC, and system must match Keep oral answers on Japanese §3.1 locked values. EL reconciliation is post-audit; do not raise it in the interview JA §3.1 Ready (oral); EL reconcile after audit
2b Cloud provider consistency Hosting CSP is consistent across SD, subprocessors, and interview Microsoft Azure throughout Whitepaper §5, §14.3 Ready
3 Advertising in SD SD is assurance text; marketing can be read as extra commitments No marketing copy SD review Confirm
4 Privacy / DC1 role If Privacy is in scope, state processor/controller; else DC8 N/A Privacy out of scope; disclose N/A via DC8 Security-only confirmation Ready
5 DC2 commitments Promises must map to the TSC being examined; over-promising widens tests Map commitments to Security; avoid overstating Availability/Confidentiality as in-report TSC SD / control matrix Confirm (SD completeness)
6–7 DC3 components / headcount Infrastructure, software, people, procedures, data are complete and consistent Cover Azure / AuditnQ / people / procedures / data; people = 1 Management confirmation Ready (headcount)
8 DC4 significant incidents Users need disclosure of material events in the window None; may note pre–formal customer offering Management confirmation Ready
9 DC5 control mapping Policies, control descriptions, and tests align one-to-one One-to-one policy/control/test mapping (Vanta may support) Control matrix / Vanta Confirm
10 DC6 CUECs Customer actions required for the company to meet commitments Customer responsibilities per shared-responsibility model Whitepaper §16 Policy ready — confirm SD text
11 DC7 CSOCs Carve out or complement controls performed by Azure / Auth0 / others Azure / Auth0 carved-out or complementary controls Whitepaper §14 Confirm
12 DC8 N/A criteria Out-of-scope TSC are disclosed with reasons so readers do not misread the report Disclose Availability / Confidentiality / Privacy (and any others) as not in this engagement, with reasons Security-only confirmation Ready (policy); finalize SD wording
13 DC9 significant changes Material in-window changes that affect user reliance are disclosed Window not started as of this draft. Dedicated IR tabletop completed 2026-08-16 and registered in Vanta. In progress: pen test (Cacilian; describe as ongoing at the interview) Change history Ready (policy)
14 Use of AI Whether AI processes or trains on customer data; draw the boundary Not embedded in the product/service. Used in development practice. Clarify customer data is not used for model training Management confirmation Ready

See the Japanese page for the full confirmation checklist, remaining tasks, and implementation talking points.


4. Remaining tasks (before interview)

No interview-blocking remaining tasks. Pen test stays in progress. EL reconciliation is post-audit. Distributed whitepaper regeneration is not needed.


5. Evidence index

Area Path / URL
Security whitepaper docs/library/auditnq-security-whitepaper.*.md
Policies docs/policies/
Change management docs/library/change-management-procedure.en.md
Whistleblower https://ren-con.jp/compliance/whistleblower/
SSO/MFA design VMS/doc/sso-mfa-authentication-design.md
Dependency triage VMS/doc/security/dependency-triage-policy.md
Compliance ops Vanta
Dedicated IR tabletop (2026-08-16) 2026-08-16 Incident Response Tabletop Exercise Documentation.pdf (Vanta “Test of incident response plan”)
BCP/DR tabletop (2026-06-22) 2026-Tabletop disaster recovery exercise PDF (Vanta “Tabletop disaster recovery exercise”)

6. Revision history

Version Date Notes
0.1 2026-08-12 Initial draft from auditor checklist + policies + VMS implementation
0.2 2026-08-13 Applied management confirmations: window, Security-only, no incidents, headcount/board=1, pen test in progress, vuln scan done, BCP tabletop done, Vanta access reviews, AI stance
0.3 2026-08-15 Whitepaper 1.3 corrected TSC scope; interview-prep note updated from discrepancy to aligned
0.4 2026-08-15 Risk assessment date set to Vanta Last updated 2026-06-22; top risks R-3 / R-5 / R-10
0.5 2026-08-15 Corrective actions: no incident-driven cases; preventive Dependabot review/fix
0.6 2026-08-15 IR test confirmed via Vanta “Test of incident response plan” (OK); distinct from BCP tabletop
0.7 2026-08-15 Noted that IR and BCP share the same DR tabletop PDF; dedicated IR resubmit planned
0.8 2026-08-15 Monthly metrics: Vanta + Dependabot primary; App Insights/Sentry on errors only
0.9 2026-08-16 Dedicated IR tabletop in progress; pen test vendor Cacilian, target end of Aug 2026
0.10 2026-08-16 Added EL/SD alignment table and DC draft language (JA §3.1 is canonical)
0.11 2026-08-16 Added auditor-intent column between question and draft answer
0.12 2026-08-16 Dedicated IR tabletop completed 2026-08-16 and registered in Vanta
0.13 2026-08-17 Pen test stays in progress at interview; EL reconcile is post-audit; no WP regen
0.14 2026-08-17 Preferred auditor channel is email; internal day-to-day is Slack