SOC 2 Type 2 Interview Prep
| Field | Value |
|---|---|
| Version | 0.14 |
| Created | 2026-08-12 |
| Updated | 2026-08-17 |
| Owner | CEO (Takayuki KIKUCHI) |
| Classification | Internal — audit preparation |
| Source agenda | Checklist_SOC 2 Type 2.docx |
| Authoritative locale | Japanese page is the working master for confirmation updates |
How to use
Draft answers and evidence pointers for the auditor interview. Distinguish policy, implementation, and evidence. Do not invent facts for items marked Confirm.
Status legend
| Tag | Meaning |
|---|---|
| Ready | Answerable from policy / implementation / management confirmation |
| Policy ready — confirm execution | Policy exists; fine-tune dates / artifacts if needed |
| Confirm | Still fact-open; do not invent |
Consistent framing
| Topic | Statement | Evidence |
|---|---|---|
| Legal entity | Rendering Consulting Inc. | Policies / whitepaper |
| System name (external) | AuditnQ | Security whitepaper §2 |
| Internal repo name | VMS (RenderingConsulting/VMS) |
Change management procedure |
| Delivery model | SaaS (TPRM / vendor audit) | Whitepaper §2 |
| Cloud | Microsoft Azure (Japan East / Japan West) | Whitepaper §5 |
| IdP | Auth0 (Okta); customer enterprise SSO via SAML 2.0 | Whitepaper §8 / VMS SSO-MFA design |
| Security & compliance owner | CEO (Takayuki KIKUCHI) | Roles and Responsibilities |
| Headcount | 1 (CEO / sole operator) | Management confirmation 2026-08-13 |
| Board | Same single individual; no multi-member board | Management confirmation |
| Observation Window | 2026-09-01 to 2026-11-30 | Management confirmation |
| TSC in report | Security only | Management confirmation |
| Compliance ops | Vanta (ongoing access reviews, etc.) | Management confirmation |
| Website | https://ren-con.jp/ | Whitepaper §17 |
Whitepaper alignment
Public whitepaper 1.3 now states that the SOC 2 Type II engagement is Security-only. Keep EL, System Description, and interview answers on the same scope. Availability, Confidentiality, and Privacy are out of scope (DC8). Mentions of high availability in BCP or contractual confidentiality/availability are not TSC-scope claims.
1. Audit Information
| Item | Draft answer | Evidence | Status |
|---|---|---|---|
| Company Website | https://ren-con.jp/ | Whitepaper §17 | Ready |
| Trust Service Criteria | Security only | Management confirmation; align EL/SD | Ready |
| Platform | AuditnQ SaaS on Microsoft Azure; Auth0 for identity | Whitepaper §2, §5, §8 | Ready |
| Observation Window | 2026-09-01 – 2026-11-30 | Management confirmation / EL | Ready |
| Externally imposed deadlines / Expectation | (customer / ISO / commercial deadlines, or none beyond audit timeline) | Management | Confirm |
| Fraud, security breach or uncorrected error in past 12 months | None. Also: formal customer product offering has not started yet | Management confirmation / IR / DC4 | Ready |
| System Description | SaaS for vendor audit & compliance | Whitepaper §2 | Ready |
| Service Type | SaaS / application service organization | Same | Ready |
| Remote or Physical Office | Physical locked suite; no on-prem production data; cloud-centric IT; single-person / remote-capable operations; DR = work from home | Physical Security / BCP-DR / headcount=1 | Ready |
| People | 1 (Takayuki KIKUCHI). Keep SD headcount consistent | Management confirmation | Ready |
| Board | Sole director / CEO; no multi-member board. Independent oversight primarily via ISO 27001 and this SOC 2 | Management confirmation / Roles | Ready |
| Board Meeting Minutes | No multi-person board cadence; material decisions recorded as sole-director decisions (show via Vanta / internal records as needed) | Management confirmation | Policy ready — confirm execution |
| Cloud Provider / Infrastructure | Microsoft Azure: SWA, Functions, PostgreSQL Flexible Server, ADLS Gen2, Application Insights | Whitepaper §5.1 | Ready |
| SSO / Identity Provider | Auth0; customer SAML SSO; password path closed after SSO; break-glass available | Whitepaper §8 / VMS SSO docs | Ready |
| Penetration Testing | In progress. Vendor Cacilian. At the interview, describe it as ongoing testing. Do not promise a completion date, report, or material findings. Vanta Penetration test report / remediation = Needs remediation | Management confirmation 2026-08-17 / Vanta | Ready (in progress) |
| BCP/DR Test | Completed 2026-06-22. Evidence: 2026-Tabletop disaster recovery exercise PDF. Vanta Tabletop disaster recovery exercise is OK. Adequate as a BCP tabletop |
Management confirmation / BCP-DR Plan / PDF / Vanta | Ready |
| Incident Response Test | Dedicated IR tabletop completed 2026-08-16 and re-uploaded to Vanta “Test of incident response plan.” Record: 2026-08-16 Incident Response Tabletop Exercise Documentation.pdf (author KIKUCHI Takayuki). Separate from the BCP DR tabletop PDF. IR plan is approved. No material incidents |
Management confirmation 2026-08-16 / PDF / Vanta / IRP | Ready |
| Risk Assessment | Policy: at least annually. Latest register update 2026-06-22 (Vanta Risk scenarios Last updated; material Inherent-8 scenarios Approved that day) | Risk Management / Vanta / management confirmation 2026-08-15 | Ready |
| Access Review | Policy: semiannual. Practice: ongoing via Vanta | Access Control / Vanta | Ready |
| Code Changes | GitHub PR review/approval and automated deploy; prod/non-prod separation; follow change-management procedure (explain single-person review path factually) | Secure Development / change-mgmt | Ready |
| Hire/Retire Checklist/Process | Policy in place; limited hire/exit activity at headcount=1 | HR / Access Control | Ready (policy) |
| Vendor Assessment | Diligence + written agreements; annual review of critical vendors; Azure, Auth0, Sentry; tracking may use Vanta | Third-Party Management / Whitepaper §14 | Ready (policy) |
| Vulnerability Scan | Completed / remediated as applicable (show Vanta / scan evidence). Policy: at least quarterly for internet-facing prod; Dependabot weekly; do not overstate CodeQL automation | Management confirmation / Ops / Dependabot | Ready |
| Policy | Layered ISMS policies; management approval; at least annual review | docs/policies/* |
Ready |
| Performance Evaluations | Annual per policy; at headcount=1 may be self-assessment / goals / Vanta task completion | HR Security | Policy ready — confirm execution |
| Whistle-blower Process | Public channel; no retaliation | AUP / CoC / Whistleblower | Ready |
| Device Compliance | Devices under AUP; approved remote access with MFA; confirm MDM details if asked | AUP | Policy ready — confirm execution |
| MFA | Required for privileged prod access; Auth0 TOTP for AuditnQ when enforced; SSO MFA via customer IdP; break-glass always MFA | Access/Ops / VMS MFA design | Ready |
| Communication channel preferred | Email with the audit team. Internal day-to-day is Slack (not Teams) | Management confirmation 2026-08-17 | Ready |
2. Interview Questions
| Question | Why the auditor asks | Draft answer | Evidence | Status |
| --- | --- | --- | --- |
| How are ethical expectations communicated? | Control environment (CC1): ethics are documented and actually communicated | At start via CoC, confidentiality, security policies; public whistleblower channel; annual awareness + policy review | CoC / HR / AUP | Ready |
| Describe a recent ethics violation | Tests whether the code of conduct operates, not just exists. “None” is acceptable if true | None — “No recent ethics violations to report.” | Management confirmation | Ready |
| Who provides independent oversight? | Who provides objective challenge (board / external audit) when the operator is also management | Single CEO owns security/compliance in-house; external independent assurance via ISO 27001 and this SOC 2 Type II | Headcount=1 / Roles / Whitepaper §15 | Ready |
| How often is security discussed? | Whether security is an ongoing management topic, not a once-a-year ritual | Not a multi-person standing committee; handled via annual risk/policy cadence, ad hoc on incidents/changes, and ongoing Vanta tasks | Vanta / headcount=1 | Ready |
| Who owns security/compliance? | Accountability (CC1.3); avoids ownerless programs | CEO (Takayuki KIKUCHI) | Roles | Ready |
| What happens on control failure? | Escalation for exceptions, violations, and incidents is defined and usable | Prior written CEO approval for exceptions; access revocation/discipline possible; IR lifecycle for incidents | Policies / IR Plan | Ready |
| How do you ensure employee competence? | People controls (CC1.4): only suitable personnel reach production | Hiring assessments, role clarity, onboarding acknowledgments, annual review; founder performs engineering + security | HR / headcount=1 | Ready |
| Is training role-based? | Higher-risk roles get more than generic awareness | Onboarding + at least annual awareness; additional training for sensitive-data roles per policy | HR Security | Ready |
| How are policies enforced? | Operation, not design: technical and organizational enforcement | Technical controls + organizational enforcement including Vanta-driven access reviews | Access / Secure Dev / Vanta | Ready |
| Show corrective actions taken | Core Type 2 question: defects are found and fixed. Preventive examples OK; do not invent | No incident-driven corrective actions. Formal customer offering has not started; no security incidents or detections. Preventive remediation is ongoing: Dependabot (and similar) PRs are reviewed regularly and merged per the dependency triage policy. Orally: “No post-incident corrective cases. Steady-state work is Dependabot / vuln-scan follow-up.” Evidence: Dependabot PRs and dependency-triage-policy.md | Management confirmation 2026-08-15 / Dependabot / triage policy | Ready |
| How do you enforce code of conduct violations? | Discipline and non-retaliation actually operate | Progressive discipline; no retaliation; possible immediate access suspension | CoC / AUP / HR | Ready |
| What are your top 3 risks this quarter? | Risk assessment is live; oral answers must match the register | From Vanta Inherent 8 (residual 4, Mitigate / Approved): (1) R-3 malware breach/corruption/unavailability; (2) R-5 unauthorized access via weak physical security or social engineering; (3) R-10 breach via compromised credentials. R-9 (natural disaster) is also Inherent 8; Security-only interview uses the three above | Vanta Risk register (updated 2026-06-22) | Ready (oral selection; swappable) |
| How are risks tracked to remediation? | Identification is not enough; treatment and residual risk are tracked (CC3) | Vanta Risk scenarios track inherent/residual, treatment, and approval. Owner is CEO. Latest register update 2026-06-22. Annual review per policy; vuln SLAs in Ops | Risk / Ops / Vanta | Ready |
| How do you approve critical vendors? | Third-party risk (CC9) before access to prod / customer data | Diligence before access; written agreements | Third-Party Management | Ready |
| How do you monitor vendors post onboarding? | Ongoing oversight after contract, not one-time onboarding | At least annual review; reassess on material change | Third-Party Management | Ready |
| Who approves security policies? | Policies have management authority, not shop-floor-only drafts | CEO | Roles | Ready |
| How often are policies updated? | Policies are not stale; annual plus ad hoc updates | At least annually; ad hoc on material change | Whitepaper §3.1 | Ready |
| When was your last incident and what changed? | DC4 and IR effectiveness; oral story must match the description | No significant incidents. Also pre–formal customer offering. Align DC4 | Management confirmation | Ready |
| What metrics do you review monthly? | Monitoring (CC4): can you notice failure? A monthly meeting is not mandatory | No monthly executive dashboard (headcount=1). Primary: (1) Vanta Tests pass/fail, items needing attention, due dates; (2) Dependabot / GitHub dependency vulnerability PRs, reviewed regularly. App Insights / Sentry only on errors or incidents. No monthly availability-SLA rollup or routine Auth0 failure-rate review. Orally: continuous Vanta + Dependabot, not a monthly metrics meeting | Management confirmation 2026-08-15 / Vanta / Dependabot | Ready |
| Who approves privileged access? | Logical access (CC6): privilege is approved, least-privilege, MFA | System/data owner (CEO today); documented approval; MFA for privileged prod; limited population at headcount=1 | Access Control | Ready |
3. System Description Questions
| # | Topic | Why the auditor asks | Draft answer | Evidence | Status |
|---|---|---|---|---|---|
| 1 | Delivery model | Fixes the service type; SaaS vs MSP changes the control boundary | SaaS | Whitepaper §2 | Ready |
| 2 | System name | Identifies the in-scope system; avoids internal vs external name mix-ups | AuditnQ | Whitepaper / change-mgmt | Ready |
| — | EL vs SD mismatch | Scope mismatches become report issues; period, TSC, and system must match | Keep oral answers on Japanese §3.1 locked values. EL reconciliation is post-audit; do not raise it in the interview | JA §3.1 | Ready (oral); EL reconcile after audit |
| 2b | Cloud provider consistency | Hosting CSP is consistent across SD, subprocessors, and interview | Microsoft Azure throughout | Whitepaper §5, §14.3 | Ready |
| 3 | Advertising in SD | SD is assurance text; marketing can be read as extra commitments | No marketing copy | SD review | Confirm |
| 4 | Privacy / DC1 role | If Privacy is in scope, state processor/controller; else DC8 N/A | Privacy out of scope; disclose N/A via DC8 | Security-only confirmation | Ready |
| 5 | DC2 commitments | Promises must map to the TSC being examined; over-promising widens tests | Map commitments to Security; avoid overstating Availability/Confidentiality as in-report TSC | SD / control matrix | Confirm (SD completeness) |
| 6–7 | DC3 components / headcount | Infrastructure, software, people, procedures, data are complete and consistent | Cover Azure / AuditnQ / people / procedures / data; people = 1 | Management confirmation | Ready (headcount) |
| 8 | DC4 significant incidents | Users need disclosure of material events in the window | None; may note pre–formal customer offering | Management confirmation | Ready |
| 9 | DC5 control mapping | Policies, control descriptions, and tests align one-to-one | One-to-one policy/control/test mapping (Vanta may support) | Control matrix / Vanta | Confirm |
| 10 | DC6 CUECs | Customer actions required for the company to meet commitments | Customer responsibilities per shared-responsibility model | Whitepaper §16 | Policy ready — confirm SD text |
| 11 | DC7 CSOCs | Carve out or complement controls performed by Azure / Auth0 / others | Azure / Auth0 carved-out or complementary controls | Whitepaper §14 | Confirm |
| 12 | DC8 N/A criteria | Out-of-scope TSC are disclosed with reasons so readers do not misread the report | Disclose Availability / Confidentiality / Privacy (and any others) as not in this engagement, with reasons | Security-only confirmation | Ready (policy); finalize SD wording |
| 13 | DC9 significant changes | Material in-window changes that affect user reliance are disclosed | Window not started as of this draft. Dedicated IR tabletop completed 2026-08-16 and registered in Vanta. In progress: pen test (Cacilian; describe as ongoing at the interview) | Change history | Ready (policy) |
| 14 | Use of AI | Whether AI processes or trains on customer data; draw the boundary | Not embedded in the product/service. Used in development practice. Clarify customer data is not used for model training | Management confirmation | Ready |
See the Japanese page for the full confirmation checklist, remaining tasks, and implementation talking points.
4. Remaining tasks (before interview)
No interview-blocking remaining tasks. Pen test stays in progress. EL reconciliation is post-audit. Distributed whitepaper regeneration is not needed.
5. Evidence index
| Area | Path / URL |
|---|---|
| Security whitepaper | docs/library/auditnq-security-whitepaper.*.md |
| Policies | docs/policies/ |
| Change management | docs/library/change-management-procedure.en.md |
| Whistleblower | https://ren-con.jp/compliance/whistleblower/ |
| SSO/MFA design | VMS/doc/sso-mfa-authentication-design.md |
| Dependency triage | VMS/doc/security/dependency-triage-policy.md |
| Compliance ops | Vanta |
| Dedicated IR tabletop (2026-08-16) | 2026-08-16 Incident Response Tabletop Exercise Documentation.pdf (Vanta “Test of incident response plan”) |
| BCP/DR tabletop (2026-06-22) | 2026-Tabletop disaster recovery exercise PDF (Vanta “Tabletop disaster recovery exercise”) |
6. Revision history
| Version | Date | Notes |
|---|---|---|
| 0.1 | 2026-08-12 | Initial draft from auditor checklist + policies + VMS implementation |
| 0.2 | 2026-08-13 | Applied management confirmations: window, Security-only, no incidents, headcount/board=1, pen test in progress, vuln scan done, BCP tabletop done, Vanta access reviews, AI stance |
| 0.3 | 2026-08-15 | Whitepaper 1.3 corrected TSC scope; interview-prep note updated from discrepancy to aligned |
| 0.4 | 2026-08-15 | Risk assessment date set to Vanta Last updated 2026-06-22; top risks R-3 / R-5 / R-10 |
| 0.5 | 2026-08-15 | Corrective actions: no incident-driven cases; preventive Dependabot review/fix |
| 0.6 | 2026-08-15 | IR test confirmed via Vanta “Test of incident response plan” (OK); distinct from BCP tabletop |
| 0.7 | 2026-08-15 | Noted that IR and BCP share the same DR tabletop PDF; dedicated IR resubmit planned |
| 0.8 | 2026-08-15 | Monthly metrics: Vanta + Dependabot primary; App Insights/Sentry on errors only |
| 0.9 | 2026-08-16 | Dedicated IR tabletop in progress; pen test vendor Cacilian, target end of Aug 2026 |
| 0.10 | 2026-08-16 | Added EL/SD alignment table and DC draft language (JA §3.1 is canonical) |
| 0.11 | 2026-08-16 | Added auditor-intent column between question and draft answer |
| 0.12 | 2026-08-16 | Dedicated IR tabletop completed 2026-08-16 and registered in Vanta |
| 0.13 | 2026-08-17 | Pen test stays in progress at interview; EL reconcile is post-audit; no WP regen |
| 0.14 | 2026-08-17 | Preferred auditor channel is email; internal day-to-day is Slack |