CC4 Security Required

Monitoring Activities

Complete guide to CC4 Monitoring Activities controls. Plain-English explanations, AICPA text, risk levels, and evidence tips for each control.

2 Controls
0 Critical
2 High
CC4.1 high

Monitoring Control Performance

You have a process to continuously or periodically verify that your security controls are working. This could be internal audits, quarterly reviews, or automated monitoring.

View official AICPA language

The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.

What auditors look for

Internal audit reports, quarterly security review meeting notes, automated control monitoring dashboards with screenshots

CC4.2 high

Evaluating and Communicating Deficiencies

When you find a control deficiency — through an audit, incident, or monitoring — you have a formal process to escalate it, assign ownership, and track remediation.

View official AICPA language

The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action.

What auditors look for

Deficiency tracking records, incident tickets showing escalation and remediation, communication of findings to leadership

Track all 2 controls in your free checklist

Assign owners, collect evidence, and get your readiness score — no credit card required.

Start Free Today