CC9.2 is where OAuth lives. CC6.7 is a different population.
Auditors have started asking for third-party OAuth evidence under SOC 2 CC9.2. Teams still hand them a user-access review and hope. CC6.7 is who can log in. CC9.2 is which vendors you authorized to act on your behalf, and whether you watch them. A spreadsheet of SaaS logos without client IDs and scopes fails both the security conversation and the privacy one.
This guide maps ScopeMantle controls to CC9.2, ISO 27001 A.5.19, and GDPR Article 32, plus the artifacts each control produces. It is educational. It is not legal advice and it is not an audit opinion. Your firm will phrase the tests differently. Write a cover memo that maps exports to their checklist wording. Do not claim we certify you.
SOC 2 CC9.2
CC9.2 wants identification, monitoring, and management of vendor relationships that could affect security commitments. A refresh token is a delegate credential. The vendor is a logical insider without an employee password. That is a vendor relationship whether or not finance has a PO.
| Control intent | What you produce | How you get it |
|---|---|---|
| Identify vendors | Daily (or dated) grant inventory: client ID, owner, scopes, created | Google Workspace and Okta export or ScopeMantle sync |
| Assess risk | Score report: Security, Privacy, Scope Sanity, Breach History | Risk scoring or the manual rubric in the scoring framework |
| Approve / accept | Attestation log with sponsor and expiry | Governance; ninety-day default |
| Terminate / respond | Revoke timestamps tied to HRIS tickets or breach-feed alerts | Governance revoke; see deprovisioning |
| Monitor / report | Quarterly board slide and optional event stream | Board template; SIEM export if you use it |
Do not accept a CC6.7 matrix as a substitute. Different people, different credentials, different revoke path. Say that in kickoff so you are not arguing it in week three.
Auditor conversation, almost word for word
When they ask for user access review: "Here it is for CC6.7. OAuth grants are CC9.2. Here is the grant export for the observation window, hashed, plus attestation and one termination revoke." When they conflate IdP login with OAuth: "The refresh token survives the login session. Disable is not revoke." When they ask if CASB covers it: send them the data path in the shadow OAuth guide.
ISO 27001 A.5.19
A.5.19 wants supplier security requirements and monitoring in proportion to risk. OAuth scopes are the proportional-risk signal. Mail read on an AI extension is not the same as calendar read on a scheduling tool you attested.
Map attestation workflow to supplier approval records. Map bulk revoke to supplier termination. Map breach-history elevation to supplier incident handling. Cadence that holds up: weekly digest for new installs, quarterly attestation for Tier 1, annual RoPA reconciliation against the OAuth export. Certification bodies will use their own phrases. Your cover memo does the translation. ScopeMantle does not claim ISO certification for you or for us unless we have published that fact (we have not, on this site, as a customer-facing certificate).
GDPR Article 32 (and why DSAR shows up)
Article 32 is appropriate technical measures: confidentiality, integrity, availability, resilience, and a process for regularly testing. Unmonitored OAuth grants punch confidentiality. A vendor can read personal data with no current DPA and no current business reason.
DSAR work is adjacent, not the same clause. If you cannot name processors, you cannot claim you understand processing risk. The DSAR playbook templates are operator-reviewed, not lawyer-reviewed. Inventory can surface a US SaaS reading EU employee mail. That triggers legal review. The product does not run a transfer assessment for you.
Evidence pack for audit week
- Grant inventory CSV with scores, observation-window dates on the filename.
- Attestation and revoke logs for the period.
- Screenshot or export of governance rules (example: auto-revoke below 40 Scope Sanity, if enabled).
- Last quarter's board slide PDF.
- One narrated revoke: HRIS termination cascade or breach-feed match.
- Hash of the inventory file in the GRC repo so the sample is reproducible.
Bring the pack in week one. Waiting until week three is how draft findings happen. Walk the auditor through CC9.2 before the observation period ends if you can. Proactive is cheaper than a finding plus a retest.
Common audit failures
- Annual spreadsheet, no scope strings.
- Vendor name only. No client ID. Rebrands break the story.
- No revoke evidence for terminated employees.
- No tabletop for "vendor disclosed today."
- Claiming CASB covers OAuth without an IdP grant export.
- Questionnaire-only GRC controls with no live export when the auditor picks twenty grants.
- Permanent exceptions.
- Mixing CC6.7 and CC9.2 in one matrix so neither test is clean.
Observation window traps
Auditors reject exports that predate the period start unless you explain the baseline in change management. If you turned on inventory in month two of a six-month window, say so. Do not back-date a CSV. If you changed the Scope Sanity threshold mid-period, the cover memo says when and who approved it. Silent threshold edits look like you tuned the control to pass the sample.
CISO sign-off letters should reference a completeness assertion that matches the file hash and the letter date. Legal drafts the letter. CISO checks the hash. Swapping those roles is how you get a confident letter on a stale export.
CC6.7 still happens. Privileged users, joiner-mover-leaver, quarterly access recert. Keep that packet in its folder. When someone tries to add OAuth rows to the user-access matrix, stop them. You will fail both tests: the matrix will be unreadable and the grant evidence will lack scopes.
HIPAA and other honesty
ScopeMantle is not HIPAA attested. No BAA. Do not map OAuth inventory to the Security Rule until counsel says the rule applies and the BAAs exist. Microsoft Entra is Beta / roadmap. Partial inventory presented as complete is an integrity problem, not a product flex.
We do not invent customer counts. Pricing is $5 per employee per month annual or $6 monthly, no seat minimum, custom at 500+, 30-day trial.
How to write the cover memo (half page)
Auditors and ISO bodies will not adopt our table headings. Your job is a cover memo that says, in their nouns, where each file lives. Something like:
- "CC9.2 identification:
oauth-inventory-2026-Q1.csv, hash …, source Google Admin SDK plus Okta API on 2026-04-02." - "CC9.2 risk assessment: score export; rubric published internally; threshold 40 documented in change ticket 1842."
- "CC9.2 monitoring: weekly digest distribution list; quarterly board slide in management review 2026-04-08."
- "A.5.19 supplier review cadence: Tier 1 attested every 90 days; new installs reviewed within 7 days."
- "Article 32: grant revoke on termination (ticket sample) and on vendor disclosure (tabletop 2026-03-12)."
Attach hashes, not a promise to export later. If Microsoft grants are missing, the memo says Entra is Beta and out of scope for completeness, not "all IdPs covered."
Sampling: twenty grants, not twenty logos
When the auditor picks a sample, they should pick rows from your export, stratified by score if you have one. Provide the selection seed (random seed or every Nth row after sort). For each sampled grant, have: client ID, scopes, owner, attestation or revoke, and whether a DPA exists. If you only have logos, the sample dies.
Terminated-user sampling is a separate test. Ten users from HRIS, zero grants remaining. That packet is the deprovisioning story. Do not mix it into the twenty-vendor sample or you will confuse the workpaper.
What Vanta (or any GRC) should and should not hold
GRC tools are good at reminders and auditor rooms. They are bad at being the system of record for OAuth. Attach the ScopeMantle or IdP CSV to the CC9.2 request. Do not re-type grant counts into a questionnaire and call it automation. The complementary story is in Vanta vs ScopeMantle.
Event stream exports (install, revoke, attestation) can land in Splunk or Datadog (GA) if the auditor wants "continuous monitoring" language. Elastic is Beta. Chronicle is Roadmap. Say the label.
Article 32 tests you can actually run
- Confidentiality: unattested mail-scope grants older than 90 days, count and trend.
- Integrity of the control: hash of inventory reproduced a week later, diff explained.
- Resilience: tabletop hours-to-revoke.
- Testing: quarterly drill recorded in the same folder as the board slide.
That is a testing program. It is not a claim that Article 32 is "done." Counsel still owns legal adequacy. We still do not review your DPIAs.
What to do this week
- Write a half-page "CC9.2 vs CC6.7" note and send it to your auditor or GRC lead before fieldwork.
- Produce one hashed grant export for the current quarter, even if ugly.
- Attach it to the GRC evidence request with a predictable name.
- Read the SOC 2 checklist and Vanta comparison.
- If you want the export to stay current, trial the platform.
Observation window traps
Auditors reject exports that predate the period start unless you explain the baseline in change management. If you turned on inventory in month two of a six-month window, say so. Do not back-date a CSV. If you changed the Scope Sanity threshold mid-period, the cover memo says when and who approved it. Silent threshold edits look like you tuned the control to pass the sample.
CISO sign-off letters should reference a completeness assertion that matches the file hash and the letter date. Legal drafts the letter. CISO checks the hash. Swapping those roles is how you get a confident letter on a stale export.
CC6.7 still happens. Privileged users, joiner-mover-leaver, quarterly access recert. Keep that packet in its folder. When someone tries to add OAuth rows to the user-access matrix, stop them. You will fail both tests: the matrix will be unreadable and the grant evidence will lack scopes.
ISO wording vs SOC wording
ISO auditors may never say "CC9.2." They will say supplier relationships, monitoring, and residual risk. Your memo maps A.5.19 to the same files. Do not maintain two inventories. Maintain one export and two cover letters. GDPR programs can add a third letter that points at Article 32 testing and at DSAR clocks without claiming the templates are legal advice.
If your firm uses Vanta, attach the CSV the same week as the evidence request. Questionnaire-only controls fail when the auditor asks for grant detail. Verify which Vanta controls are automated versus attested by a human. That distinction belongs in the walkthrough, not in a footnote you hope they skip. Drata and Secureframe have the same attachment shape. We are not running a GRC bake-off. The file is the point. If they want a walkthrough recording, store it next to the hash. Do not keep the production grant list on a personal laptop and call that evidence handling.
Field guide: cover memo in thirty minutes
Five bullets: identification file plus hash, assessment rubric plus threshold ticket, monitoring digest list, termination sample, known gaps. Two IdP names. One sentence that CC6.7 is a different folder. Send it before fieldwork. $5 / $6, no seat min, HIPAA not attested. Checklist.