CRM & Tools

Insurers: Verify These 6 SOC 2 Evidence Items for CRM

KB
Kyle Buxton ·
Insurers: Verify These 6 SOC 2 Evidence Items for CRM

A CRM vendor’s SOC 2 report is necessary evidence, but it is not proof that your clients’ data is protected. Before trusting any vendor, request the current Type II report, confirm its scope and auditor, and add breach-notification language to the contract. The sections below explain what to check, how to validate it, and what to keep on file for an exam.


TL;DR:

  • A SOC 2 report must be current, specify scope, and include a remediation summary to be effective for vendor validation.
  • A Type II report provides stronger assurance than Type I because it covers control effectiveness over several months.
  • Agencies should verify encryption details, MFA enforcement, access controls, and third-party subprocessors for comprehensive review.
  • When vendors lack a current SOC 2, agencies should conduct additional due diligence and document risk acceptance and controls.
  • Ongoing oversight requires regular updates, documented reviews, and vendor contract checks to maintain effective cybersecurity protections.

Callbackcrm
Modernize Your Insurance CRM
CallBack CRM combines secure data handling with AI powered automation for insurance teams managing customer engagement, leads, and sales processes.
Explore CallBack CRM

Table of Contents

What a SOC 2 report actually covers for a CRM

A SOC 2 report evaluates a vendor against five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. For a CRM holding client records, Security and Confidentiality matter most, since they govern who can access data and how it is protected from exposure. Availability, Processing Integrity, and Privacy add context but do not replace the first two.

A vendor’s audit scope may not include every criterion. A SOC 2 report that excludes Confidentiality or Privacy offers limited assurance for a CRM storing personal client data, so the scope line matters as much as the report itself.

When reviewing a report, look for specific control evidence rather than a pass or fail summary:

  • Admin access restricted through role-based permissions and multi-factor authentication
  • Encryption applied both in transit and at rest for stored client records
  • Backup and restore testing documented against a stated recovery time
  • Logging and retention policies covering who accessed what data and when
  • Change management procedures for any third-party integrations connected to the CRM

There are two report types. A Type I report confirms controls were designed correctly on a single date. A Type II report confirms those controls operated effectively over a period, typically a period of several months. Type II with a recent testing window is the stronger form of evidence, since it shows the controls held up over time rather than on one snapshot day. Our guide to cloud security in CRM platforms covers how hosting choices affect which of these controls a vendor can even demonstrate.

Vendor evidence checklist for SOC 2 review

Requesting a SOC 2 report is only the first step. Validating it requires a structured review before signing or renewing.

  1. Request the current report and record the report date, the auditor’s name, and whether it is Type I or Type II.
  2. Confirm the explicit scope, meaning which Trust Services Criteria were tested, not just that “a SOC 2 exists.”
  3. Ask for a remediation summary covering any exceptions noted in the report and how they were closed.
  4. Request details on the vendor’s continuous monitoring or patch cadence between audit periods.
  5. Confirm contract language on breach-notification timing, support for state insurance department reporting, data return or deletion at contract end, and audit rights.
  6. Request technical artifacts: encryption specifics, MFA enforcement for admin roles, role-based access control documentation, logging and retention policies, and a list of third-party subprocessors.

Pro Tip: Ask for the subprocessor list in writing, since a CRM vendor’s own SOC 2 scope often excludes tools it integrates with, such as dialers or email providers.

A SOC 2 report is a point-in-time or period-based assurance. It says nothing about what the vendor fixed after the audit window closed, which is why the remediation summary matters as much as the report grade. Our CRM data privacy guide for agencies walks through how to log this evidence during a vendor review.

SOC 2 audit period and remediation timeline

Mapping SOC 2 evidence to NAIC and IDSM expectations

Insurance licensees operate under their own regulatory expectations, separate from what a SOC 2 report covers. The NAIC Insurance Data Security Model Law (MDL-668) requires licensees to maintain a written information security program, oversee third-party service providers, investigate cybersecurity events, and meet breach-notification timelines. Regulators treat third-party oversight as an ongoing responsibility, not a one-time checkbox completed at signup.

A SOC 2 report can satisfy part of this. It documents the vendor’s own controls and gives an agency something concrete to point to during a review. It does not replace the agency’s own written information security program, its vendor oversight process, or its incident-response timeline commitments to policyholders and regulators.

Market conduct exam checklists used by state examiners list specific pre-breach and post-breach items licensees must produce, including vendor contract standards and incident response plans. For an exam, keep on file:

  • The vendor’s SOC 2 report itself
  • Contract clauses covering breach notification and audit rights
  • Correspondence documenting any remediation the vendor completed
  • Notes from the agency’s annual vendor review

When a CRM vendor has no current SOC 2 report

Some CRM vendors, particularly smaller ones, will not have a current SOC 2 report available. This does not automatically disqualify them, but it does shift the burden onto the agency to document why it proceeded. SEC filings describing vendor management practices note that companies routinely perform additional reviews when a vendor cannot produce a SOC report, rather than skipping the review entirely.

  1. Send a vendor due-diligence questionnaire and request alternative attestations, such as ISO 27001 certification, penetration-test summaries, or written security policies.
  2. Require a remediation plan with dated milestones if gaps surface, along with stronger contractual breach-notification terms and audit rights as interim protection.
  3. Document the risk-acceptance decision internally: why the agency proceeded, what compensating controls were required, and who approved it.

This process will not produce the same assurance as a completed Type II report. However, it creates a defensible record if a regulator asks why the vendor was approved.

Documenting your vendor decision for ongoing reviews

A vendor review is only useful if the agency can produce it later. Keep a single file per CRM vendor containing:

  • The SOC 2 report itself, along with the auditor’s name and the scope tested
  • Contract text covering breach notification, audit rights, and data return terms
  • A remediation log noting any exceptions and how they were resolved
  • Dates of each annual review and who conducted it

Record the decision rationale alongside the file: why the agency approved the vendor, what residual risk was accepted, and who signed off internally. Assign one person ownership of the annual SOC 2 refresh so the file does not go stale between exams.

Pro Tip: Set a calendar reminder tied to the vendor’s last report date rather than the calendar year, since SOC 2 testing periods rarely align with January.

Why ongoing vendor oversight is the agency’s responsibility

Agencies that treat a SOC 2 report as a one-time approval step miss the point of the document. It is evidence of a control environment during a past testing window, not a guarantee about today. The agencies that hold up best under exam are the ones that keep asking vendors for updated reports, remediation notes, and contract confirmations year after year. The vendor publishes security and compliance resources for agents and agencies, providing reviewers with concrete reference material rather than relying solely on the vendor’s statements.

— Kyle

How CallBack CRM approaches secure data handling

The CRM vendor hosts data on Google Cloud and provides 24/7 support for agencies needing assistance during vendor reviews or exams. The platform is built to support insurance sales workflows, consolidating documentation and integrations used for follow-up, outreach, and pipeline management within a single system.

Callbackcrm

  • Centralized data handling reduces the number of vendor files an agency needs to track during a compliance review.
  • Published compliance resources give agencies a starting point when documenting vendor evidence for exams.
  • Support is available around the clock for questions that come up during a review or renewal.

Agencies evaluating a CRM switch can review plans on the Professional signup page, or compare account tiers on the Enterprise plans page for larger teams and IMOs.

Sources

For deeper reading or exam preparation, keep these on hand: the NAIC Insurance Data Security Model Law, the Market Regulation Handbook exam checklists, an explanation of SOC 2 Trust Services Criteria, and an SEC filing describing vendor SOC report review practices. Agencies building a broader operational checklist may also find this marketing automation checklist useful for documenting vendor onboarding steps.

FAQ

Is a SOC 2 Type II report always required for a CRM vendor?

No single report is universally required, but a current Type II report is the strongest form of evidence a CRM vendor can provide. If a vendor lacks one, agencies should request alternative attestations and document the compensating steps taken, as described in SEC vendor management practices.

What is the difference between SOC 2 Type I and Type II?

A Type I report confirms controls were designed properly as of one date. A Type II report confirms those same controls operated effectively over a testing period, usually a period of several months, which makes it the more reliable of the two for ongoing data protection.

Which SOC 2 criteria matter most for CRM data security?

Security and Confidentiality matter most for a CRM holding client records, since they govern access control and data exposure. Availability, Processing Integrity, and Privacy round out the five Trust Services Criteria but carry less weight for typical CRM use cases.

How often should an agency request a new SOC 2 report from its CRM vendor?

Agencies should request an updated report regularly, timed to the vendor’s testing period, tied to the vendor’s own testing period rather than the calendar year. This keeps the vendor file current for exam readiness and catches any new exceptions before they become a bigger issue.

Does CallBack CRM publish a SOC 2 report?

CallBack CRM hosts data on Google Cloud and provides published security and compliance resources for agencies to reference. Agencies should request the specific documentation they need directly from CallBack CRM as part of their own vendor review process.

Ready to Put This Into Practice?

Start your free trial and see how CallBack's AI automation transforms your insurance business.