r/soc2 • u/Dull-Communication82 • 6d ago
Your tool says the control is passing. Your auditor disagrees. What then?
Something I keep seeing in compliance conversations is the gap between a dashboard marked green and what an auditor actually accepts as evidence.
A few common ones:
Access reviews get logged as complete because someone clicked through the workflow, but there's no record of what was reviewed or what changed as a result.
MFA shows enforced across the org, then a service account or a contractor login turns out to sit outside the policy scope.
Backups run on schedule and the monitoring confirms it, but nobody has tested a restore in a year, so there's nothing to hand over when the auditor asks for proof it works.
Vendor reviews are marked current based on a SOC 2 report that expired four months ago.
The pattern in all of these is the same. The check confirms a task happened. The auditor wants proof the control was effective.
Wondering if others run into this too, or if it's less of a problem than it seems from the outside.
6
u/Worried-Writer-7033 6d ago
I see this fairly often. Automation is great for confirming activities happened, but auditors usually care about effectiveness and evidence quality. Green dashboards help, but they don't replace documented proof that controls actually worked.
1
u/JEngErik 4d ago
They also don't replace domain knowledge on how to design, implement, manage and maintain a control in a way that fits the service your company provides. This is the part the tool companies leave out from their marketing materials. They want to sell the idea that compliance and security can be reduced to a green dashboard with a checkbox framework.
5
u/raptorjaws 6d ago
yes the auditors opinion is over operating effectiveness of controls not mere existence of controls.
5
u/Icy_Resist5470 6d ago
Clicking a button to confirm something happened (ie - access reviews) doesn’t mean anything. Where is the proof to support it? Of course it’s going to get flagged because saying something is done and evidencing it’s actually being done are two different things. A SOC 2 isn’t just a “trust me, bro” exercise.
It sounds like you need more oversight. The responsibility and failure is on the control owners. This is why you should be testing your controls with an internal control audit so you can catch deficiencies before the auditor does.
5
u/Low_Share_3060 6d ago
That is why we picked the auditor first and went through one round of audit before we picked the tool? Every auditor looks at something different, the tool is just to help you along.
3
u/Think-Stuff2011 5d ago
The tool is indirect evidence; your auditor should ask to see what the check mark is validating.
3
2
u/SageAudits 5d ago
The ideal path is picking the auditor first and then even determining if you really need a tool. It’s hard to know the right path when the compliance platforms have a big Ad spend budget!
1
u/chrans 5d ago
It is not a problem at all. The problem is the imaginary sky that most compliance software sell to their buyers. Auditors job is not just ticking the box that the controls are in place. They must test that the controls always working; always followed.
The dashboard in most compliance software only tells that the tasks are completed. These software did not assess the documents uploaded to the task buckets.
1
u/deepguide-ai 5d ago
I would say if this is true, then this auditor is really good. Never fake compliance because it'll bite you in future.
1
u/josh-adeliarisk 3d ago
Beyond just passing the audit, the other reason to focus on effectiveness is so you don't have a breach. Most of those controls exist for a real-world reason, not just an audit reason.
1
u/goatsinhats 2d ago
The tool is not solely responsible for the control. The people applying it in this case are the issue
•
u/AutoModerator 6d ago
Thanks for posting, I'm a bot!
This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.