Reference case: continuous SOC 2 Type II evidence collection throughout the year
CISO, Engineering team, and Compliance — B2B SaaS company with annual SOC 2 audit and enterprise clients requiring the report.
Antes
- Audit window opened without accumulated evidence — 3-week sprint to collect retroactively
- Change management approved on Slack — no formal CAB log for auditors
- Access review in AD-exported spreadsheet — no evidence of who decided what
Depois
- Flow per control executes automatically at the right frequency — evidence accumulated throughout the year
- Each deploy with impact assessment evidence, CAB approval, and post-change verification
- Quarterly access review with (keep/revoke) decision recorded by manager — exportable by TSC