Selecting the right partner to assist with SOC 2 compliance (or anything else) can be challenging. If you are trying to sort through the marketplace to select a vendor here are a few considerations. You can also download our free vendor selection template here.
1| Experience Assess resumes of the individuals who will be performing the audit (including those performing audit fieldwork). Insight: Ask the vendor for the resumes of all individuals who will be performing audit fieldwork (not just the management team) and the amount of time you can expect with the management team. Obtaining this type of commitment up front can help avoid "resource bait and switch" later. 2| Qualification Does the audit team have the relevant background and certifications to perform the work for your firm? Are their current or previous clients raving fans? Insight: Firms that have experience with similar clients in your industry may be able to perform higher quality work. 3| Project Fit How will the firm accomplish our mission? Do they align with us culturally? Do they get it? Insight: Sometimes "project fit" is more up to judgement that anything quantifiable. Start by reviewing their proposal, prior deliverable, and intangibles like responsiveness, flexibility, and a desire to win your business. 4| Audit Software or Tools How will the firm actually perform the audit fieldwork? How will they request audit documentation, communicate with the team, and will it be a burden to our Company? Insight: Audit fieldwork is often performed via email communciation and spreadsheets. Overall, this is ineffective and inefficient. Costs go well beyond audit fees and creep into operational disruption. At risk3sixty, for example, we use Phalanx GRC to cut audit time in half and make the audit process easy for all stakeholders. 5| Price Are prices competitive with the market? Are you getting a good value? Insight: Consider overall value in addition to cost. Also, consider the total cost of the audit process over 2 or 3 years, not just year one. SOC 2 audits are annual so sometimes the picture is more clear if you look at cost over a couple of years, rather than just year one. Hint - when using the same audit firm, there is much efficiency to be gained over time: if you are not realizing pricing efficiencies over time, it may be time to start asking questions. Let's Get Started If you are considering SOC 2 compliance please contact one of our professionals and find out how we stack up.
1| Experience Assess resumes of the individuals who will be performing the audit (including those performing audit fieldwork). Insight: Ask the vendor for the resumes of all individuals who will be performing audit fieldwork (not just the management team) and the amount of time you can expect with the management team. Obtaining this type of commitment up front can help avoid "resource bait and switch" later. 2| Qualification Does the audit team have the relevant background and certifications to perform the work for your firm? Are their current or previous clients raving fans? Insight: Firms that have experience with similar clients in your industry may be able to perform higher quality work. 3| Project Fit How will the firm accomplish our mission? Do they align with us culturally? Do they get it? Insight: Sometimes "project fit" is more up to judgement that anything quantifiable. Start by reviewing their proposal, prior deliverable, and intangibles like responsiveness, flexibility, and a desire to win your business. 4| Audit Software or Tools How will the firm actually perform the audit fieldwork? How will they request audit documentation, communicate with the team, and will it be a burden to our Company? Insight: Audit fieldwork is often performed via email communciation and spreadsheets. Overall, this is ineffective and inefficient. Costs go well beyond audit fees and creep into operational disruption. At risk3sixty, for example, we use Phalanx GRC to cut audit time in half and make the audit process easy for all stakeholders. 5| Price Are prices competitive with the market? Are you getting a good value? Insight: Consider overall value in addition to cost. Also, consider the total cost of the audit process over 2 or 3 years, not just year one. SOC 2 audits are annual so sometimes the picture is more clear if you look at cost over a couple of years, rather than just year one. Hint - when using the same audit firm, there is much efficiency to be gained over time: if you are not realizing pricing efficiencies over time, it may be time to start asking questions. Let's Get Started If you are considering SOC 2 compliance please contact one of our professionals and find out how we stack up.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)