Kristine Walker

Case studies / 02

Business analysis case study · 02

Audit-Ready Every Day

Turning SOC compliance for client-facing reports from an audit-week scramble into a daily habit

Role
Reporting Coordinator — workflow platform co-administrator and the team’s SOC subject-matter expert
Organization
Global relocation management company
Scope
The reporting team’s two SOC controls over client-facing report changes, within the company-wide SOC 1 and SOC 2 audits
Tools
SmartQ (Jira-style workflow platform), BMC Remedyforce, Excel
2SOC controls owned by the team
7checks on every SOC ticket
Dailyreview, same-day follow-up
54,000requests a year on the platform

1The problem

Our reporting team owned two SOC controls covering every client-facing report we built or changed. To pass, each change had to show a clear owner, testing in a separate environment, the right approvals, and a release to production by a second, senior developer — with dates proving it all happened in order.

The risk sat in the tickets themselves. A missing tag, a skipped approval or a date out of order was easy to miss in the moment and hard to fix months later, when an auditor pulled that ticket into the sample.

2The control framework

The two controls were tested through seven checks on every SOC-tagged ticket — standard change-management practices, described here in general terms.

Report change lifecycle from request to production release
#CheckWhat it proves
1OwnershipThe requester is the owner of the report.
2Scope tagEvery client-facing report is tagged SOC.
3Environment separationDevelopment and testing happen outside production.
4Requester reviewThe owner tests and reviews the report before release.
5Dual approvalBoth the requester and the developer approve.
6Segregation of dutiesA second, senior developer releases to production — only after the requester confirms.
7Milestone datesDates show every step happened, in the right order.

3The solution: a daily gap report

Each day, compliance filters I built in the workflow platform pulled the SOC tickets and their key fields. I reviewed every ticket against the seven checks and sent an Excel gap report to the analysts and developers the same day, with each gap flagged next to the owner who needed to fix it. Owners corrected their own tickets while the details were fresh.

Mock-up of the daily SOC gap report

Illustrative mock-up with invented ticket data.

Chart comparing audit-week cleanup to steady daily checks

Illustrative shape of the change, not measured data.

NeedAudit-week cleanupDaily compliance check
Finding gapsDuring audit preparationThe same day
Fixing gapsMonths later, from memoryWhile the details are fresh
Who fixesWhoever is availableThe ticket’s own analyst or developer
Auditor sampleRework on pulled ticketsRecords already complete

4Results

  • Every SOC ticket checked daily against seven checks, with gaps routed to the owner the same day.
  • Smooth audit testing cycles: records were complete when auditors pulled their sample.
  • Less pre-audit cleanup, because gaps were fixed as they happened.
  • Trusted beyond the team: represented the reporting team’s two controls in the company-wide audit, then went on loan to Internal Audit, coordinating SOC audit activities across the company’s 180 controls.

5What I’d recommend next

  • Let the system enforce the checks. Required fields and workflow rules that block release without approvals would turn a daily review into an exception report.
  • Bring recurring business reviews into scope. They hold some of the most sensitive client information and belong in the controlled process.
Compliance is a habit, not an event. And good controls start with asking what’s actually sensitive, not just what’s been labeled that way.

Described in general terms. Figures are from memory and the author’s resume; visuals are illustrative and contain no confidential company, client or system data.

Downloads

The full case study includes requirements, stakeholder analysis and trade-offs.