1The problem
Our reporting team owned two SOC controls covering every client-facing report we built or changed. To pass, each change had to show a clear owner, testing in a separate environment, the right approvals, and a release to production by a second, senior developer — with dates proving it all happened in order.
The risk sat in the tickets themselves. A missing tag, a skipped approval or a date out of order was easy to miss in the moment and hard to fix months later, when an auditor pulled that ticket into the sample.
2The control framework
The two controls were tested through seven checks on every SOC-tagged ticket — standard change-management practices, described here in general terms.

| # | Check | What it proves |
|---|---|---|
| 1 | Ownership | The requester is the owner of the report. |
| 2 | Scope tag | Every client-facing report is tagged SOC. |
| 3 | Environment separation | Development and testing happen outside production. |
| 4 | Requester review | The owner tests and reviews the report before release. |
| 5 | Dual approval | Both the requester and the developer approve. |
| 6 | Segregation of duties | A second, senior developer releases to production — only after the requester confirms. |
| 7 | Milestone dates | Dates show every step happened, in the right order. |
3The solution: a daily gap report
Each day, compliance filters I built in the workflow platform pulled the SOC tickets and their key fields. I reviewed every ticket against the seven checks and sent an Excel gap report to the analysts and developers the same day, with each gap flagged next to the owner who needed to fix it. Owners corrected their own tickets while the details were fresh.

Illustrative mock-up with invented ticket data.

Illustrative shape of the change, not measured data.
| Need | Audit-week cleanup | Daily compliance check |
|---|---|---|
| Finding gaps | During audit preparation | The same day |
| Fixing gaps | Months later, from memory | While the details are fresh |
| Who fixes | Whoever is available | The ticket’s own analyst or developer |
| Auditor sample | Rework on pulled tickets | Records already complete |
4Results
- Every SOC ticket checked daily against seven checks, with gaps routed to the owner the same day.
- Smooth audit testing cycles: records were complete when auditors pulled their sample.
- Less pre-audit cleanup, because gaps were fixed as they happened.
- Trusted beyond the team: represented the reporting team’s two controls in the company-wide audit, then went on loan to Internal Audit, coordinating SOC audit activities across the company’s 180 controls.
5What I’d recommend next
- Let the system enforce the checks. Required fields and workflow rules that block release without approvals would turn a daily review into an exception report.
- Bring recurring business reviews into scope. They hold some of the most sensitive client information and belong in the controlled process.
Described in general terms. Figures are from memory and the author’s resume; visuals are illustrative and contain no confidential company, client or system data.
Downloads
The full case study includes requirements, stakeholder analysis and trade-offs.