SOC2 / Vanta Evidence Collection
Continuous audit-readiness; zero last-minute scrambling
Evidence collection for SOC 2 is a two-quarter grind. Someone at the company opens Vanta / Drata / Secureframe every day and chases the failing checks. Employees get pinged for laptop-security screenshots, engineers for repo permissions, IT for MFA screenshots. Everyone loathes it. The company passes audit because someone worked nights the last three weeks. Then it starts again next year.
An hour-by-hour walkthrough.
Step by step.
- 01
Pull the control state daily
Read every control from Vanta / Drata / Secureframe / Tugboat / Thoropass. Automated checks + evidence-age + manual-attestation requirements. Normalise to a common control record.
Vanta · Drata · Secureframe · Tugboat · Thoropass - 02
Detect failing + aging + missing evidence
Failing: automated check is red. Aging: evidence older than the control's rolling window. Missing: manual attestation past its refresh deadline. Each maps to a different owner + remediation.
Compliance policy · Evidence age matrix - 03
Route to the correct owner with the fix
Context Graph resolves owner (individual, team, function). Owner DM has: the specific failing check, why it matters, the exact fix (not a link to a runbook), and often a one-click remediation.
Slack · Teams · Context Graph · Runbook library - 04
Track responses + escalate
Response tracker per control. Nudge at day 2, escalate to manager at day 4, security lead at day 7. Non-response is itself a signal — surfaces control ownership gaps for org planning.
Approval tracker · Slack · Manager escalation - 05
Weekly digest + audit-readiness score
Weekly digest to security lead: control health rollup, aging evidence trend, top owners with open items, audit-readiness score (0-100) with drivers. Auditor-facing dashboard when audit window opens.
Analytics · Slack digest · Auditor portal
What you connect to make this run.
Vanta · Drata · Secureframe
read+writeRead control state, evidence age, connector status. Write remediation events, attestation acknowledgements, evidence uploads. The GRC platform stays the audit-facing system of record; Sig is the orchestration layer.
Okta · Google Workspace · Jamf · GitHub · AWS
read+writeDirect writes for automated remediations. Missing MFA → force enrollment. Missing branch protection → PR to enable. Unencrypted laptop → MDM policy push. Each verified before marking evidence current.
Slack · Teams · Email
read+writeOwner-specific DMs with the exact fix. Attestation acknowledgement forms embedded. Nudge + escalation ladder. Weekly digest to security lead + auditor.
Context Graph · Directory · CODEOWNERS
readOwner resolution: repo → maintainer, vendor → vendor-manager, laptop → user. Escalation ladder from org chart. Non-response gaps surface owner-mapping issues.
Before and after, honestly.
Answers about this playbook.
How does this differ from what Vanta / Drata already do?
Vanta detects the failing check + emails the owner. Sig routes to the correct owner via Context Graph, drafts the actionable fix (not just "go fix this"), often executes the fix directly, chases non-responses, and rolls up owner-response patterns for planning. GRC platforms report; Sig acts.
What if we have multiple compliance frameworks (SOC 2 + ISO 27001 + HIPAA)?
Sig deduplicates controls across frameworks. Laptop encryption is one control satisfying multiple framework requirements — one evidence-refresh action, multiple framework check-ins. Reduces employee burden proportionally.
Can auditors interact with the system?
Read-only auditor view. Auditor sees the current state, evidence links, remediation history, control ownership. No writes; can request additional evidence which routes to owners the same way.
What about controls that require in-person or physical evidence?
Physical-security controls (badge access logs, camera positioning) still require human verification. Sig routes the request to the office manager or physical-security team with the specific evidence template.
How does it handle new employees mid-audit-period?
New employees added to owner-resolution automatically. Their evidence backfills as they complete onboarding checks (laptop enrolment, MFA setup, security training). Auditor sees a full picture including hires within the window.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.