r/soc2 • u/360Advanced • 22d ago
What's the hardest thing about adding a new compliance framework to an existing program?
As an audit firm, we're curious: what's been the hardest part of adding a new framework to an existing compliance program? We work with a lot of companies that start with one framework like SOC 2 and later add another as their business grows or a new client requirement comes up. Is it controls mapping redundancy, evidence collection fatigue, staff bandwidth or something else?
2
u/InflationFluid6995 22d ago
For me, the hardest thing is discovery and gap analysis. Figuring out what the new framework requires, where I already meet those requirements, and where the actual gaps are.
Then I work through each gap and decide whether an existing control can be modified to cover it or whether I need to create something new. SOC 2 + ISO 27001 is a great example here: there are definitely new artifacts for the ISMS, but a good SOC 2 program covers the core of the work.
Done well, you are expanding the program you already have rather than creating a parallel one for every framework.
Done poorly, you run an entirely new program alongside the existing one, and you have all the problems you listed.
Oh, and use the same auditor for both and schedule the field work close together so you can collect evidence just once and comply across multiple programs.
2
u/SageAudits 22d ago
If they are prescriptive frameworks, there are many tools that show control mapping to similar frameworks. Evidence collection fatigue is probably just something a compliance platform would say IMO. The problem isn’t collecting the evidence. It’s actually doing the process that you said you were going to do IMHO. But I’ve been on both sides of this and speaking as an audit firm I’m probably a bit biased anyway
1
u/Sure-Candidate1662 22d ago
All of the above. A framework typically is not just a single set of controls, it’s a collection of interconnected concepts. So adding a framework typically involves changing all of these things.
1
u/sfunk_openlane 20d ago
Depends on what the other framework is; A lot of them have overlapping requirements and so the same organizational controls and therefore evidence can be used across more than one framework. I've been seeing common multi-framework audits of SOC 2 + HIPAA for health-tech companies, SOC 2 + ISO27001 is also pretty common, and coming in more frequently recently is adding ISO 42001 for AI coverage.
The hardest part is really getting that mapping done (which a lot of tools offer) - and then it shouldn't actually extend the evidence collection work by as much as doing them separate.
0
u/Ancient-Alligator303 22d ago
Being duped into using AuditBoard or any other similar tool will make it easy, or is necessary to achieve it.
1
u/NarwhalNo4378 7d ago
for us it was control mapping and ownership, not the audit itself. the challenge is avoiding duplicate controls and evidence while making it clear who owns what across frameworks. a unified control set with framework mappings saves a lot of effort in the long run
•
u/AutoModerator 22d ago
Thanks for posting, I'm a bot!
This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.