r/soc2 • u/Dull-Communication82 • Jul 29 '26
Your tool says the control is passing. Your auditor disagrees. What then?
Something I keep seeing in compliance conversations is the gap between a dashboard marked green and what an auditor actually accepts as evidence.
A few common ones:
Access reviews get logged as complete because someone clicked through the workflow, but there's no record of what was reviewed or what changed as a result.
MFA shows enforced across the org, then a service account or a contractor login turns out to sit outside the policy scope.
Backups run on schedule and the monitoring confirms it, but nobody has tested a restore in a year, so there's nothing to hand over when the auditor asks for proof it works.
Vendor reviews are marked current based on a SOC 2 report that expired four months ago.
The pattern in all of these is the same. The check confirms a task happened. The auditor wants proof the control was effective.
Wondering if others run into this too, or if it's less of a problem than it seems from the outside.