SOC 2 & ISO 27001 Compliance Automation Pipeline
Compressed a 12-week SOC 2 evidence cycle to 9 business days - enabling concurrent SOC 2 Type II and ISO 27001 certification with evidence packages accepted without re-submission.
An organisation pursuing concurrent SOC 2 Type II and ISO 27001 certification faced an evidence collection process that took 12 weeks per framework - effectively requiring 24 weeks of manual evidence work for dual certification. The process involved spreadsheet tracking, manual evidence requests to control owners, and no systematic mapping between the two frameworks. Auditors were receiving inconsistent evidence packages and requesting re-submissions.
I built a common control framework (CCF) mapping SOC 2 Trust Service Criteria and ISO 27001 Annex A controls to a single set of control activities. Each control activity mapped to both frameworks simultaneously - eliminating redundant evidence collection. I implemented a continuous evidence pipeline using Vanta as the evidence collection platform, integrated with AWS Config, Azure Policy, and key SaaS tools to pull automated evidence on a continuous basis. Manual evidence items were assigned to control owners with standardized templates and tracked through ServiceNow. The combined evidence library fed both audit streams from a single source.