ISO 27001 to a SOC 2 Type 2 report in four months, with no compliance hire

Engineered Intelligence had the controls and none of the SOC 2 expertise. Nank.ai's Compliance as a Service supplied both halves of what was missing.

TL;DR

Engineered Intelligence did not build a SOC 2 team. It subscribed to one. The platform mapped two years of ISO 27001 controls onto the Trust Services Criteria. A named compliance manager designed what SOC 2 asks for and ISO 27001 does not, then ran evidence collection. Audit-ready in three months, report in the fourth, zero exceptions.

3 moTo SOC 2 audit-ready
4 moTo the Type 2 report in hand
0Exceptions in the report
3 moOf a full-time hire saved

Source: Engineered Intelligence engagement record, Nank.ai

The challenge

Engineered Intelligence is a Calgary software company. Its platform, ENGIN, models an electric grid as a connected system and predicts how one failing asset drags the rest down with it. Some of the largest distribution networks in Canada run on that answer.

The company had held ISO 27001 for two years. Then several large utility customers asked for a SOC 2 Type 2 report instead. A CPA firm writes that one, and it states whether your controls ran across a period the auditor tested. A procurement team that asks for it will not take a certificate in its place.

Two problems sat in the way. Nobody on the team had run a SOC 2 before, so there was no in-house expertise to draw on. And two years of records sat across spreadsheets, shared drives and document stores. The controls were running. Proving it against a framework nobody knew was a different job.

"Two years of ISO 27001 gave us a mature control environment. What it did not give us was a way to present those controls against the SOC2 Trust Services Criteria. The mapping between the two frameworks was the real work, and it called for expertise our engineering team did not have."

Alex KacharChief Technology Officer, Engineered Intelligence Inc.

The solution

Engineered Intelligence subscribed to Nank.ai's Compliance as a Service. One subscription, two halves. A platform that does the work nobody should do by hand, and a person who owns the outcome.

"We had evaluated compliance platforms before. A platform gives you a place to record the work. It does not carry the work for you. What we needed was a partner who would own the plan, the schedule and the auditor relationship. Our engineers contributed where it mattered and stayed on the product."

Alex KacharChief Technology Officer, Engineered Intelligence Inc.

The platform mapped the controls

The compliance management platform took the existing ISO 27001 control set and mapped it onto the Trust Services Criteria. No one did that by hand. Every control landed in one library against the criteria it satisfies.

That mapping is what the rest of the engagement ran on. It showed which criteria the company already answered, which it did not, and where the two years of records belonged. Artifacts and technical evidence then sat against the criterion each one proves, rather than under the framework that first asked for them. A SOC 2 auditor tests a criterion and then asks for the population behind the sample. The library answers in that shape.

The compliance manager ran the program

A named compliance manager supplied the expertise the team did not have. He designed the controls SOC 2 asks for and ISO 27001 does not name. He drafted the system description and walked each owner through the rollout.

He then ran evidence collection on the platform. Collection pulled from source systems on a schedule. Control status then showed the real configuration, not a screenshot from whenever somebody last thought to take one. He tested every control, routed findings to an owner and tracked each retest to closure. He held the auditor relationship for the whole examination.

The team reached audit-ready in three months. The auditor issued the SOC 2 Type 2 report in the fourth month with zero exceptions.

Why the report landed in month four

That timeline needs its mechanism, because the number is hard to believe without it.

A Type 2 report covers a period. You and your auditor agree that period, and the auditor tests whether your controls ran across it. Nothing in the AICPA Trust Services Criteria requires it to sit in the future. For most companies it does, because the evidence does not exist yet. Our guide to how long a SOC 2 Type 2 takes is blunt about it. The fastest honest path from a standing start is six and a half months. We publish that even though it makes us look slow.

Engineered Intelligence was not starting from a standstill. The controls that mattered had run under the ISMS for two years, with dated evidence behind every one. The mapped library could show which ones. The auditor set the window over a period that had already elapsed.

Read this before you quote the four months

A retrospective window works only for controls that were already running and already evidenced. Anything designed during the engagement has no history and has to run first. That splits your control set in two, and the split is the conversation to have with your auditor on day one. If a vendor offers you a fast Type 2, ask which period the report covers and which controls were in scope for it.

The return

Nank.ai ran the preparation end to end. Engineered Intelligence's staff kept their day jobs and adjusted processes they already owned. Nobody moved onto a compliance project.

The company puts the saving at about three months of one full-time hire. Treat that as their estimate, not a benchmark. Salaries vary, and nobody gets to run the other version of the year to check.

"One system now covers the full lifecycle. We design a control, implement it, monitor it, verify it and present it to the auditor without moving the record between tools. We write each control once and it answers both ISO 27001 and SOC 2. That is what made the second framework affordable."

Alex KacharChief Technology Officer, Engineered Intelligence Inc.

The larger saving does not show up on a timesheet. A first SOC 2 tends to force one of two choices. Recruit a compliance lead the deal flow does not yet pay for. Or pull engineers off the roadmap for months of policy writing and evidence chasing. Engineered Intelligence made neither choice. For what a first report costs, see what a SOC 2 Type 2 report costs.

"Compliance as a Service kept my engineers on the product. The compliance programme ran beside them, not through them. They adjusted processes they already owned and gave up none of the roadmap."

Alex KacharChief Technology Officer, Engineered Intelligence Inc.

Frequently asked questions

Can we do SOC 2 with no in-house compliance expertise?

That is the case this story describes. Nobody at Engineered Intelligence had run a SOC 2 before. The compliance manager supplied the judgment, the platform supplied the mapping and the evidence collection, and the engineering team stayed on the product. What you do need is controls that already work, and someone on your side who can approve a process change.

How does the platform map ISO 27001 controls to SOC 2?

Every control goes into one library and gets mapped to the Trust Services Criteria it satisfies, without anyone doing it by hand. Artifacts and technical evidence then sit against the criterion each one proves. Write the control once and it answers both frameworks, which is why the second framework costs a fraction of the first.

What does the compliance manager do that a platform cannot?

Judgment and ownership. Designing the controls a framework leaves to your risk assessment. Deciding which controls have enough history to support a window. Walking owners through a change rather than sending them a task list. Holding the auditor relationship. The platform maps, collects and monitors. It does not sit across from an auditor.

Can our observation window cover a period that has already passed?

Sometimes. The AICPA sets no rule that the period must sit in the future. An auditor can test an elapsed period when dated evidence exists for every control in scope. A certified ISMS is the usual reason it exists. Controls you designed during the project have no history, so they have to run first.

Can we give buyers an ISO 27001 certificate instead of a SOC 2 report?

No. ISO 27001 certifies a management system. SOC 2 is an attestation report from a licensed CPA firm on your controls against the Trust Services Criteria. A procurement team that asked for SOC 2 will not swap. Holding one does make the other faster, which is what this story shows.

Asked for SOC 2, and nobody in-house has run one?

A named compliance manager takes the program, and the platform maps the controls you already run onto the second framework. Book a scoping call and see what carries over.

Table of Contents

Scroll to Top