Service organization controls reporting
We agree the report before we start: SOC 2 Type 2, a Type 1 point-in-time examination, or SOC 1 when the controls affect customer financial reporting. For a Type 2 we agree the system, the criteria, and the observation window, write each control with its owner, and test it before the window opens. During the window we check evidence each month, so the CPA firm gets complete populations and samples when fieldwork starts.
Engagement brief
Fixed scope
AccountableYour named owner
ResponsibleA Truvara practitioner
Drafts and citesCASK
Phases
We confirm scope and timing after a first call.
When teams call us
Enterprise buyers ask for a SOC 2 Type 2 report before they sign
You have a Type 1 report and customers now want Type 2
An auditor is booked and evidence collection has not started
Last year's report had exceptions you need to fix
What you receive
Drag the divider. On the left, where the work usually starts. On the right, the files you receive.
What you receive
The files from this engagement
Gap assessment
Implementation
Before the engagement
What we usually find on day one
A zip of screenshots. The control story is still in someone's head.
What it works against
CASK maps every requirement to evidence in the workspace, so scoping starts from what already exists and what is missing.
Key areas covered
How it runs
One sequence, from the records you already have to the outcome in your hands.
Set scope
Agrees the system boundary, criteria, and window dates with you and your CPA firm.
Design controls
Writes controls with each owner so they match how the team works today.
Test readiness
Tests a sample for each control and presents the gaps.
Run the window
Meets owners each month and follows up on late evidence.
Support fieldwork
Answers auditor questions with your team and reviews every response before it goes out.
What we need from you
Questions