GUARDVEST / ILLUSTRATIVE EXAMPLE

SOC 2 readiness.
An example of the work.

A fictional example showing how GuardVest turns a gap into a clear evidence request, remediation action and leadership decision.

Illustrative only. Northstar Sample Co. is fictional. This is a selected readiness-work example, not a complete assessment, a client deliverable or an independent SOC 2 report.

Engagement contextGuardVest / Example / 01

The business.
The requirement.

Company: Northstar Sample Co., a fictional B2B software company with 35 employees.

System: Its hosted customer application, supporting cloud infrastructure and relevant business processes.

Goal: Prepare for a Security-category SOC 2 Type II examination requested by an enterprise buyer.

Scope decisions: Confirm system boundaries, customer commitments, service-provider responsibilities and the observation period with the independent CPA firm.

Leadership summaryGuardVest / Example / 02

What needs attention?

The team has documented policies and access-management tooling. The review identifies inconsistent evidence that access reviews occur and that departing employees’ access is removed promptly.

Readiness decision: Assign owners and demonstrate that these processes operate before relying on them during an examination period.

Still to confirm: Whether the supporting records are complete across all in-scope systems. The assessment remains open until the evidence is reviewed.

Selected assessment findingGuardVest / Example / 03

ACCESS MANAGEMENT / PRIORITY: HIGH

Access reviews are not consistently evidenced.

Observed condition: The IT lead describes quarterly reviews, but the records provided do not show reviewer approval or follow-up for two in-scope applications.

Business risk: Unnecessary or elevated access could remain active without a documented review or timely resolution.

Recommended action: Establish a repeatable review covering in-scope systems. Retain the reviewed access list, reviewer approval, exceptions and evidence of follow-up.

Owner: IT lead. Target: Within 30 days of the agreed plan.

Completion evidence: A completed review with sign-off, documented exceptions and closure records. GuardVest reviews the submitted evidence before updating the finding’s status.

Evidence request and remediation trackingGuardVest / Example / 04

The action behind the finding.

EVIDENCE REQUEST

Show how the review happened.

  • Access lists for the in-scope systems
  • Reviewer approval and review date
  • Exceptions and resulting changes
  • Confirmation that agreed changes were completed

Owner: IT lead
Status: Requested; not yet reviewed

REMEDIATION TRACKER

Make the follow-through visible.

Action: Complete and document the review; address exceptions.

Priority: High
Owner: IT lead
Target: Day 30
Status: In progress

Closure condition: Evidence demonstrates the review and follow-up occurred.

Actual findings, timing and evidence requests depend on the agreed scope and the company’s environment.

Discuss your requirementsGuardVest / Example / 05

Let’s scope your
SOC 2 readiness work.

Bring the customer request, target date and a summary of your environment. We’ll discuss the work your team needs and the right scope of support.