Skip to content

Retained advisory

Ready for the audit, not just papered for it.

We prepare organizations for SOC 2 Type II and ISO 27001 by making the controls real first and the evidence automatic second.

Service

Compliance & Audit Readiness

Engagement

Retained advisory

To audit-ready

3 – 6 months

In short

What is Compliance and audit readiness?

Compliance and audit readiness is the work of making the controls a framework requires real in the environment, and the evidence for them automatic, before an independent auditor arrives. Fincham Systems prepares organizations for SOC 2 Type II and ISO 27001; it does not perform the audit, which must be done by a licensed firm.

The problem

Policy that does not match practice fails twice

The fastest route to an audit is a template policy set nobody follows. It survives the readiness review and fails the audit, because Type II tests whether the control operated over a period, not whether it was written down. The slower route is the only one that holds: make the control real first, then collect the evidence automatically.

Scope

What the engagement covers.

Anything outside this list is quoted separately rather than absorbed quietly.

Framework selection and scoping: SOC 2 Type II, ISO 27001, HIPAA, CIS or NIST CSF
Gap assessment against the chosen framework
Control design that fits how your organization actually operates
Policy authoring and review, written to match practice
Evidence automation so collection is continuous, not a quarterly scramble
Auditor liaison and support through fieldwork
Remediation of the technical controls, not just documentation of them

Deliverables

What you are left holding.

Every item here is an artifact you own, in your systems, readable by someone who was not in the room.

01

Control matrix

Every framework requirement mapped to the control that satisfies it, the system that enforces it and the evidence that proves it.

02

Policy set

Written to describe what your organization does. If a policy and the practice disagree, we change one of them deliberately.

03

Evidence pipeline

Automated collection wherever the platform allows it, so the observation window takes care of itself.

04

Readiness assessment

An honest verdict on whether you would pass today, and what stands between you and that.

To audit-ready: 3 – 6 months

SOC 2 Type II additionally requires an observation window, typically 3 – 12 months, which runs after readiness.

Fit

Who this is for, and who it is not.

We would rather lose the engagement at this paragraph than three weeks in.

A good fit if

  • A customer or investor has made SOC 2 or ISO 27001 a condition
  • You failed a readiness review and need the technical gaps genuinely closed
  • You have compliance software but nobody to make the controls real

Not a fit if

  • You want the certificate without changing how the organization operates
  • You need the audit itself. That must come from an independent licensed firm, and we cannot be both

Questions

About Compliance and audit readiness.

Is Fincham Systems SOC 2 certified?

No. Fincham Systems LLC holds no compliance certifications, and you should be skeptical of consultancies that imply otherwise. What we provide is the engineering and advisory work that gets your organization ready for its audit. The audit itself is performed by an independent licensed firm.

Do you work with Vanta, Drata or Secureframe?

Yes. Those platforms are good at collecting evidence and poor at making a control real in the first place. We handle the engineering they assume you have already done.

How long until we have the report?

Readiness typically takes 3 – 6 months depending on your starting point. SOC 2 Type II then requires an observation window, commonly 3 – 12 months, before the auditor can issue. Anyone promising a Type II report in 30 days is describing a Type I.

Often paired with

What this usually runs alongside.

These are the combinations that come up most often, not an upsell list.

Project or retained

DevOps & CI/CD

Deployments that are boring on purpose.

Read the scope

Compliance & Audit Readiness

Thirty minutes, no pitch.

Tell us what the environment looks like today. We will tell you what we would change first, and whether this is the right engagement for it.