Home All services
Start a project → Call Now

Audit evidence for SaaS and technology companies

Pass your customers' security reviews — and keep shipping.

Enterprise customers want a SOC 2 report, an ISO 27001 certificate or a completed security questionnaire before they sign. We help you get the everyday controls running first, so the records an auditor checks build up while your team keeps shipping. Then you book the audit.

  • Records in place before the audit
  • Scoped to the product your customer buys
  • We reply within one working day.
  • AICPA AT-C 105 and 205
  • AICPA TSP 100
  • ISO/IEC 27001:2022
  • ISO/IEC 42001:2023
Illustration: a cloud platform holding separate app windows in glass compartments, linked to a clipboard with three check marks

In brief

Who it's for
SaaS and technology companies whose enterprise customers send security questionnaires, or ask for a SOC 2 report or an ISO certificate, before they sign.
What gets in the way
Booking the audit before the controls run. These audits read records made before anyone looked, so a rushed start turns the audit into catch-up work.
How we help
We pin down what the customer asked for, scope it to the product they buy, and set up controls that leave dated records. An independent auditor then signs.

Reading the questionnaire

What your customer is really asking for.

Most security questionnaires point to one of three documents. Each proves something different, so find out which one before you start.

A SOC 2 Type 2 report

An independent auditor's opinion on whether your controls actually ran across a stated period, with every test and exception listed. It is a report, not a certificate: there is no SOC 2 certificate to send. More on SOC 2 readiness.

An ISO/IEC 27001 certificate

Proof that an accredited certification body audited your information security management system: the risks, policies and controls you run. Buyers check that it cites the 2022 edition and covers the product they are buying. More on ISO 27001.

Questions about your AI

Once a model is part of your product, AI governance questions point to ISO/IEC 42001:2023. It certifies how you manage AI within a stated scope, not any model or its output. More on ISO/IEC 42001.

Who signs these. A licensed CPA firm signs a SOC 2 report, and an accredited certification body issues ISO/IEC certificates. We are neither: our job is getting you ready.

Audit first, evidence later

Why booking the auditor first backfires.

An audit can only describe what already happened.

It usually goes like this. A prospect sends a security questionnaire, the deal stalls on the audit question, and the company signs up an auditor before its controls exist. The audit period starts anyway. Then come the first access review anyone has run, change tickets written for code that already shipped, and policies approved the month the auditor asks for them. That is catch-up, not evidence.

  • SOC 2 Type 2. The auditor tests whether your controls ran throughout the period, using records dated as things happened. A review skipped in the second month stays skipped.
  • ISO/IEC 27001. There is no observation period, but the certification body expects your own internal audit and a management review to be finished first. Policies written the week before look exactly that new.

So the order is simple: get the controls running, let them build records, then book the audit.

SOC 2 Type 2 and the AICPA standards

Under the AICPA's attestation standards, AT-C sections 105 and 205, a SOC 2 Type 2 opinion covers whether controls operated throughout a stated period. The controls are measured against the AICPA's Trust Services Criteria (TSP section 100). The auditor samples records dated as events happened, so a SOC 2 Type 2 observation period should open only after the controls run.

ISO/IEC 27001:2022 clauses 9.2 and 9.3

ISO/IEC 27001:2022 has no observation period, and the trap still works. A certification body expects a completed internal audit under clause 9.2 and a management review under clause 9.3 before Stage 2, the main certification audit. Policies drafted just before that visit look as new as they are. The ISO/IEC 27001 Statement of Applicability has to trace back to risks assessed first.

Before anyone is booked

Six controls that should already be running.

Each one leaves its own dated record as your team works, so the evidence an auditor samples builds up while you ship.

Reviewed code changes

Code reaches production only through a pull request, linked to a ticket, that someone other than its author approves.

Single sign-on with MFA

Access to production and admin consoles goes through single sign-on, with multifactor authentication (a second login step) enforced.

Central logs

Production logs reach one central store and cover the whole audit period.

Regular access reviews

Reviews run on a fixed schedule and record who kept access and who lost it.

Clean offboarding

A ticket removes a leaver's access and shows when it happened.

A written scope

One statement names the product, its environments and what sits outside the audit.

For the engineering side, see DevSecOps consulting and cloud security review. For the policies and reviews around them, see GRC and compliance.

When a model ships

What changes once AI is part of your product.

ISO/IEC 42001:2023 asks a question no information security audit asks.

ISO/IEC 27001 asks what could happen to your information. ISO/IEC 42001:2023 asks what your AI systems do to the people they make decisions about. Its clause 6.1.4 makes that a separate impact assessment, with no counterpart in an information security management system.

What a 42001 auditor asks to see

  • An AI inventory. Every AI system in scope, including AI features inside vendor tools.
  • Impact assessments. One for each system that shapes a decision about a person.
  • A reason for every exclusion. Each Annex A control left out of the Statement of Applicability (the list of controls you apply) needs a written reason.
  • Triggers for a fresh look. Named events, such as a new model version, that force a new assessment.

Customers may also ask how your AI features resist misuse such as prompt injection. That is a technical question, answered by LLM security testing. For the wider picture, see AI governance.

Find the right help

Start with the situation you're in.

Most SaaS teams come to us with one of these. Each one leads to the page that answers it.

The order that works

Evidence first, auditor last.

Four steps. Skipping one only pushes the catch-up work later.

  1. Get the exact wording

    Get the questionnaire line or contract clause in writing, and note when the customer needs an answer. A report and a certificate lead to different work.

  2. Scope what the customer buys

    Draw the boundary around the product, environments and people this customer relies on. Unrelated offices and product lines add audit work nobody asked to see.

  3. Let the controls build records

    Run the six controls above day to day until they have built up dated records. Then open the SOC 2 period or book the first ISO audit visit, known as Stage 1.

  4. Hire an independent signer

    A licensed CPA firm signs the SOC 2 opinion, and accredited certification bodies issue both ISO/IEC certificates. SecWiz signs none of them, because whoever prepares the controls cannot also judge them.

From our work

A SaaS company, certified to ISO 27001 in eight months.

A B2B SaaS company kept losing enterprise deals at the buyer's security review. We ran its ISO 27001 program, from the first gap assessment through control design and evidence collection. Eight months after that first assessment, it passed its certification audit on the first attempt.

The timeline held because the company's own people owned the controls and did the work. Where a company can't commit people, the same program takes longer, and we say so at the start.

Read the case study

FAQ

Questions SaaS companies ask before booking an audit.

SOC 2, ISO 27001, ISO 42001 and the tools in between. For anything else, ask us directly.

Only if a customer has said in writing it will accept one while a Type 2 period runs. A Type 1 reports on control design at one point in time and tests nothing across a period. It does not start the Type 2 period or count as coverage, so doing it first can push the Type 2 further out.

The AICPA standards set no minimum length, which leaves the decision with the customer's vendor-risk team. Ask what it accepts before committing, because a period it considers too short buys a report it sets aside. Whatever the length, every control must be running when the period opens, since the auditor samples only what happened inside it.

No. The provider's report covers the provider's controls. When your SOC 2 carves the provider out, its controls fall outside your auditor's opinion, and your report states what you rely on it to do. Choosing and assessing that vendor stays your job, so customers still expect proof you reviewed its report.

It can gather evidence, but it cannot supply an opinion or records from before it was connected. Its automated checks are point-in-time queries against the vendor's own control list, not tests of a sample across a period. Connected halfway through an observation period, it says nothing about the stretch before.

Not unless the customer says so. A request for a SOC 2 report wants a CPA firm's tests and exceptions, which an ISO/IEC 27001 certificate and its Statement of Applicability do not contain. The work overlaps, though: a risk assessment, policies and management review records built for one carry across to the other.

It is voluntary, so the need comes from customers who ask. ISO/IEC 42001:2023 covers companies that only deploy AI, and a deployer can exclude most development controls with written reasons, though not impact assessment or third-party relationships. If the only AI in use is staff on a public chatbot, an acceptable-use policy and a vendor review is enough.

Let's talk

Send the questionnaire before you book an auditor.

Send the questionnaire or contract clause, with your customer's deadline. Project work is delivered remotely from India during business hours. We reply within one working day.