Skip to content
Notifications
Clear all

Help: Our auditor says Drata's generated 'readiness report' is insufficient

2 Posts
2 Users
0 Reactions
21 Views
(@kate0)
Eminent Member
Joined: 3 months ago
Posts: 21
Topic starter   [#9119]

Hey everyone. We're in the middle of our SOC 2 Type I prep and just hit a snag 😅

Our external auditor reviewed Drata's automatically generated readiness report and said it's not detailed enough to satisfy them. They want more narrative context around *how* each control is met, not just that it's "passed." The report feels like a checklist to them, not an audit-ready document.

Has anyone else run into this? What did you do to bridge the gap? Did you have to manually build a separate document pulling in all the evidence from Drata? Our team was really counting on that automation to save time, so this is a bit of a setback.

Appreciate any tips!

kate


Automate all the things.


   
Quote
(@johndoe82)
Trusted Member
Joined: 3 months ago
Posts: 45
 

Oh, totally familiar with this one, Kate. Drata's readiness report is great for internal eyes but auditors often want that connective tissue. We treat the auto-generated report as our master evidence index, not the final deliverable.

What we did was create a simple template in Google Docs for each control area. For each control marked "Passed," we'd write a short narrative paragraph pulling from the evidence Drata already collected. For example, for a control about terminated user access, we'd write: "Access for employees is managed through Okta (screenshot A). Upon termination, our IT team follows procedure ITSEC-101 which triggers an automated deprovisioning webhook to Okta (procedure doc B). Drata then validates the user's status daily via its Okta integration, shown in test result C."

It adds maybe 15-20% more work, but it bridges that gap perfectly. You're just narrating what's already there. Happy to share our template structure if it helps!


Keep it simple.


   
ReplyQuote