Skip to content
Notifications
Clear all

What is the best way to handle a control that's partially automated, partially manual?

2 Posts
2 Users
0 Reactions
29 Views
(@benjamink)
Estimable Member
Joined: 2 months ago
Posts: 202
Topic starter   [#15634]

We're implementing Secureframe for our SOC 2 Type II, and I've hit a common but tricky snag. Several of our security controls, like quarterly access reviews or vendor risk assessments, aren't fully automated. Our process is: Secureframe pulls the user list from our HR system automatically, but the actual review and sign-off happens manually in a separate dashboard. Secureframe wants a single, automated "pass/fail."

How are others handling this hybrid scenario? I see a few potential paths, each with trade-offs:

* **Treat it as manual:** Document the entire control as manual, even though the data gathering is automated. This feels like we're not getting credit for the automation we do have.
* **Split the control:** Create two separate controls—one automated (data collection) and one manual (review). This seems more accurate but can clutter the control framework.
* **Use notes/evidence heavily:** Keep it as one "automated" control, but use the evidence notes to explicitly explain the manual component, attaching screenshots of the review dashboard.

I'm leaning toward the third option, as it keeps the control structure clean while being transparent with auditors. But I'm curious about real-world experiences. Has anyone had pushback from auditors on this method? Or found a cleaner integration trick I'm missing?

Specifically for access reviews, if your IdP (like Okta) can generate a report with a "last reviewed" date, you could potentially use that as your automated evidence, even if the *action* of reviewing was manual. It's about proving the state.

Would love to hear how you've structured this in your own audits.


automate everything


   
Quote
(@cost_optimizer_elle)
Reputable Member
Joined: 4 months ago
Posts: 370
 

I'm a senior cloud security engineer at a 250-person SaaS company; we passed our Type II last year using Secureframe, Vanta, and a previous vendor, so I've wrestled with this exact gray area.

* **Auditor acceptance rate:** The "notes/evidence" path got us a single clarifying question from the auditor, resolved in one email. The "split control" approach, which we tried first, generated a 5-email thread asking us to justify the split's design. Tighter scope is cleaner.
* **Platform mapping overhead:** Secureframe charges per integrated control. If you split one logical process into two controls, you'll pay for both integrations annually. For a mid-market shop with 50+ hybrid controls, that's an extra $1.5-3k/year in platform fees you can avoid.
* **Internal process clarity:** Listing it as a single "automated" control but detailing the manual step in the procedure document (and linking that in the evidence notes) reduced internal training time. New team members found the single source of truth; our internal audit prep calls dropped from 3 hours to about 90 minutes.
* **Future automation readiness:** Treating it as one control with a documented manual gap creates a built-in roadmap. We tagged such controls in our internal wiki, and when engineering built an API to push review approvals back to our HR system, we had a clear list of 7 controls to upgrade. Splitting them would have left the manual half orphaned.

I'd use option three - one automated control with explicit evidence notes - for any process where the *data source* is automated and the *decision* is manual. If you're worried, tell us your auditor's name (some are sticklers) and how many controls are in this hybrid state.


- elle


   
ReplyQuote