How GetComply runs the work

A practical Managed GRC process for teams that need more than a checklist. SOC 2 is where many engagements begin. The operating rhythm continues after the first report.

The model

A shared workspace with a real advisor in it

The workspace keeps scope, controls, evidence, risks, decisions, blockers, and next steps in one place. Your advisor works there with your team, so the program does not live across spreadsheets, Slack threads, email, and someone's memory.

The workspace keeps the work visible. The advisor keeps it moving.

01

Set the scope

We identify the systems, services, vendors, people, locations, and commitments that matter to the engagement. We also clarify what is creating pressure, such as a customer request, procurement deadline, or planned examination.

You leave with

Defined scope, documented assumptions, and a working program baseline
02

Find the gaps

Your advisor reviews the controls, policies, governance practices, and evidence that already exist. We distinguish between missing work, weak work, and work that can be reused.

You leave with

A prioritized plan based on actual risk, external commitments, and the target examination
03

Work the next steps

We do not hand your team a giant list and disappear. The work is broken into focused actions, tracked in the workspace, and reviewed through weekly follow-up.

You leave with

Clear owners, visible blockers, and a current plan for the next week
04

Review the evidence

We review whether the evidence identifies the system, date or period, population, reviewer, approval, result, and follow-up needed to support the control.

You leave with

Stronger evidence and clear correction notes before auditor handoff
05

Prepare the CPA package

When the program is ready for the next stage, we organize the controls, evidence, risks, decisions, and context so the independent CPA firm is not starting from a pile of disconnected files.

You leave with

An organized package and supporting context for the CPA firm
06

Keep the program from drifting

After the first push, people change, vendors are added, policies age, access reviews come due, and questionnaires continue to arrive. Managed GRC keeps the recurring calendar active between audit cycles.

You leave with

A continuing operating rhythm instead of an annual emergency rebuild

The shared workspace

See what the program needs this week

Your team and advisor use the same workspace. Tasks, evidence, controls, risks, and blockers are visible to everyone involved. Nothing lives in a separate spreadsheet or email thread.

GetComply
|
Alex S.

Next Actions

8

2 in progress

Controls

47/63

12 in progress

Blockers

1

high priority

Evidence Items

38

4 pending review

Blocker: Vendor Assurance Report Overdue

Last completed 47 days ago. Required quarterly. Overdue by 17 days.

Readiness by Trust Criteria

Security (CC)82%
Availability (A)68%
Confidentiality (C)74%

Recent Activity

CC6.1 logical access control policy — evidence reviewed and approved2h ago
Next action assigned: upcoming GitHub access reviewYesterday
Blocker flagged: vendor assurance report overdue for review2 days ago
Monthly program brief delivered — completed work, blockers, and decisionsMar 1

Sample program data. Company details and figures are illustrative.

Who owns what

Clear responsibility, not fuzzy outsourcing

GetComply owns the operational work. The client retains business accountability and decision authority.

GetComply runs the program's operating cadence and prepares the work. Your team remains responsible for confirming internal facts, approving business decisions, authorizing changes, and accepting risk. GetComply does not replace management, legal counsel, technical administrators, or the independent CPA firm.

Your team retains GetComply owns
Confirm internal facts, systems, and ownership Maintain the shared workspace and current plan
Provide approved access to information and evidence Keep work moving through weekly follow-up
Approve policies, scope, exceptions, and process decisions Draft and refine policies and operating materials for review
Authorize and perform technical changes only your team can safely make Identify gaps, recommend controls, and track remediation
Accept or reject business risk Document risk decisions and keep the decision trail visible
Select the independent CPA firm and sign management representations Organize evidence and context for the CPA firm
Attend key review and decision checkpoints Flag blockers before they stall the program

GetComply will do as much hands-on GRC work as reasonably fits the engagement and its competence. When legal advice, privacy counsel, a CPA opinion, specialist engineering, penetration testing, certification authority, or another independent service is required, GetComply identifies the need instead of pretending to provide it.

The operating rhythm

A cadence that keeps running between audits

Weekly

  • Update priorities and blockers
  • Follow up on focused next steps
  • Review newly submitted evidence
  • Record decisions and changes

Monthly

  • Review program status
  • Summarize completed work and open risk
  • Escalate decisions that require leadership
  • Set the next operating priorities

Quarterly

  • Review governance, access, risk, and recurring obligations
  • Reassess vendors and changes that affect scope
  • Confirm that recurring controls continue to operate

Annually or by audit cycle

  • Refresh policies and risk work as appropriate
  • Coordinate tabletop and governance activities in scope
  • Prepare the evidence and context for the next examination cycle

See whether this operating model fits your team

Book an intro call to discuss the trigger, current ownership, and where the program is getting stuck.