Compliance Assessment Workflow
A systematic compliance assessment workflow takes you from initial client intake through final report. Here is the process that produces consistent, defensible assessments.
Phase 1: Client Intake
Every assessment starts with intake. This phase establishes scope, expectations, and access. Skip it and you will spend the engagement renegotiating boundaries.
Intake activities:
- Scope confirmation: Which systems, products, locations, and data flows are in scope?
- Framework selection: SOC 2, ISO 27001, CMMC, HIPAA, or multiple? Type I or Type II?
- Stakeholder identification: Executive sponsor, technical leads, evidence custodians
- Access provisioning: Document repositories, ticketing systems, monitoring tools, evidence storage
- Schedule: Kickoff date, evidence deadline, fieldwork window, report delivery
- Communication plan: Cadence, channels, escalation paths
Document everything in a project charter or statement of work. Both sides sign before substantive work begins.
Use the assessment learning module for intake templates and prompt structures that accelerate this phase.
Phase 2: Evidence Indexing
Evidence indexing maps every artifact you receive to controls and requirements. Without an index, you cannot answer auditor questions efficiently.
Indexing approach:
- Receive evidence: Through document portal, shared drive, or GRC platform
- Catalog each artifact: Filename, source system, capture date, content type
- Tag to controls: Which framework requirements does this artifact support?
- Identify gaps: Controls without evidence, evidence without controls
- Request additional evidence: Specific, named requests for missing items
The index is typically a spreadsheet or database with one row per artifact. Columns include the source, date, control mappings, sensitivity classification, and status (pending review, reviewed, accepted, rejected).
Build the index iteratively. Start with the artifacts already on hand. Track the gap list. Request additional evidence in batches rather than one at a time.
Phase 3: Control Evaluation
For each in-scope control, evaluate effectiveness using examine, interview, and test methods:
- Examine: Review documentation and configuration evidence
- Interview: Talk to control owners and operators
- Test: Verify operation through samples
Document evaluation results for each control:
- Control description from the framework
- Implementation as documented in the SSP or SoA
- Evidence reviewed
- Interviews conducted
- Tests performed
- Findings (effective, partially effective, ineffective)
- Rationale for the finding
Sample size depends on framework and control frequency. SOC 2 Type II often requires 25-40 samples for daily controls. CMMC follows NIST 800-171A guidance with smaller samples but more rigorous documentation. ISO 27001 internal audit can be tighter than the external surveillance audit.
The evaluation phase is where most engagement time is spent. Plan for 60-70% of total engagement effort here.
Phase 4: Gap Identification and Remediation
Gaps emerge from control evaluation. Categorize and prioritize them:
- Critical gaps: Controls absent or fundamentally ineffective. Block certification.
- Significant gaps: Controls partially implemented. Remediation required before audit.
- Minor gaps: Controls effective with minor improvements available. Track but do not block.
- Observations: Strengths and best practices to document
For each gap, work with the client to develop remediation:
- Description of the gap
- Recommended remediation
- Estimated effort and resources
- Target completion date
- Verification method
Some remediations can be completed during the assessment engagement. Others extend post-engagement. Document the timeline clearly so the client knows what is committed during the engagement and what extends beyond.
Phase 5: Reporting
Three deliverables typically emerge from a compliance assessment:
- Executive summary: 5-10 pages for leadership. Overall posture, key findings, recommended program plan, expected timeline to certification
- Detailed findings report: 50-200 pages with control-by-control analysis. Includes findings, evidence reviewed, gaps identified, recommendations
- Remediation roadmap: Prioritized backlog with owners, dates, and dependencies. The operational document for closing gaps
Report quality matters. Reports that audit firms refer back to during certification audits are well-organized, thoroughly evidenced, and clearly written. Reports that gather dust were too generic or too verbose to be useful.
Build the report iteratively as the engagement progresses. Do not wait until the end to start writing. By fieldwork end, the report should be 80% drafted with only the executive summary and final findings list to complete.
Frequently Asked Questions
Related Articles
System Security Plan Writing Guide
The System Security Plan is the central document for CMMC, FedRAMP, and NIST 800-53 assessments. Here is how to write one that holds up under assessor scrutiny.
Audit Readiness Checklist
Audit readiness is more than controls. Documentation, evidence, personnel, and logistics all need preparation. Here is a comprehensive checklist that applies across frameworks.
Evidence Collection Best Practices
Evidence quality determines audit speed and outcome. These patterns apply across SOC 2, ISO 27001, CMMC, and any other framework you operate.