Contracts, risk and SOC 2 evidence
Fiona's view · what's in flight, what's flagged, and where the audit stands. Nothing here was sent; drafts wait for you.
AI summary
Good morning. SOC 2 evidence is 11 of 16 items acknowledged, one outstanding: the incident-response tabletop after-action report, the auditor's flagged priority. The highest-severity open risk is LC-01, the SOC 2 finding rate, directly tied to the commercial-FM pipeline it gates. The sub-processor gap on Meridian Cloud Analytics remains open, live in production without a signed DPA.
SOC 2 evidence complete
11/16
69% acknowledged, 1 outstanding
ISO 27001
Held
no known drift, next surveillance ~3mo out
Contracts in flight
14
4 flagged for attention now
Open risks
12
1 High, 5 Medium, 4 Low-Medium, 2 Low
High severity, act this cycle
LC-01: SOC 2 evidence standard not yet met on access-review and incident-response controls, directly blocking Objective 5 KR3 and the commercial-FM pipeline gated on it. The tabletop after-action report is the priority item, target closure 10 days. Fiona owns escalation to the board on timeline risk if it slips.
Contract pipeline and renewals
LC-S-301, Meridian Cloud Analytics DPA
Compliance-linked, live 3 weeks without signed DPA
Flagged
LC-P-201, Meridian Channel Partners redline
7 days, no response, due a nudge
Nudge
LC-C-106, Helix Systems order form
Two issues to fix before redline returns
Flagged
LC-C-109, Halcyon renewal
Largest in 8-week window, briefing not written
Flagged
LC-C-101, Verda Facilities order form
Security review pending, 12 days to close
On track
Risk register, highest first
LC-01, SOC 2 finding rate
Mitigating, on track for estimated completion
High
LC-02, Meridian Cloud Analytics DPA gap
Open, mitigating, target 3-4 days
Medium
LC-03, customer scope creep on DPA
Amendment being drafted
Medium
LC-07, liability clause pressure
Monitoring, within tolerance
Medium
LC-12, Clearline Payments continuity
Monitoring, PCI-DSS reviewed 6-monthly
Medium
SOC 2 evidence status and sub-processor gap
Incident response: detection and response testing
Outstanding · auditor's priority item · target 10 days
Outstanding
Access control: privileged access review
In preparation · reformatting sign-off doc · target 4 days
In prep
Change management: emergency change process
In preparation · sample being pulled · target 1 week
In prep
HR: background checks and confidentiality
In preparation · sample being pulled · target 5 days
In prep
Sub-processor list: Meridian Cloud Analytics
Pending risk assessment, no signed DPA, live 3 weeks
Open gap
11 other evidence items
Submitted and acknowledged, including AI-governance controls
Acknowledged