SOC 2 readiness assessment: finding the gaps before the auditor does
A readiness assessment is not part of the audit. It exists so that the audit does not become an expensive way of discovering you were not ready.
The authorisation is the document you produce when a customer disputes a debit. If you cannot produce it, the debit comes back regardless of what was agreed.
An ACH authorization form is the record of a customer’s permission for a business to debit their bank account. Network rules require the originator — the business taking the payment — to obtain authorisation before debiting, to give the customer a copy, and to retain the authorisation for a defined period after it ends.
The reason it matters commercially is disputes. When a customer claims a debit was unauthorised, the originator is asked to produce the authorisation. A business that cannot is not in a position to argue: the return is processed, and a pattern of them affects standing with the processor. The form is not paperwork for its own sake — it is the evidence in the only proceeding that follows.
The obligation is to keep the authorisation for a period after it is revoked or terminated — commonly two years — because a dispute can arrive after the customer has left. That means authorisations belong in a retained record rather than in the payment system, which may purge inactive customers on its own schedule. Where a customer revokes, keep both the authorisation and the revocation, with dates.
Give the customer a copy at the time. It is required for many authorisation types, and it is also the single most effective reduction in disputes: people query debits they do not recognise, and a copy in their inbox from the day they signed usually ends the conversation before it becomes a return.
Debits between businesses use a different entry class and rest on the agreement between the parties rather than a consumer-style authorisation form, and the window for the receiving business to return an item is much shorter. That is why suppliers taking payment from business customers should still hold a signed authorisation as a term of the contract — the network rules are less prescriptive, but the evidential problem when a customer disputes is identical.
Ettex Forms collects the authorisation with the required fields and the customer’s acceptance recorded, Ettex Records keeps it against the customer with the retention date visible so revoked authorisations are not deleted early, and the cheque-side equivalent of this control is covered in positive pay.
To be clear: this is forms and records, not a payments processor, and none of it is legal advice. Network rules set the required content, retention and entry classes, and they change; your processor and the current rules are the authority.
The record of a customer’s permission to debit their bank account, required before originating debits and retained for a period after it ends.
For a period after revocation or termination — commonly two years — because disputes can arise after the relationship ends.
Only with an authentication method appropriate to the entry class. A bare checkbox with no authentication is weak evidence in a dispute.
Yes. A different entry class applies, resting on the agreement between the parties, with a much shorter return window — but holding a signed authorisation is still the practical protection.
A readiness assessment is not part of the audit. It exists so that the audit does not become an expensive way of discovering you were not ready.
Every new employee has to be reported to a state directory within days of starting. It is the fastest-recurring obligation in HR, and the one most often discovered late.
There are several self-assessment questionnaires and they differ enormously in length. Answering the wrong one carefully is worse than answering the right one quickly.