Framework Scope Lock (Onboarding)
A checklist with 7 steps: Collect the client's actual buyer-side compliance asks before naming any framework.
By InnovaAI ResearchPublished
What are the steps?
Framework Scope Lock (Onboarding)
- 01
Collect the client's actual buyer-side compliance asks before naming any framework
Pull the security questionnaires, RFP clauses, and vendor review packets the client's prospects have sent in the last 12 months. The certification a buyer names in writing is the one that closes deals; anything else is scope the agency will pay for and never bill.
- 02
Map each requested framework to the controls it shares with the others
SOC 2 and ISO 27001 overlap heavily on access control, change management, and logging, so a single control set can often satisfy both. Platforms such as Sprinto and Secureframe publish cross-framework control mappings that shorten this exercise from days to hours.
- 03
Decide whether the engagement is readiness, audit support, or ongoing monitoring
Readiness ends at the auditor's report; ongoing monitoring runs monthly and belongs on retainer. Write the boundary into the statement of work so the client cannot treat a one-time readiness project as perpetual compliance coverage.
- 04
Assign a named control owner inside the client organization for every control family
Compliance workflows fail when the agency is the only party holding the controls. Get a client-side owner for access reviews, vendor risk, and incident response, and record the name in the shared workspace.
- 05
Inventory the systems that will feed automated evidence collection
List cloud accounts, identity providers, code repositories, and HR systems, then confirm each has an integration path. Vanta and Drata both connect to AWS, Okta, GitHub, and Slack, but a client running an unsupported legacy system needs a manual evidence procedure instead.
- 06
Set the evidence retention window and the review cadence in writing
Auditors typically want evidence covering the full observation period, which for SOC 2 Type II runs three to twelve months. A monthly review rhythm catches gaps while they are still fixable rather than during fieldwork.
- 07
Document the exit path for the compliance platform itself
Export control mappings, policies, and evidence history into a client-owned repository at onboarding. If the engagement ends or the client switches vendors, the certification record stays with the client instead of being trapped in the agency's account.