Ramp

Dual-report engagement covering financial reporting and security.

A combined SOC 1 / SOC 2 engagement for a fintech processing corporate card transactions, with shared control mapping to reduce evidence duplication.

Sector
Corporate spend & fintech
Framework
SOC 1 Type II + SOC 2 Type II
Year
2024
Signed by
Partner
§ 01 — Scope

What we tested.

  • 01ITGC testing across three production environments
  • 02Transaction processing controls (SOC 1)
  • 03Trust Services Criteria mapping (SOC 2)
  • 04Third-party ledger reconciliation controls
§ 02 — Findings
01
Overlapping evidence collapsed to a single unified control matrix, reducing management burden by ~40%.
02
Two SOC 1 process-level exceptions, both remediated pre-issuance.
§ 03 — Outcome

Both reports issued in the same package, delivered to auditors of downstream customers.

§ 04 — Next

A similar engagement for you.