Ramp
Dual-report engagement covering financial reporting and security.
A combined SOC 1 / SOC 2 engagement for a fintech processing corporate card transactions, with shared control mapping to reduce evidence duplication.
- Sector
- Corporate spend & fintech
- Framework
- SOC 1 Type II + SOC 2 Type II
- Year
- 2024
- Signed by
- Partner
§ 01 — Scope
What we tested.
- 01ITGC testing across three production environments
- 02Transaction processing controls (SOC 1)
- 03Trust Services Criteria mapping (SOC 2)
- 04Third-party ledger reconciliation controls
§ 02 — Findings
01
Overlapping evidence collapsed to a single unified control matrix, reducing management burden by ~40%.
02
Two SOC 1 process-level exceptions, both remediated pre-issuance.
§ 03 — Outcome
Both reports issued in the same package, delivered to auditors of downstream customers.
§ 04 — Next