For the people who run the programme

Why compliance programmes stall: nine pain points and the fix for each

Most SOC 2 and ISO 27001 programmes do not fail. They stall: evidence scattered across tools, policies nobody reads, a questionnaire that resets every deal, an auditor who asks by email. This guide names the nine places time goes and what removes each one.
In one paragraph: programmes stall because the work is spread across people who have other jobs and tools that were not built to hold evidence. The fix is structural: one control library shared by every framework, connectors that collect evidence automatically and hash it on arrival, policies written with the team that must follow them, and a named lead who runs the weekly cadence. With that structure a first SOC 2 or ISO 27001 is audit-ready in 8 to 12 weeks.
Where compliance programmes lose timeChasing evidence by hand34%Rewriting policies that were never followed18%Answering the same questionnaire again15%Email loops with the auditor12%Re-scoping after a surprise finding11%Reporting to leadership10%Share of programme time, illustrative distribution from Certifyi engagements. The first three rows are the ones a platform with a named lead removes almost entirely.

The nine pain points

Each one costs weeks. Together they are why “we started SOC 2 last year” is such a common sentence.

Evidence

1. Evidence lives everywhere

Screenshots in Slack, exports in Drive, tickets nobody closed. Fix: read-only connectors to cloud, identity, code and ticketing tools collect evidence on a schedule; every file is hashed and versioned on arrival.

Policies

2. Policies describe a company you are not

Downloaded templates fail the first staff interview. Fix: policies written with your team by a named compliance lead, then mapped to controls and tested.

Frameworks

3. Every framework starts from zero

SOC 2 done, now ISO 27001 wants it all again. Fix: one control library; a second framework reuses most of the first.

Sales

4. The questionnaire resets every deal

Same questions, new spreadsheet. Fix: answers from your record, a public Trust Center, and suppliers answering once in their own workspace.

Audit

5. The auditor asks by email

Attachments, versions, “which one is final”. Fix: the audit firm works in the Auditor Workspace on the same record, with findings and CAPA on one trail.

Risk

6. Risk is a colour, not a number

Red, amber, green persuades nobody with a budget. Fix: Monte Carlo loss modelling turns the register into a currency range the board can act on.

Access

7. Access reviews and offboarding slip

The most common audit finding. Fix: identity connectors flag leavers and stale privileges; reviews run on a schedule with evidence attached.

Cadence

8. Nobody owns the calendar

Evidence collected in a rush before the audit. Fix: continuous monitoring after the audit, not just before it, and a weekly check-in with a named lead.

Reporting

9. Leadership hears about it at the audit

Surprise findings, surprise cost. Fix: monthly health reports and a quarterly board pack built from live data.

What a realistic timeline looks like

Eight to twelve weeks to audit-ready is achievable when the structure is right. Here is how the weeks are spent.
WeeksWorkWhoOutput
0 to 1Scoping call, framework choice, deployment provisionedCompliance lead, founder or CTOScope, gap list, plan
1 to 2Connectors, control mapping, first evidence runCompliance lead, engineeringControl library live, evidence flowing
2 to 4Policies with the team, risk register, vendor listCompliance lead, team ownersApproved policies, quantified risks
4 to 8Control remediation, access reviews, training, auditor selectedTeam, auditor in workspaceControls passing, readiness review
8 to 12Internal readiness review, Type I or Stage 1; Type II observation beginsAuditor, compliance leadAudit-ready; report or certificate path

Self-serve platform, consultant, or done-with-you

The three ways teams buy compliance, and where each one stalls.
Self-serve platformConsultantCertifyi (done-with-you)
Who runs the weekly workYouThe consultant, off-platformA named compliance lead, in the platform with you
Evidence integrityVariesDocuments and emailHashed, versioned, never silently deleted
Auditor accessShare links or exportsEmailAuditor Workspace on the same record
SuppliersQuestionnaire emailsManualSupplier Workspace, answer once
Pricing basisHeadcount and add-onsDay rateScope and framework; platform fee due at audit sign-off

Stalled programmes, answered

Re-scope. Most stalled programmes carry controls that do not apply and evidence collected by hand. A readiness call maps what exists to one control library and gives a realistic date, usually 8 to 12 weeks from restart.

It can be, if someone owns the programme and has the time. The common failure is that nobody does. Certifyi includes that person, working in the same record.

Not separately. A consultant working by email creates its own evidence problem. A done-with-you model puts the expert inside the platform, so the work and the evidence stay together.

Because a stalled programme usually has evidence of unknown provenance. Hashing and versioning on arrival means every file you collect from now on can be proven unchanged, which is what the auditor needs.

Continuous monitoring, scheduled access reviews, and a monthly report to leadership. The certificate is a point in time; the management system is the thing that earns its keep.

Find out where your programme is stuck

Twenty minutes with a compliance lead. You leave with a scope, a gap list and a realistic date.
Scroll to Top