WEBINAR
The Assurance Gap: What 103 SOC 2 Reports Actually Showed Us
August 26, 2026 | 11:30 AM CT
Third-party risk teams collect assurance artifacts at volume and record the result in a column: SOC 2, yes. New research examining 103 SOC 2 reports across 37 audit firms shows what that column can and cannot support. Every report carried a clean opinion. Forty percent contained exceptions the reader had to evaluate. None of them tested the vendor’s own service providers.
AJ Yawn and Ryan Patrick open the series by tracing how information security assurance evolved from a periodic compliance exercise into a core operating requirement, and why the artifacts we inherited from that evolution struggle under the weight now placed on them. This session establishes the vocabulary for the series: scope, threat coverage, quality, supply chain, and measurable outcomes. Attendees leave able to read their next vendor report for what it proves rather than what it is labeled.
Speakers


AJ Yawn
Author, GRC Engineering Lead
Rippling
Ryan Patrick
EVP, TPRM Customer Solutions
HITRUST