WEBINAR

The Assurance Gap: What 103 SOC 2 Reports Actually Showed Us

August 26, 2026 | 11:30 AM CT 

Third-party risk teams collect assurance artifacts at volume and record the result in a column: SOC 2, yes. New research examining 103 SOC 2 reports across 37 audit firms shows what that column can and cannot support. Every report carried a clean opinion. Forty percent contained exceptions the reader had to evaluate. None of them tested the vendor’s own service providers.

AJ Yawn and Ryan Patrick open the series by tracing how information security assurance evolved from a periodic compliance exercise into a core operating requirement, and why the artifacts we inherited from that evolution struggle under the weight now placed on them. This session establishes the vocabulary for the series: scope, threat coverage, quality, supply chain, and measurable outcomes. Attendees leave able to read their next vendor report for what it proves rather than what it is labeled.

 

Speakers

FY26 - Q3 - Headshot - AJ Yawn
FY25 - Q4 - Ryan Patrick - Executive Profile Headshot

AJ Yawn
Author, GRC Engineering Lead
Rippling

Ryan Patrick
EVP, TPRM Customer Solutions
HITRUST 

Webinar Registration

The Only Certification Proven to Work

With a 99.62% breach-free rate among HITRUST-certified environments, HITRUST stands alone in cybersecurity assurance. From third-party risk to internal controls, trust the solution that reduces risk — and proves it.

Engage with HITRUST

Chat Now

This is where you can start a live chat with a member of our team