Compliance, Audit & Regulatory Control Effectiveness

Helix BioPharma | Frameworks: SOC 2 Type II, ISO 27001, HIPAA, FDA 21 CFR Part 11 | Domain: GRC & Compliance | Owner: J. Martinez, VP GRC
Control Operating Effectiveness
92.4%
-2.1% vs target 95%
Open Audit Findings
38
+12 from last month
Evidence Automation Coverage
67%
+8% QoQ
Framework Overlap Efficiency
0.71
71% control reuse
Control Test Failure Rate
7.6%
Change Mgmt spike
Finding Mean Age
52d
Target: <45 days
Customer Review Pass Rate
88%
Target: 95%
Regulatory Exam Readiness
82/100
Good standing
Policy Exception Rate
4.2%
All approved
Incident-Control Mapping
94%
+6% this quarter

Framework Control Crosswalk Matrix

Access
Crypto
Change
Risk
Incident
Backup
Network
Vendor
Monitor
Audit
Training
Physical
SOC 2 Type II
18
12
8
14
10
9
11
7
13
15
6
5
ISO 27001
16
11
7
13
12
8
10
9
14
12
7
8
HIPAA
14
13
5
10
11
9
12
6
10
14
8
7
FDA 21 CFR 11
9
8
4
7
6
10
5
4
8
11
5
6
Effective (≥90%) Good (80-89%) Fair (70-79%) Needs Attention (<70%) Critical (<60%)

12-Week Control Effectiveness Trend

Finding Aging Distribution (Pareto)

Failed Control Test Register

Control ID Framework Domain Test Date Failure Type Owner SLA Status
CM-042 SOC 2, ISO 27001 Change Mgmt 2024-01-08 Unapproved prod deploy D. Kim Overdue 12d In Progress
CM-038 FDA 21 CFR 11 Change Mgmt 2024-01-10 Missing validation docs R. Patel Overdue 8d In Progress
AC-019 HIPAA, SOC 2 Access Control 2024-01-12 Stale privileged access M. Nguyen On Track Remediation Planned
VC-007 ISO 27001 Vendor Mgmt 2024-01-14 Missing SLA review L. Chen On Track In Progress
IR-015 SOC 2 Incident Response 2024-01-16 Runbook out of date A. Rodriguez On Track Remediation Planned
BK-011 ISO 27001, HIPAA Backup 2024-01-18 Restore test failed J. Martinez Due 3d In Progress
MN-022 SOC 2 Monitoring 2024-01-19 Alert threshold breach K. Singh On Track Closed
TR-004 HIPAA Training 2024-01-20 87% completion only P. Garcia On Track In Progress

Evidence Automation by Domain

Customer Security Review Outcomes

Regulatory Exam Readiness

82 / 100
Good Standing

Policy Exception Rate

Total Exceptions 24
Approved 24
Pending Review 0
Unapproved Active 0
All active exceptions properly approved

Incident-Control Mapping

Total Incidents (90d) 34
Mapped to Controls 32
Unmapped 2
Coverage
94%
2 incidents pending RCA → control link

Critical & High-Severity Findings

AUD-2024-003 Critical
Change management validation gaps in production deployment process (FDA 21 CFR 11)
Age: 68 days Owner: D. Kim
AUD-2024-007 Critical
Privileged access review frequency non-compliant with SOC 2 requirements
Age: 62 days Owner: M. Nguyen
AUD-2024-011 High
Backup restore testing cadence does not meet ISO 27001 control objectives
Age: 48 days Owner: J. Martinez
AUD-2024-014 High
Vendor security assessment documentation incomplete for Tier-1 suppliers
Age: 41 days Owner: L. Chen

Finding Remediation Burndown

Upcoming Assessor Windows & Evidence Staleness Alerts

UPCOMING EXTERNAL ASSESSMENTS

SOC 2 Type II Annual
Assessor: Deloitte
Feb 12-16
21 days
ISO 27001 Surveillance
Assessor: BSI Group
Mar 4-5
42 days
HIPAA Security Rule Review
Assessor: Internal Audit
Mar 18-22
56 days

EVIDENCE STALENESS ALERTS

Access Review Evidence
Stale 47d
Last upload: Dec 5, 2023 | Owner: M. Nguyen
Penetration Test Report
Stale 31d
Last upload: Dec 21, 2023 | Owner: K. Singh
Vendor SLA Documentation
Stale 28d
Last upload: Dec 24, 2023 | Owner: L. Chen
Training Completion Records
Fresh 8d
Last upload: Jan 14, 2024 | Owner: P. Garcia