Skip to content

Video training

Short lessons that walk through a real SOC 2 audit in GRCFlow. Each one completes an actual task against a live system — nothing is animated, mocked, or sped up, and the data on screen is real assessment data.

Every video carries an on-screen caption explaining what is being done and why, and highlights each control as it is clicked so the steps are easy to follow.

New to GRCFlow?

Watch the lessons in order — they follow one audit from creation to report. If you would rather see the whole thing in one sitting, start with the masterclass at the bottom.

1. Create a SOC 2 assessment

Name the assessment, pick the framework — which pulls all 61 Trust Services controls into scope automatically — choose Type 1 or Type 2, and set the examination period.

Type 1 tests whether controls are designed correctly on a single date. Type 2 tests whether they actually operated across a period, which is what customers usually ask for. Evidence only counts if it falls inside the examination window.

2. Evaluate a control and pass it

Work a control end to end and record a PASS. GRCFlow shows the objective, the test procedures, and the evidence an auditor expects, so you are not guessing at the method.

The step people skip is writing down why it passed. A verdict with no rationale is worthless six months later when someone asks how you reached it.

3. Fail a control and raise a finding

Not every control passes. Record an honest FAIL, write the rationale, and watch it become a tracked finding with severity and status on the Findings register.

4. Ask the Copilot why a control failed

The Audit Copilot is docked inside the assessment, so it already knows which assessment and control you are looking at. Ask in plain English why a control failed and what evidence would close it.

Answers are labelled: Grounded in your data when the reply used your real control text and findings, and honestly marked when it did not. It runs against a self-hosted model, so nothing leaves your infrastructure.

5. Request evidence from the person who owns it

Most audit time goes on asking people for documents. Turn that into a tracked evidence request: tie it to the control it satisfies, name an owner, set a due date, and spell out what "good" looks like. Acceptance criteria are the difference between one round trip and four.

6. Turn failures into a remediation plan (POA&M)

A Plan of Action & Milestones is the auditable record of what you are fixing, who owns it, and by when. Generate it straight from the assessment so every failed control becomes an item and nothing quietly falls off the list.

7. Generate the audit report

Everything recorded during the audit rolls up into a report. Pick the assessment, choose the audience — Executive Summary for a board, Detailed Findings for your auditor, Gap Analysis while you are still closing holes — and the format. The report is produced from recorded evidence and verdicts; nothing is invented for it.

Masterclass: a full SOC 2 audit

All seven steps in one continuous take — create the assessment, test controls, handle a failure, ask the Copilot what would close it, chase the evidence, plan the fix, publish the report.

Chapter
00:01 Introduction
00:06 Create a SOC 2 assessment and scope its controls
00:56 Evaluate a control and pass it on the evidence
02:02 Evaluate a control, fail it, and create a finding
04:02 Ask the Copilot why a control failed
05:26 Request evidence from the person who owns it
06:43 Turn failures into a tracked remediation plan (POA&M)
07:36 Generate the audit report
08:26 Wrap-up