Skip to content
Iru Logo on White

How Iru completed four audits at once with zero findings using its own compliance product

iru office

The challenge

This year, Iru's GRC team became customer zero for Iru’s Compliance Automation solution. The team ran Iru's entire audit cycle, with four frameworks across every product (including adding one new product in scope for SOC 2), while using two different audit firms, on the same compliance product. This exercise not only was necessary to validate Iru’s compliance posture, but also to validate the product’s capabilities and ability to get a fast-moving organization audit ready.

Andres Cabrera is a senior member of the GRC team at Iru. His remit spans governance (including AI security), risk and vendor management, and compliance, from annual audits to the customer assurance work that lets security-conscious buyers trust Iru with their data. Andres is the owner of the audit cycle, end-to-end.

That cycle can be demanding. Iru is a platform of multiple products, and while many controls apply org-wide, auditors test product-facing areas like logical access and change management separately for each product in scope. Every new product can add its own evidence trail, collaborators, and workflows.

Last year's cycle was especially heavy. Andres inherited a previous compliance tool where about half the source integrations were not returning reliable results, so the team made the choice to move off that tool and run the audits by hand, with evidence spread across drive folders and spreadsheets. New products entered scope and each needed its own gap assessment and internal audit, creating a ton of manual work.

“Before Iru, it was hard. We had to get a temporary GRC contractor because the audit process was such a big lift. And not to mention, last year was when we rolled out all our new products. And on top of it all, the old compliance automation tool that we were using at that time was failing.”

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

This year, the team set up an Iru Compliance tenant in January and prepared for a September cycle covering four frameworks at once: recertifications for SOC 2 Type 2, ISO 27001, ISO 42001, and, for the first time, HIPAA.

The solution

Mapping once, satisfying four frameworks

Running four audits concurrently was a deliberate choice. SOC 2 and ISO 27001 share a large set of controls, as do ISO 27001 and ISO 42001, so testing them together made sense, especially before audit firms get busy in Q4. The hard part is proving that a single piece of evidence can satisfy different controls across multiple frameworks, without doing the same work two or three times.

That is where the Iru Compliance Automation solution carried the most weight. It surfaced overlapping evidence across SOC 2, ISO 27001, ISO 42001, and HIPAA automatically, so the team could see where evidence already gathered already covered another framework's requirement.

"For me personally, I love the evidence mapping. There's so much overlap between these frameworks, and automated evidence mapping just saves you so much time, even before the audit."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

The overlap showed up clearly in the HIPAA audit. Because Iru's SOC 2 evidence was already in place, and Iru does not process PHI, HIPAA required only a 15-item delta on top of what was already being tracked.

 

iru office 2

Scoping per product without multiplying the work

The Iru Compliance Automation solution breaks controls down into actions, assignable sub-tasks to different members of the business. Under a control like SOC 2 CC6, which covers logical access, there needed to be separate actions for each of Iru’s six products in scope, so it was always clear what needed to be gathered, and proven, for each one. Iru AI successfully generated controls and actions to reflect this nuance, making it easier for Andres to collaborate with different product divisions while sticking to the audit timelines.

Evidence built for auditors

For the technology systems that Iru has in its tech stack, Andres connected the platform to those technologies via the Sources module to automatically gather evidence based on the control set. This evidence pull was successful, and Iru mapped that pulled evidence to the right controls across multiple frameworks. Each piece of automatically-collected evidence is accompanied by two things: an AI-generated summary of what was collected and the raw JSON behind it.

"It's nice having the raw JSON as well as the summary it gives you, because it's a usable audit artifact. And the auditors even verified this."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

The raw data matters because auditors are liable to follow up and ask deep questions about any evidence gathered. When one asks how a piece of evidence was gathered, the team can show the underlying data instead of reconstructing it.

Both audit firms reviewed the gathered evidence, as well as the product as a whole, and verified its legitimacy for use in audits.

"Both audit firms looked at the product and verified its legitimacy. It's definitely audit-usable, in their eyes."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

Andres also credits Iru’s UX for keeping a four-framework cycle manageable. Controls, actions, and mapped evidence live in one clear view, so he could see what was done and what was left at a glance.

"I really like the UI and the way everything is set up. It makes a big audit cycle a lot easier to manage."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru
Iru Office - Desks

Controls that match the framework

To begin each framework, Andres used Iru Compliance's updated intake form, which captured company technologies and generated controls to fit the context of the business. Because there were already controls and evidence within the platform for the other three frameworks, Iru AI used those as context as well to generate accurate controls.

He was positive about the quality of those generated controls and the intake process.

“The controls that are generated are high-quality and are very aligned to the framework. I loved the new intake form flow, and seeing how our technologies linked to these controls."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

Results

Iru completed SOC 2 Type 2, ISO 27001, ISO 42001, and its first HIPAA audits, across all products, all in the same engagement window during September. Though we won’t receive the certificates until November, this experience was still very valuable to test the compliance product. Auditors reviewed the gathered information and returned very positive results across all four frameworks:

 

“This year, we had few follow-up requests from auditors, and fewer questions. And at the end of the engagement, the audit firms returned zero findings and zero recommendations.”

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

That's the real test of a compliance tool. It’s not just about collecting evidence and mapping it across frameworks; Iru provides the controls and evidence that audit firms need to see to confer a passing opinion.

ISO 42001, the standard for AI management systems, is a notable result on its own. Iru was among the first companies in the US to achieve this certification last year, giving customers assurance that Iru vets its AI vendors, runs AI risk assessments, and keeps strong data protection controls around AI-powered products, including Iru Compliance Automation itself. Re-certification for this framework continues to position Iru on the cutting edge of AI governance and trust with customers and partners.

For Iru's customers, and enterprise buyers, their expectation to see SOC 2 or ISO 27001 are often non-negotiable. Now, those businesses will be satisfied by these certifications that show that Iru has mature processes for protecting their data.

Andres estimates the team spent about 35% less time on the audit than the year before. Part of that came from experience: most products were already scoped and fewer gap assessments were needed. But a large part of those efficiency gains were due to the automatic evidence collection, and cross-framework mapping of evidence, that Iru Compliance Automation delivers.

Another benefit to the business: the team got through the audit cycle without having to hire the temporary contractor it needed the year before.

Looking ahead

Now that controls are built within Iru, and automatic evidence collection is up and running, Iru can look ahead to keeping the business audit-ready all year. Andres expects that to compound the efficiency gains and successes uncovered this year for the next round of annual audits.

"I'm very confident that next year, there's going to be another dramatic reduction of workload. Now that we already have everything in the product, we just need to make updates."

andres headshot
Andres Cabrera
Senior GRC Analyst, Iru

For SOC 2, ISO 27001, ISO 42001, and HIPAA, the next cycle will be about control updates rather than rebuilding. Upcoming tech stack changes, like a new HRIS, will flow through those updates, and Iru’s Adaptive Compliance capabilities will help Andres adjust his controls when these changes hit.

About Iru

Iru is an AI-powered IT and security platform that unifies identity, endpoint management, endpoint security, and compliance automation. Thousands of organizations use Iru to secure their devices and people, stay audit-ready, and give IT and security teams time back for the work that matters.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.