Skip to content
Last updated: Sep 25, 2026

Assessment & Evidence Cadence ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. The operating schedule for the security programme — what assessments and control activities run, how often, who owns them, and where their output lands.

It turns the control set from a static list into an operating system: this is what makes a SOC 2 Type II observation window produce evidence continuously rather than in a pre-audit scramble. ⚠️ Since 2026-09-15 the continuous half rests on scheduled activities rather than per-PR gates — see the Control Register.

How to read ​

Two tiers, each activity naming its owner and its evidence destination:

  • Automated — runs without human initiation. ⚠️ No activity in this tier currently gates a merge; the guards that did were withdrawn on 2026-09-15 (see Control Register).
  • Periodic — scheduled; driven by calendar reminders until a GRC tool automates collection.

Automated (machine-run — none currently blocking) ​

ActivityLensEvidence →Status
Dependency scan (bun audit)SCADependency Health mail✅ live — weekly, non-blocking (listed under Periodic)
Secret scanning (gitleaks)SecretFindings · Evidence🎯 in-CI
Static analysis (CodeQL / Semgrep)SASTFindings · Evidence🎯 not yet run
IaC scan (tfsec / checkov)IaCFindings · Evidence🎯 in-CI
Container image scan (Trivy)ImageFindings · Evidence🎯 in-CI
Lockfile guardIntegrity—⛔ withdrawn 2026-09-15 — see Control Register
Cloud posture (Prowler / Security Hub)CSPMFindings · Evidence🎯 at AWS go-live

Periodic (scheduled) ​

ActivityFrequencyOwnerEvidence →
Dependency scan (bun audit)Weekly (Sun)SekharDependency Health mail · Control Register
Posture re-verificationQuarterly + ad hocSekharPosture · Audit Log
Risk register reviewQuarterlySekharRisk Register
Threat-model reviewQuarterly + per significant changeSekhar / EngEvidence · Risk Register
Access review (prod + source control)QuarterlySekharEvidence (export)
DAST scanQuarterlySekharAudit Log · Findings
Backup / restore drillQuarterlySekharEvidence · Staging DB Restore Console
Vendor / subprocessor reviewAnnual + on onboardingPayeliSubprocessors
Penetration testAnnual + major changeSekhar (3rd party)Audit Log
IR tabletop exerciseAnnualSekharEvidence
Security-awareness trainingOnboarding + annualPayeliEvidence (completion records)
Policy reviewAnnualPolicy ownersPolicy revision history
Management reviewQuarterly / annualCEO / COOEvidence (minutes)
DPIA (on new/changed data flows)Per changePayeliDPIA

Where output is kept & shown ​

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial cadence — automated and periodic activities with owners and evidence destinations.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.