What Vanta Doesn't Do for Your Audit

What Vanta Doesn't Do for Your Audit
Vanta is excellent at what it does. It connects to your infrastructure, monitors controls continuously, collects evidence automatically, and surfaces gaps before your auditor finds them. That's real value. For most SaaS companies, it compresses months of manual work into weeks.
But a green dashboard is not a passed audit. And the gap between those two things is where unprepared teams get stuck.
Here's what Vanta handles — and what still requires a human.
Does Vanta perform the audit?
No. Vanta is a compliance automation platform. It is not a CPA firm. It cannot examine your controls, form an opinion, or sign a SOC 2 report. Only a licensed CPA firm can do that. Vanta helps you prepare for the examination. The examination itself is a separate engagement with a separate firm.
- Vanta maintains a network of auditor partners, and the platform is built to share evidence directly with your auditor during fieldwork. That makes the process faster. But the auditor works for you, not for Vanta. You select them, you negotiate the engagement, and you pay them separately.
Does Vanta write my policies?
Partially. Vanta ships auditor-reviewed policy templates that map to SOC 2, ISO 27001, HIPAA, and other frameworks. They're solid starting points. But templates describe a generic company. Your policies need to describe your company: your access control model, your incident response procedures, your data classification standards, your specific environment.
Customizing policies requires someone who understands how your organization actually operates. What systems store customer data. Who has access. How changes get deployed. How incidents get escalated. Vanta gives you the structure. You fill in the substance.
Does Vanta handle my risk assessment?
Vanta includes a risk register where you can document risks, link them to controls, and assign ownership. But the risk assessment itself (identifying threats specific to your business, evaluating their likelihood and impact, selecting treatment plans) is judgment work. Vanta's register covers the checklist. It does not model risk dynamically or embed risk scoring into operational workflows.
Your auditor will ask how you identified risks, why you prioritized certain threats, and how your controls map to those decisions. The answer needs to come from someone who knows your business, your architecture, and your threat landscape. A populated risk register satisfies the documentation requirement. The reasoning behind it satisfies the auditor.
What about the controls Vanta can't monitor?
Vanta automates evidence collection for cloud infrastructure, identity providers, code repositories, HR systems, and dozens of other integrated tools. That covers a significant portion of technical controls.
It does not cover everything.
- Physical security. Clean desk policies, visitor logs, badge access records, secure disposal of hardware — none of this lives in a SaaS platform. Your auditor will ask for evidence of physical controls, especially if you have an office or a data center presence.
- People controls. Vanta tracks whether security training was completed. It cannot verify whether the training was substantive, whether it matched the employee's actual role, or whether people who handle sensitive data understand the procedures. Training records need to show who was in scope, who completed it, when, and who is overdue.
- Operational controls. Business continuity tests, tabletop exercises, disaster recovery drills — these are manual activities that produce manual evidence. Vanta can remind you to perform them. It cannot perform them for you.
- Vendor risk management. Vanta offers vendor risk capabilities, but the underlying work — evaluating subprocessor security, reviewing SOC 2 reports from critical vendors, maintaining a current vendor inventory — requires human judgment. Automated tracking helps. It doesn't replace the assessment.
Does a passing dashboard mean I'll pass the audit?
No. A green Vanta dashboard means your monitored controls are configured correctly at this moment. An auditor evaluates design, implementation, and operating effectiveness across a sustained period. They also ask questions.
The auditor will sit down with your team and ask why specific controls exist, how they map to identified risks, and what happens when something goes wrong. They'll want to understand your organization's context — not just its configuration. If your team can't explain the rationale behind a control, the fact that it's currently passing in Vanta doesn't resolve the finding.
Vanta x Cloudsapio can help you be
SOC 2 ready in 8-16 weeks.
Does Vanta handle remediation?
Vanta identifies gaps and creates tasks with fix instructions. It assigns those tasks to the right people and tracks completion. That's valuable project management.
But the actual work- reconfiguring an IAM policy, deploying endpoint protection, restructuring your offboarding process, building an incident response runbook- falls on your engineering and operations teams. Vanta sequences the work. Your team executes it.
For companies without dedicated security staff, this is where the timeline stretches. The platform can tell you exactly what's broken. Fixing it still requires someone with the skills and the bandwidth to do the work.
What about edge cases and ambiguous controls?
Every environment has controls that don't map cleanly to a framework checkbox. A custom authentication system. A hybrid cloud deployment with on-prem components. A legacy application that doesn't integrate with your identity provider.
Vanta works best with standard SaaS stacks — AWS, GCP, Azure, Okta, GitHub, Jira. When your environment deviates from that pattern, you hit the edges of automation. You'll upload evidence manually, build custom tests, or work with a consultant to translate your architecture into auditor-friendly documentation.
The platform expects a level of standardization. If your infrastructure doesn't match that expectation, the gap between the dashboard and audit readiness widens.
So what does all this mean?
Vanta handles evidence collection, continuous monitoring, policy templates, task tracking, and auditor collaboration. That eliminates the most time-consuming, repetitive parts of audit preparation. Teams using automation report significantly shorter prep timelines — often cutting audit readiness time in half.
What Vanta doesn't handle: the audit itself, risk assessment judgment, policy customization, physical security evidence, operational control execution, remediation work, and the ability to explain your security program to an auditor in a live conversation.
The bottom line: Vanta is the system of record. It is not the security team. The companies that pass clean audits are the ones that pair automation with someone — internal or external — who owns the program. The platform monitors your controls. A person defends them.
Ready to move faster?
Too much to do,
too important to ignore.
Start with a 30-minute discovery call. If we're not the right fit, we'll tell you and point you in the right direction. If we are, we'll leave the call with a clear plan to get you up and running.

