Skip to main content
MTD for Income Tax is now live for landlords earning over £50,000.See what changes for you
Client login
FigsFlow

Engagement Letter Templates

SOC 2 Change Management & Software Development Engagement Letter Template

A professional engagement letter template designed to formalise the relationship between service providers and clients concerning SOC 2 compliance related to change management and software development processes.

  • Aligned with ECTEA 2023
  • Editable Word format
  • Built for ACSP compliance

Template Content Overview

Last updated: July 2025

SOC 2 Compliance: Change & Software Development Workflow

Purpose: To ensure robust SOC 2 compliance by providing a structured, repeatable workflow for managing changes, software development, testing, and implementation.

Initiating Change

☐ Clearly identify the need for the change (e.g., new feature, bug fix, security patch).

☐ Document a formal change request, detailing its purpose, scope, impact, and timeline.

☐ Assess potential risks and impacts of the change on system security, availability, integrity, confidentiality, and privacy.

Planning & Design

☐ Develop a detailed solution design, including architectural diagrams and functional specifications.

☐ Define a comprehensive testing strategy (unit, integration, user acceptance, security testing).

☐ Create a clear rollback strategy to revert the system if deployment issues arise.

☐ Obtain all necessary approvals from relevant stakeholders (management, security, compliance).

Development & Testing

☐ Develop or modify code according to the approved design specifications.

☐ Perform unit testing to verify individual components.

☐ Conduct integration testing to ensure different system components interact correctly.

☐ Execute security testing (e.g., vulnerability scans, penetration tests, code reviews).

☐ Facilitate User Acceptance Testing (UAT) with end-users.

☐ Document all test results, including identified defects and their resolutions.

☐ Address and thoroughly re-test any identified defects.

Deployment

☐ Finalize deployment scripts, configurations, and communication plans.

☐ Perform the deployment in a controlled environment.

☐ Verify successful deployment through post-deployment checks and monitoring.

☐ Communicate the deployment status to all relevant stakeholders.

Post-Implementation & Review

☐ Continuously monitor system performance and stability after deployment.

☐ Conduct a post-implementation review to evaluate the change’s success and control effectiveness.

☐ Update all relevant documentation (e.g., system manuals, user guides, training materials).

☐ Formally close the change request once all activities are complete.

Key Features

Everything This Template Covers

Designed to help firms meet SOC 2 requirements, this template focuses on change management and software development controls

  • Helps meet SOC 2 Change Management and software development requirements
  • Defines roles, responsibilities, and key processes
  • Fully customizable for your organization’s needs
  • Quick-to-implement for seamless SOC 2 compliance
FigsFlow - Single Template - Word File - 2

Created for Regulated Practice

Created for SOC 2 Change Management & Software Development Engagements

Work with confidence: our templates are shaped by best practices and trusted UK standards.

  • ACCA
  • CIOT
  • CIMA
  • ICAEW
  • ATT
  • AAT
  • & Many More

Quick Answers

FAQs to Keep You Moving

Got questions? We’ve got answers.
Explore our FAQs to learn how FigsFlow simplifies your workflows and boosts efficiency.

What does this template cover?

It helps businesses establish SOC 2-compliant change management and software development controls.

Who should use this template?

This template is ideal for firms seeking SOC 2 compliance in software development and change management processes.

How customisable is the template?

The template is fully customisable to meet your organisation’s specific change management and development needs.

How quickly can I implement this template?

It’s designed for easy integration into your existing workflow, helping you meet SOC 2 requirements quickly.

Simplify MTD Client Engagements

Streamline SOC 2 compliance with a smart, editable engagement letter template designed for auditors, IT teams, and risk managers.

Change Management & Software Development - Global

See it run on your own practice.

Screen-shared, using your services, your client mix and your deadlines. You will see where FigsFlow fits, and where it does not.

Design previews, not a shipped build — we will tell you on the call what is live today.

9:41
SignatureEngagement letter
Ready to sign
Engagement letter 20263 signatories · you are firstSign
Audit trailIP, device and timestamp recordedOn
Also waiting
Letter of representationDue 30/09Due
HomeDocsTasksChatProfile
9:41
Tasks3 open
Upload bank statementsVAT Q3 · due todayDue
Sign engagement letterOnboarding · due 05/09Sign
Approve VAT returnQ2 · due 07/09Review
Confirm payroll changesAugust · doneClosed
HomeDocsTasksChatProfile
9:41
Client portalRidgeline Foods Ltd
Upload Sign Pay Ask
Your services
Annual accountsYear end 31/03/2026Live
VAT returnsQuarterly · next 07/10Filed
PayrollMonthly · 14 employeesCurrent
Your team
Amara · ManagerUsually replies within a day
HomeDocsTasksChatProfile
9:41
DocumentsStored in your SharePoint
Recent
Bank statement — AugUploaded by camera · 2 MBSynced
Sales ledger Q3Shared by AmaraNew
Accounts 2025Signed 14/06/2025Final
Add a document
Scan with the cameraEdges cropped automatically
HomeDocsTasksChatProfile
9:41
MessagesAmara · Manager
This job
Re: VAT Q3Amara · 2 hours agoNew
Statement attachedYou · yesterday
Next deadline
VAT Q3 filing07/10/2026 · 15 daysSoon
HomeDocsTasksChatProfile