Regarding the internal audit - I did not create it because it is kind of pointless when we have just one framework, and the tests and documents are already in place, so I can just see the status, and remediate the issues on an ongoing basis, rather than do it once within the scope of internal audit. I understand that when internal audit is a compliance requirement (e.g. for SOX or ISO), it can be useful to have a snapshot and documented record that internal audit was conducted, but for SOC 2, we use ongoing compliance monitoring control instead of a point-in-time audit. What I would find useful is that if we could create an internal audit project that is not tied to any exact frameworks, and can run it on an ad-hoc basis when we want to audit some process/operation/product, if that makes sense