I'd really like to have something to point to, when the issue of forcing-background-checks thing comes up again for our SOC2 certification.
In one case, I know a company is using reference checks to comply with the "background check" requirement.
In one case, I know a company is using reference checks to comply with the "background check" requirement.
(This is why there's a SOC3.)
Long story short: it's not complicated, and if you're currently doing a SOC2, like right now (or in the future) and you have reached the point where you're trying to get out of background checking everyone, shoot me a line and I'll tell you what we did and what we said (I may performatively NDA you in the process, because I like our auditors and don't want to irritate them).