Drat.
One of our clients at $Day_Job is a laboratory - subject to arbitrary (from their viewpoint) rules for certifications, etc. If the certifying agency says "round this value to 3 decimal places" - it doesn't much matter if $Client hates that idea, or if it is (science-wise) wrong. One can argue with them...if done wisely, that occasionally works.
I'd be tempted to look into the SOC 2 stuff. Especially real-world accounts of how the AICPA interprets and applies the rules. There can be wide gulfs between what the written rules (plus "reasonable professional" logic) say, and the standards which the auditors (with their own mindsets and habits) actually apply.
Hmm...does the US startup you're working for have someone really familiar with SOC 2 certification working for them? Or just some energetic manager-type, who's zealously trying to apply his own interpretation of the written rules?
Best wishes.