← All services

Service 03

Compliance and Risk

Controls that get you through procurement, security reviews, and formal audits.

Two colleagues reviewing a compliance file and control evidence at a desk

Overview

Enterprise clients do not buy from vendors they cannot audit. We design and implement the controls that get you through procurement, security reviews, and formal audits, and we prepare you to pass them the first time.

In scope

  • SOC 2 readiness: control design, gap assessments, and audit preparation.
  • ISO 27001 readiness and information security management.
  • Privacy compliance programs for PIPEDA and Alberta's PIPA.
  • Vendor risk and security questionnaire response programs.
  • Policy libraries, evidence collection, and continuous compliance monitoring.

Our point of view

Somewhere right now, your largest prospect's security team is writing the questionnaire that decides whether you can be their vendor. Compliance is treated as a cost until the deal that requires it shows up, and by then the timeline is someone else's. We prepare mid-market companies to clear procurement, security reviews, and formal audits before the deal depends on it. Readiness is a revenue position.

Who this is for

You will recognize yourself in at least one of these:

01

A big contract just asked for SOC 2, and you have eleven months and no controls.

02

Security questionnaires keep arriving and each one eats a week of founder time.

03

You handle client data and know, privately, that your controls would not survive a serious look.

04

Enterprise deals keep stalling in procurement and nobody can tell you exactly why.

What we deliver

The Gap Assessment

Your current state mapped against SOC 2 Trust Services Criteria or ISO 27001, with a sized remediation plan.

The Control Matrix

Every control designed, assigned to an owner, and wired into how work actually happens.

The Policy Library

Security, privacy, access, vendor, and incident policies your team will actually follow.

The Evidence Engine

Automated evidence collection so audit season is an export.

The Questionnaire Playbook

A maintained answer bank that turns week-long security questionnaires into a half-day task.

The first 30 days

Week 1

Scoping: which framework, which systems, which client obligations drive the timeline.

Week 2

Gap assessment across people, process, and technology controls.

Week 3

Remediation plan sequenced by deal impact: what unblocks revenue first goes first.

Week 4

Control build begins. Policy library drafted, owners assigned, evidence collection switched on.

What we measure

Every initiative carries a metric agreed before we build:

Controls implemented vs framework requirement.
Evidence coverage rate.
Questionnaire turnaround time.
Findings per external review.
Time to audit-ready.

An illustrative system

The readiness engine

The readiness engine

Illustrative workflow
GAP FOUNDCLEANFramework requirementsSOC 2 / ISO 27001Gap assessmentPeople, process, techControl designFit to real workOwner assignmentNamed accountabilityPolicy rolloutTraining + attestationAutomated evidence collectionContinuous captureInternal reviewDecision branchExternal auditIndependent bodyContinuous monitoringDrift detection
Illustrative pattern.

Honest edges

Where this service stops:

  • Only a licensed CPA firm can issue a SOC 2 report, and only an accredited body can certify ISO 27001. We design, implement, and prepare. The audit itself stays independent, which is exactly how it should be.
  • We will not paper over gaps to hit a date. A failed audit costs more than an honest timeline.
  • Compliance tooling is useful but it is not the work. We implement the controls; the platform just collects the evidence.

Questions we get

How long until we are audit-ready?

It depends on your starting point, which is what the gap assessment establishes in week two. What we can promise is a sequenced plan where the controls that unblock revenue come first.

SOC 2 Type I or Type II?

Usually Type I to satisfy the immediate deal, then straight into the observation window for Type II. We plan both from day one so nothing is built twice.

Can you also handle privacy law?

Yes. PIPEDA and Alberta's PIPA are built into every control set we design, because your compliance position and your privacy position are the same conversation in Canada.