SOC 2, ISO 27001, TPRM audits, and ongoing GRC guidance. From gap assessment to full program leadership, we help you stay compliant, not just for audit day, but every day.
Three areas of focus, built around what companies actually need to pass audits and stay ready between them.
Gap assessments, control implementation, and mock audits to prepare for SOC 2 Type II, ISO 27001, SOX, NIST CSF, and CIS Controls.
Build a robust third-party risk management program. Assess vendors, document risk, and maintain compliance confidence.
Strategic compliance guidance tailored to your business, whether you need a one-time audit or an ongoing advisor.
I started Compliant by Design to do independently what I'd already built successfully at other organizations: compliance programs that are strategic, embedded, and done right from the start. No constraints. No compromises.
I've spent six years in GRC, the last three building compliance programs from the ground up. The years before that were spent auditing and assessing other people's programs, which is where I learned what auditors actually look for and why so many programs fall apart between cycles.
The programs that hold up are proactive, intentional, and built in from day one. Not reactive. Not bolted on. Working independently gives me the freedom to do this work exactly how I believe it should be done, with clients who care about doing it right.
I built a compliance program from the ground up for a SaaS company operating across five regions that had failed multiple SOC 2 audits before I arrived. I led the implementation for both SOC 2 Type II and ISO 27001, and we passed both audits on the first try. The program kept running after the auditors left: evidence collected on a cadence, controls owned by the teams that operate them, and the next cycle starting from a program already in motion rather than a scramble.
The third-party risk program was a spreadsheet nobody followed. I replaced it with a real one: tiered assessments, documented risk decisions, and a review process that actually ran. More than 50 vendors came under it, and vendor risk became something leadership could see rather than guess at.
The SOX and ITGC assessment surfaced control gaps that had been flagged in prior years and never closed. I worked the remediation end to end, and findings that had followed the organization from audit to audit stopped recurring. The auditors signed off.
We scale with you. Start with a gap assessment and move to ongoing advisory or full program leadership as your needs grow.
A full audit against your target framework. We identify gaps, rate them by risk, and hand you a prioritized remediation roadmap. Mock audit available before the real one.
We implement the program: policies, procedures, risk registers, vendor management processes, and controls. Designed to hold up after the audit, not just through it.
A standing advisor between audit cycles. Regular program review, framework updates, risk flagged before it becomes a finding, and guidance on compliance decisions as they come up.
Fractional GRC leadership. We run the compliance function: manage the risk program, oversee vendor assessments, report to leadership, and keep controls current.
Tell us about your compliance needs. We'll get back to you within one business day to schedule a time that works.