Compliance
HIPAA, FINRA, PCI, SOX, 17 CFR, FDA and GSA — checked every week, reviewed every 90 days
An assigned specialist, automated weekly control checks and a signed manual review every 90 days.
Compliance fails when it's a once-a-year scramble to produce evidence nobody was collecting. We assign you a specialist in your framework — HIPAA, FINRA, PCI DSS, the IRS Red Flags Rule, Sarbanes-Oxley, 17 CFR books-and-records, FDA 21 CFR Part 11, GSA and federal contracting, or AI governance. Automated checks run against your controls every week. Every 90 days that specialist works them by hand and signs the report. When the audit arrives, a technician sits with you and answers the IT questions directly.
Compliance is our comfort zone. We document continuously and sit with you through the audit — including the questions you'd rather not answer alone.
What's included
- An assigned specialist in your specific regulation
- Automated control checks every week
- Manual specialist review every 90 days, signed and dated
- AI governance: policy, inventory and technical guardrails
- Gap assessment against your specific framework
- Automated documentation and evidence collection
- Written policies your staff can actually follow
- Security awareness training and phishing simulation
- A technician present for the IT portion of the audit
What changes for your business
-
Audit-ready year round
Evidence accumulates as we work, so an audit request becomes an export rather than a three-week fire drill.
-
You're not alone in the meeting
Our technician answers the technical questions, in the auditor's language, with the documentation open.
-
Drift gets caught in a week
A firewall rule loosened for a project, an old admin account, encryption switched off — the weekly automated check flags it within seven days, not eleven months later at audit.
How we deliver it
What actually happens
No vague promises — these are the concrete pieces of work included in the engagement.
-
Gap analysis
Control-by-control status against your framework, with the effort and cost to close each item.
-
Policy and control set
Access control, backup, incident response, acceptable use and vendor management, written for your actual operation.
-
Audit support
Evidence packages, auditor liaison, remediation of findings and a documented plan for anything left open.
Frameworks we work in
Eight regulations, one control set
Most businesses fall under more than one. We map a single set of controls to all of them, so you implement once and evidence everywhere.
-
HIPAA / HITECH
45 CFR §164.308–312
Who it hits: Medical, dental, behavioral health, billing companies and any business associate touching PHI.
What we do: Security Risk Analysis, encryption at rest and in transit, access reviews, audit logging, BAAs with every vendor, and workforce training with evidence retained.
-
FINRA
FINRA Rules 3110 / 4511
Who it hits: Broker-dealers, registered representatives and the firms that support them.
What we do: Supervisory system evidence, electronic communication capture and archiving, cybersecurity controls, and vendor due diligence packaged for a cycle exam.
-
PCI DSS 4.0
PCI DSS v4.0 Req. 1–12
Who it hits: Anyone who stores, processes or transmits cardholder data — retail, restaurants, e-commerce, clinics.
What we do: Network segmentation of the cardholder data environment, quarterly scanning, patch SLAs, MFA on admin access, and the SAQ completed with you rather than for you to guess at.
-
IRS Red Flags Rule & WISP
16 CFR §681 · IRS Pub. 4557
Who it hits: Tax preparers, CPAs, lenders, and creditors holding covered accounts.
What we do: A written Identity Theft Prevention Program and Written Information Security Plan, identity-theft red flag detection and response, staff training, and annual program review.
-
Sarbanes-Oxley (SOX)
SOX §302 / §404 — ITGC
Who it hits: Public companies and the private suppliers, subsidiaries and service organizations inside their reporting scope.
What we do: IT general controls: change management, segregation of duties, privileged access review, backup and recovery evidence, and a control matrix your auditor can walk straight through.
-
17 CFR — SEC & CFTC records
17 CFR §240.17a-3 / 17a-4
Who it hits: Investment advisers, broker-dealers and commodity firms under SEC or CFTC books-and-records obligations.
What we do: WORM-compliant retention, tamper-evident archiving of email and messaging, retrieval within the required window, and a designated third-party access letter on file.
-
FDA 21 CFR Part 11
21 CFR Part 11 · Subpart B
Who it hits: Life sciences, device manufacturers, labs and clinical operations keeping electronic records and signatures.
What we do: System validation documentation, unique user attribution, secure time-stamped audit trails, electronic signature controls and record-copy integrity checks.
-
GSA schedules & federal contracting
FAR 52.204-21 · NIST SP 800-171
Who it hits: GSA schedule holders, federal subcontractors and anyone handling federal contract information.
What we do: FAR basic safeguarding controls, NIST SP 800-171 gap work toward CMMC, SAM registration hygiene, incident reporting paths and a system security plan that stays current.
The cadence
Automated every week. Human every 90 days.
Annual compliance means eleven months of not knowing. This is the schedule that keeps nothing more than seven days stale.
-
Every week
Automated control checks
Every Monday the platform re-tests your control set and compares it to last week's state. Anything that drifted becomes a ticket the same day, not an audit finding nine months later.
- Encryption, MFA and endpoint policy state on every device
- Privileged and stale account detection
- Firewall rule, port and external exposure diff
- Patch level against the SLA your framework requires
- Backup success, retention and restore-point verification
- Evidence snapshot filed with a timestamp
-
Every 90 days
Manual specialist review
Automation catches drift; it does not catch bad judgment. Four times a year your assigned specialist works the control set by hand and signs the result.
- Line-by-line control walkthrough against the current rule text
- Access review with the owner — who left, who changed roles
- Policy and procedure refresh where the business changed
- Vendor, BAA and subprocessor list re-verified
- Sample evidence pulled the way an auditor would pull it
- Signed quarterly report with open items and owners
What it costs
The line items behind this service
Straight from the rate card we quote from. Add them to a full estimate in the calculator.
Build a full estimate| Service | List price |
|---|---|
| Assigned Compliance Specialist | $295/contract* /month |
| AI Governance & Compliance | $9/user* /month |
| Regulatory Compliance Program | $15/user /month |
| LionGuard | $75/site /month |
| Narmada IT Compliance & Risk | $45/contract + $2.50/user /month |
Estimated price. Confirmed in writing before anything is signed.
Informational use only — this is not a quote The numbers on this page are for informational use only and are not a factual quote. Pricing depends on what we find in your environment. For an actual quote, please contact us.
Frequently asked questions
Which frameworks do you support?
HIPAA/HITECH, FINRA, PCI DSS 4.0, the IRS Red Flags Rule and WISP, Sarbanes-Oxley IT general controls, 17 CFR §240.17a-3/17a-4 records retention, FDA 21 CFR Part 11, GSA/FAR federal contracting and NIST SP 800-171, plus CJIS and SOC 2 readiness — and AI governance across all of them. If you're facing something else, tell us the requirement and we'll tell you honestly whether we're the right fit.
Can you make us compliant?
We can make the IT side compliant and document it. Compliance also covers process and people — training, policy adherence, physical controls — and that part needs your participation. We'll be clear about the line.
Do you provide the backup evidence auditors want?
Yes — retention settings, encryption at source, in transit and at rest, four-location storage and the results of the annual recovery test.
How often is anything actually checked?
Automated checks run every week and produce a timestamped evidence snapshot plus tickets for anything that drifted. Your assigned specialist performs a manual, hands-on review every 90 days and signs a quarterly report. Nothing in your posture is ever more than seven days stale.
Compliance
Related services
-
AI Governance & AI Compliance
Your staff already use AI. Governance decides whether that's an asset or a breach
-
Assigned Compliance Specialist
A named specialist in your regulation — checking weekly, reviewing every 90 days
Let's take IT off your plate.
A free onsite consultation: we assess your network and security, flag the risks we find, and show you exactly what it costs to fix them.