Compliance · Compliance specialist
A named specialist in your regulation — checking weekly, reviewing every 90 days
Assigned Compliance Specialist
Compliance is not a project that finishes. You get an assigned specialist who knows your framework and your environment: HIPAA, FINRA, PCI DSS, the IRS Red Flags Rule, Sarbanes-Oxley, 17 CFR books-and-records, FDA 21 CFR Part 11 or GSA and federal contracting. Automated checks run against your control set every single week. Every 90 days that same specialist works the controls by hand and signs a report you can put in front of an examiner.
Automated checks every week. A human review every 90 days. Nothing in your compliance posture is ever more than seven days stale.
What's included
- One named specialist, not a rotating ticket queue
- Automated control checks every week, with same-day tickets on drift
- Manual specialist review every 90 days, signed and dated
- Framework-specific control matrix maintained continuously
- Evidence library ready to export the day it's requested
- A technician in the room for the IT portion of the audit
- Remediation plans with owners and dates, tracked to close
What changes for your business
-
Weekly beats annual
A control that broke in February shows up the following Monday. Under a once-a-year model, it stays broken for eleven months and then becomes a finding.
-
The same person every quarter
Your specialist remembers the exception you documented last year and why the server in the back room is scoped the way it is. Institutional memory is most of this job.
-
A signed report, four times a year
Board packets, cyber insurance renewals, client security questionnaires and examiner requests all get answered from the same current document.
How we deliver it
What actually happens
No vague promises — these are the concrete pieces of work included in the engagement.
-
Framework scoping and gap analysis
We establish exactly which rules apply to you — and which don't — then score every control, with the effort and cost to close each gap.
-
Weekly automated check
Encryption, MFA, privileged accounts, patch level, firewall exposure, backup verification and logging are re-tested every week and diffed against last week.
-
90-day manual review
A hands-on walkthrough with the owner: access review, policy refresh, vendor and BAA re-verification, sample evidence pulls, and a signed quarterly report.
-
Audit and examination support
Evidence packages assembled, auditor liaison handled, findings remediated and anything left open documented with a dated plan.
Frameworks we work in
Eight regulations, one control set
Most businesses fall under more than one. We map a single set of controls to all of them, so you implement once and evidence everywhere.
-
HIPAA / HITECH
45 CFR §164.308–312
Who it hits: Medical, dental, behavioral health, billing companies and any business associate touching PHI.
What we do: Security Risk Analysis, encryption at rest and in transit, access reviews, audit logging, BAAs with every vendor, and workforce training with evidence retained.
-
FINRA
FINRA Rules 3110 / 4511
Who it hits: Broker-dealers, registered representatives and the firms that support them.
What we do: Supervisory system evidence, electronic communication capture and archiving, cybersecurity controls, and vendor due diligence packaged for a cycle exam.
-
PCI DSS 4.0
PCI DSS v4.0 Req. 1–12
Who it hits: Anyone who stores, processes or transmits cardholder data — retail, restaurants, e-commerce, clinics.
What we do: Network segmentation of the cardholder data environment, quarterly scanning, patch SLAs, MFA on admin access, and the SAQ completed with you rather than for you to guess at.
-
IRS Red Flags Rule & WISP
16 CFR §681 · IRS Pub. 4557
Who it hits: Tax preparers, CPAs, lenders, and creditors holding covered accounts.
What we do: A written Identity Theft Prevention Program and Written Information Security Plan, identity-theft red flag detection and response, staff training, and annual program review.
-
Sarbanes-Oxley (SOX)
SOX §302 / §404 — ITGC
Who it hits: Public companies and the private suppliers, subsidiaries and service organizations inside their reporting scope.
What we do: IT general controls: change management, segregation of duties, privileged access review, backup and recovery evidence, and a control matrix your auditor can walk straight through.
-
17 CFR — SEC & CFTC records
17 CFR §240.17a-3 / 17a-4
Who it hits: Investment advisers, broker-dealers and commodity firms under SEC or CFTC books-and-records obligations.
What we do: WORM-compliant retention, tamper-evident archiving of email and messaging, retrieval within the required window, and a designated third-party access letter on file.
-
FDA 21 CFR Part 11
21 CFR Part 11 · Subpart B
Who it hits: Life sciences, device manufacturers, labs and clinical operations keeping electronic records and signatures.
What we do: System validation documentation, unique user attribution, secure time-stamped audit trails, electronic signature controls and record-copy integrity checks.
-
GSA schedules & federal contracting
FAR 52.204-21 · NIST SP 800-171
Who it hits: GSA schedule holders, federal subcontractors and anyone handling federal contract information.
What we do: FAR basic safeguarding controls, NIST SP 800-171 gap work toward CMMC, SAM registration hygiene, incident reporting paths and a system security plan that stays current.
The cadence
Automated every week. Human every 90 days.
Annual compliance means eleven months of not knowing. This is the schedule that keeps nothing more than seven days stale.
-
Every week
Automated control checks
Every Monday the platform re-tests your control set and compares it to last week's state. Anything that drifted becomes a ticket the same day, not an audit finding nine months later.
- Encryption, MFA and endpoint policy state on every device
- Privileged and stale account detection
- Firewall rule, port and external exposure diff
- Patch level against the SLA your framework requires
- Backup success, retention and restore-point verification
- Evidence snapshot filed with a timestamp
-
Every 90 days
Manual specialist review
Automation catches drift; it does not catch bad judgment. Four times a year your assigned specialist works the control set by hand and signs the result.
- Line-by-line control walkthrough against the current rule text
- Access review with the owner — who left, who changed roles
- Policy and procedure refresh where the business changed
- Vendor, BAA and subprocessor list re-verified
- Sample evidence pulled the way an auditor would pull it
- Signed quarterly report with open items and owners
What it costs
The line items behind this service
Straight from the rate card we quote from. Add them to a full estimate in the calculator.
Build a full estimate| Service | List price |
|---|---|
| Assigned Compliance Specialist | $295/contract* /month |
| Regulatory Compliance Program | $15/user /month |
| LionGuard | $75/site /month |
| Narmada IT Compliance & Risk | $45/contract + $2.50/user /month |
| AI Governance & Compliance | $9/user* /month |
Estimated price. Confirmed in writing before anything is signed.
Informational use only — this is not a quote The numbers on this page are for informational use only and are not a factual quote. Pricing depends on what we find in your environment. For an actual quote, please contact us.
Frequently asked questions
Which regulations do your specialists cover?
HIPAA/HITECH, FINRA, PCI DSS 4.0, the IRS Red Flags Rule and WISP requirements, Sarbanes-Oxley IT general controls, 17 CFR §240.17a-3/17a-4 records retention, FDA 21 CFR Part 11, and GSA/FAR federal contracting including NIST SP 800-171. If you're facing something outside that list, we'll tell you honestly whether we're the right fit.
Are you the auditor?
No — and that's deliberate. We build, monitor and evidence the controls; an independent auditor or examiner assesses them. We sit on your side of that table.
What if we fall under more than one framework?
Common — a medical billing firm under HIPAA that also takes cards is under PCI too. We build one control set mapped to both, so you implement a control once and evidence it twice.
What does the weekly check actually produce?
A timestamped evidence snapshot filed to your library, plus tickets for anything that drifted. You can see both in your portal — we don't hold compliance evidence hostage.
Compliance
Related services
-
AI Governance & AI Compliance
Your staff already use AI. Governance decides whether that's an asset or a breach
Let's take IT off your plate.
A free onsite consultation: we assess your network and security, flag the risks we find, and show you exactly what it costs to fix them.