Mon–Fri, 9:00 AM – 5:00 PM PST

Compliance · Compliance specialist

A named specialist in your regulation — checking weekly, reviewing every 90 days

Assigned Compliance Specialist

Compliance is not a project that finishes. You get an assigned specialist who knows your framework and your environment: HIPAA, FINRA, PCI DSS, the IRS Red Flags Rule, Sarbanes-Oxley, 17 CFR books-and-records, FDA 21 CFR Part 11 or GSA and federal contracting. Automated checks run against your control set every single week. Every 90 days that same specialist works the controls by hand and signs a report you can put in front of an examiner.

Automated checks every week. A human review every 90 days. Nothing in your compliance posture is ever more than seven days stale.

What's included

  • One named specialist, not a rotating ticket queue
  • Automated control checks every week, with same-day tickets on drift
  • Manual specialist review every 90 days, signed and dated
  • Framework-specific control matrix maintained continuously
  • Evidence library ready to export the day it's requested
  • A technician in the room for the IT portion of the audit
  • Remediation plans with owners and dates, tracked to close

What changes for your business

  • Weekly beats annual

    A control that broke in February shows up the following Monday. Under a once-a-year model, it stays broken for eleven months and then becomes a finding.

  • The same person every quarter

    Your specialist remembers the exception you documented last year and why the server in the back room is scoped the way it is. Institutional memory is most of this job.

  • A signed report, four times a year

    Board packets, cyber insurance renewals, client security questionnaires and examiner requests all get answered from the same current document.

How we deliver it

What actually happens

No vague promises — these are the concrete pieces of work included in the engagement.

  1. Framework scoping and gap analysis

    We establish exactly which rules apply to you — and which don't — then score every control, with the effort and cost to close each gap.

  2. Weekly automated check

    Encryption, MFA, privileged accounts, patch level, firewall exposure, backup verification and logging are re-tested every week and diffed against last week.

  3. 90-day manual review

    A hands-on walkthrough with the owner: access review, policy refresh, vendor and BAA re-verification, sample evidence pulls, and a signed quarterly report.

  4. Audit and examination support

    Evidence packages assembled, auditor liaison handled, findings remediated and anything left open documented with a dated plan.

Frameworks we work in

Eight regulations, one control set

Most businesses fall under more than one. We map a single set of controls to all of them, so you implement once and evidence everywhere.

  • HIPAA / HITECH

    45 CFR §164.308–312

    Who it hits: Medical, dental, behavioral health, billing companies and any business associate touching PHI.

    What we do: Security Risk Analysis, encryption at rest and in transit, access reviews, audit logging, BAAs with every vendor, and workforce training with evidence retained.

  • FINRA

    FINRA Rules 3110 / 4511

    Who it hits: Broker-dealers, registered representatives and the firms that support them.

    What we do: Supervisory system evidence, electronic communication capture and archiving, cybersecurity controls, and vendor due diligence packaged for a cycle exam.

  • PCI DSS 4.0

    PCI DSS v4.0 Req. 1–12

    Who it hits: Anyone who stores, processes or transmits cardholder data — retail, restaurants, e-commerce, clinics.

    What we do: Network segmentation of the cardholder data environment, quarterly scanning, patch SLAs, MFA on admin access, and the SAQ completed with you rather than for you to guess at.

  • IRS Red Flags Rule & WISP

    16 CFR §681 · IRS Pub. 4557

    Who it hits: Tax preparers, CPAs, lenders, and creditors holding covered accounts.

    What we do: A written Identity Theft Prevention Program and Written Information Security Plan, identity-theft red flag detection and response, staff training, and annual program review.

  • Sarbanes-Oxley (SOX)

    SOX §302 / §404 — ITGC

    Who it hits: Public companies and the private suppliers, subsidiaries and service organizations inside their reporting scope.

    What we do: IT general controls: change management, segregation of duties, privileged access review, backup and recovery evidence, and a control matrix your auditor can walk straight through.

  • 17 CFR — SEC & CFTC records

    17 CFR §240.17a-3 / 17a-4

    Who it hits: Investment advisers, broker-dealers and commodity firms under SEC or CFTC books-and-records obligations.

    What we do: WORM-compliant retention, tamper-evident archiving of email and messaging, retrieval within the required window, and a designated third-party access letter on file.

  • FDA 21 CFR Part 11

    21 CFR Part 11 · Subpart B

    Who it hits: Life sciences, device manufacturers, labs and clinical operations keeping electronic records and signatures.

    What we do: System validation documentation, unique user attribution, secure time-stamped audit trails, electronic signature controls and record-copy integrity checks.

  • GSA schedules & federal contracting

    FAR 52.204-21 · NIST SP 800-171

    Who it hits: GSA schedule holders, federal subcontractors and anyone handling federal contract information.

    What we do: FAR basic safeguarding controls, NIST SP 800-171 gap work toward CMMC, SAM registration hygiene, incident reporting paths and a system security plan that stays current.

The cadence

Automated every week. Human every 90 days.

Annual compliance means eleven months of not knowing. This is the schedule that keeps nothing more than seven days stale.

  • Every week

    Automated control checks

    Every Monday the platform re-tests your control set and compares it to last week's state. Anything that drifted becomes a ticket the same day, not an audit finding nine months later.

    • Encryption, MFA and endpoint policy state on every device
    • Privileged and stale account detection
    • Firewall rule, port and external exposure diff
    • Patch level against the SLA your framework requires
    • Backup success, retention and restore-point verification
    • Evidence snapshot filed with a timestamp
  • Every 90 days

    Manual specialist review

    Automation catches drift; it does not catch bad judgment. Four times a year your assigned specialist works the control set by hand and signs the result.

    • Line-by-line control walkthrough against the current rule text
    • Access review with the owner — who left, who changed roles
    • Policy and procedure refresh where the business changed
    • Vendor, BAA and subprocessor list re-verified
    • Sample evidence pulled the way an auditor would pull it
    • Signed quarterly report with open items and owners

What it costs

The line items behind this service

Straight from the rate card we quote from. Add them to a full estimate in the calculator.

Build a full estimate
Compliance
Service List price
Assigned Compliance Specialist $295/contract* /month
Regulatory Compliance Program $15/user /month
LionGuard $75/site /month
Narmada IT Compliance & Risk $45/contract + $2.50/user /month
AI Governance & Compliance $9/user* /month

Estimated price. Confirmed in writing before anything is signed.

Informational use only — this is not a quote The numbers on this page are for informational use only and are not a factual quote. Pricing depends on what we find in your environment. For an actual quote, please contact us.

Frequently asked questions

Which regulations do your specialists cover?

HIPAA/HITECH, FINRA, PCI DSS 4.0, the IRS Red Flags Rule and WISP requirements, Sarbanes-Oxley IT general controls, 17 CFR §240.17a-3/17a-4 records retention, FDA 21 CFR Part 11, and GSA/FAR federal contracting including NIST SP 800-171. If you're facing something outside that list, we'll tell you honestly whether we're the right fit.

Are you the auditor?

No — and that's deliberate. We build, monitor and evidence the controls; an independent auditor or examiner assesses them. We sit on your side of that table.

What if we fall under more than one framework?

Common — a medical billing firm under HIPAA that also takes cards is under PCI too. We build one control set mapped to both, so you implement a control once and evidence it twice.

What does the weekly check actually produce?

A timestamped evidence snapshot filed to your library, plus tickets for anything that drifted. You can see both in your portal — we don't hold compliance evidence hostage.

Compliance

Back to overview

Let's take IT off your plate.

A free onsite consultation: we assess your network and security, flag the risks we find, and show you exactly what it costs to fix them.