Compliance as a Service · the person, not the queue

Your compliance manager: a named owner, not a support queue

Every Nank.ai engagement assigns one experienced compliance manager who owns the outcome. That person scopes the work, designs the controls, runs the internal audit and faces the auditor with you. Here is what they do, and what stays with your team.

1
Named owner accountable for the outcome
5
Lifecycle phases they run with you
12
Frameworks they can scope and map
Canada
Data held in your own country
The argument

Why a named owner is the whole product

Compliance software tells you what remains open. It cannot decide what a control should look like for a company of your size, in your architecture, with your customer base. It cannot chase your own people for evidence. Those two jobs need a person, and they are where most programs fail.
So the compliance manager is not an add-on to the compliance platform. The platform exists to make one expert able to run a program that used to need a full-time hire.
1

Hire a compliance lead

Full coverage and full cost, at a salary your deal flow may not justify yet. Recruiting takes months. When the person leaves, the program leaves with them.
2

Run a platform with your own team

Cheaper on paper. The judgment calls, the chasing and the auditor relationship all land on people whose day job is something else.
3

Compliance as a Service

One named expert owns the outcome and leads the work. The cost sits between the two, and the expertise arrives on day one rather than after a search.
Deliverables

What your compliance manager owns

These are deliverables, not activities. Each has a name your SOC2 or SOC 2 auditor will recognise. Each is something a certification body or CPA firm asks to see.

Scope and gap assessment

What the report or certificate covers, which systems and teams sit inside it, and the shortlist of what you do not already have.

Risk assessment

Risks identified, owners assigned and treatment decided against criteria you set, in the form ISO 27001 Clause 6.1.2 asks for.

Control design and mapping

Each control written once, with an owner, an evidence rule and a frequency, then mapped to every framework in scope.

Statement of Applicability

For ISO 27001, every Annex A control with a decision, a reason and a status. Auditors read it first, so we write it to be read.

Policies and procedures

Drafted from your actual context, not a template pack. Reviewed with the owner who has to live with the wording.

Internal audit and management review

The Clause 9.2 internal audit and the Clause 9.3 management review pack. A certification body wants to see both before Stage 2.

The lifecycle

How your compliance manager runs the lifecycle

Five phases, and a clear split at every one. The pattern is the same whether you are working toward SOC 2, ISO 27001 or ISO 42001.
1

Design

Your manager sets the scope, runs the risk assessment and designs the control set.

Your team answers questions about how the business works, and names an owner for each control.
2

Implement

Your manager assigns and tracks the rollout tasks, drafts the policies and supplies guidance, worked samples and templates.

Your team adjusts the processes it already runs, so the control matches reality rather than fighting it.
3

Operate

Your manager schedules the access reviews, approvals, scans and training, then follows up when a record is late.

Your team performs its own work as it always did, and the platform captures the evidence.
4

Verify

Your manager tests each control with documented sampling, routes findings to an owner and tracks retesting to closure.

Your team fixes what the testing found while there is still time.
5

Audit

Your manager prepares the evidence pack, runs the scoped audit workspace, answers the auditor’s requests and tracks every one to a close.

Your team turns up for the interviews the auditor asks for.

One programme, twelve frameworks

The same five phases carry every framework in scope, from one control library.
What stays with your team
Three things, and no honest provider can take them from you. Leadership still owns the risk decisions, because they are business decisions. Control owners still perform the controls, because a control someone else performs is not yours. And your team still supplies the evidence no integration can reach. That is a real share of any SOC 2 or ISO 27001 program. Your compliance manager keeps the list short and tells each owner what to produce and when.
Two questions worth asking

The internal audit question

ISO 27001 Clause 9.2.2 asks you to select auditors and run audits in a way that keeps the process objective and impartial. Handing the internal audit to an outside firm is common and acceptable. What certification bodies question is one individual designing a control and then auditing their own work.
Ask any provider how they separate the two roles. It is the fastest way to tell a compliance partner who has sat through certification audits from one who has read about them. The complete ISO 27001 guide in our library covers where the internal audit sits in the certification sequence.

Continuity, which nobody advertises

A single in-house compliance lead is a single point of failure. When that person leaves, the reasoning behind every control decision tends to leave too. The next audit becomes an archaeology project.
Your compliance manager works inside a platform that records every control, decision, policy version and evidence item. If your manager changes, the record does not. That is the unglamorous case for a service over a hire, and it matters most in year two.
The person

Who your compliance manager is

An experienced practitioner, not a coordinator with a checklist. The work calls for four things at once. Reading Annex A and ruling on what applies to your business. Writing a Statement of Applicability an auditor will accept. Running an internal audit that holds up. And holding a conversation with a CPA firm about sampling.
They also carry the questions your team cannot answer. What counts as evidence here. Whether this exception needs a compensating control. What the auditor will ask when they see this. Those answers are the difference between a program that finishes and one that renews its subscription.

Framework depth

SOC 2 Trust Services Criteria, ISO 27001 Annex A and ISO 42001, plus the privacy frameworks that sit alongside them.

Auditor fluency

Runs the relationship with your CPA firm or certification body, and translates their requests into work your team can action.

Canadian context

PIPEDA, PHIPA, Quebec Law 25, the PIPA statutes and the OSFI guidelines that reach vendors through the supply chain.

Canadian coverage

SOC 2 and ISO 27001 support across Toronto, Ontario and Canada

Nank.ai works from Toronto, so your compliance manager sits in your time zone and knows the Canadian buyer’s questions before they arrive.
That matters in practice. A Canadian CPA firm can issue your SOC 2 report and it carries the same weight with United States buyers. For ISO 27001, the Standards Council of Canada accredits the certification bodies here. Your manager will tell you to check that yours holds SCC accreditation, or sits under another IAF signatory, before you sign.
Canadian privacy law is also not one law. PIPEDA applies federally, PHIPA covers Ontario health data, and Quebec Law 25 and the PIPA statutes each apply on their own terms. Your manager maps the ones that reach your business rather than all of them. Our privacy and security services cover the rest.

Canadian data residency compliance

The part most vendors leave out
Neither SOC 2 nor ISO 27001 contains a data residency requirement. Nothing in the Trust Services Criteria asks where your data sits, and ISO 27001 sets no rule either. So the report or the certificate will not answer the question a Canadian health, finance or government buyer asks in the security review. Residency is a separate commitment. Nank.ai holds client data in the client’s own country, and your compliance manager will help you answer the question in writing.
Getting started

How it starts

1

A scoping call

Which framework, which buyer asked, what you already run and what the deadline is.
2

A gap assessment

Your manager reports what your existing controls already answer and what they do not.
3

A plan, a start date and a name

Owners, dates, evidence rules, and the person accountable for the result.
Questions

Frequently asked questions

They own your compliance program end to end. That means scope, risk assessment, control design and mapping, and policy drafting. It also means rollout tracking, evidence planning, control testing, the internal audit, the management review pack and the auditor relationship. They answer the framework questions your team cannot, which is the part a platform alone never covers.
You get one named person who owns your program and knows your business. They are not a rotating support queue, and you are not filing tickets. They work across a portfolio rather than sitting on your payroll, which is what makes the expertise affordable at your stage.
Less than running a platform yourself, and far less than a first program without help. Your team answers questions about how the business works and adjusts processes it already owns. It performs its own controls and supplies the evidence no integration can reach. Clients who reached audit-ready in about three months did so without hiring and without moving people off their day jobs.
An outside firm performing an internal audit is common and acceptable. Clause 9.2.2 asks for objectivity and impartiality in the audit process, and the test is independence from the work under audit. Ask us, and any provider, how the person who designed a control is kept separate from the person who audits it.
The record does not change with them. Every control, decision, policy version and evidence item lives in the platform rather than in one person’s head or inbox. That beats a single in-house hire, where a resignation tends to take the reasoning behind every control decision with it.
No. A licensed CPA firm issues a SOC 2 report and an accredited certification body issues an ISO 27001 certificate. Those roles stay independent of whoever built your controls. Your compliance manager gets you ready, runs the audit workspace and manages the relationship with the firm you appoint.

Meet the person who would run your program

Book a scoping call. You will see what your existing controls already cover, and meet the compliance manager who would own the work.
Scroll to Top