Your compliance manager: a named owner, not a support queue
Every Nank.ai engagement assigns one experienced compliance manager who owns the outcome. That person scopes the work, designs the controls, runs the internal audit and faces the auditor with you. Here is what they do, and what stays with your team.
- Scope
- Risk assessment
- Control design
- Statement of Applicability
- Policies
- Evidence plan
- Internal audit
- Auditor liaison
Why a named owner is the whole product
Hire a compliance lead
Run a platform with your own team
Compliance as a Service
What your compliance manager owns
Scope and gap assessment
What the report or certificate covers, which systems and teams sit inside it, and the shortlist of what you do not already have.
Risk assessment
Risks identified, owners assigned and treatment decided against criteria you set, in the form ISO 27001 Clause 6.1.2 asks for.
Control design and mapping
Each control written once, with an owner, an evidence rule and a frequency, then mapped to every framework in scope.
Statement of Applicability
For ISO 27001, every Annex A control with a decision, a reason and a status. Auditors read it first, so we write it to be read.
Policies and procedures
Drafted from your actual context, not a template pack. Reviewed with the owner who has to live with the wording.
Internal audit and management review
The Clause 9.2 internal audit and the Clause 9.3 management review pack. A certification body wants to see both before Stage 2.
How your compliance manager runs the lifecycle
Design
Your team answers questions about how the business works, and names an owner for each control.
Implement
Your team adjusts the processes it already runs, so the control matches reality rather than fighting it.
Operate
Your team performs its own work as it always did, and the platform captures the evidence.
Verify
Your team fixes what the testing found while there is still time.
Audit
Your team turns up for the interviews the auditor asks for.
One programme, twelve frameworks
The internal audit question
Continuity, which nobody advertises
Who your compliance manager is
Framework depth
SOC 2 Trust Services Criteria, ISO 27001 Annex A and ISO 42001, plus the privacy frameworks that sit alongside them.
Auditor fluency
Runs the relationship with your CPA firm or certification body, and translates their requests into work your team can action.
Canadian context
PIPEDA, PHIPA, Quebec Law 25, the PIPA statutes and the OSFI guidelines that reach vendors through the supply chain.