Partner program

MSP and MSSP partnership program

Your clients keep asking for a SOC 2 report. Some now ask for ISO 27001 before they will sign. You already run their cloud, their identity system and their endpoints, so you hold most of the evidence an auditor wants. What you may not hold is a compliance team.
The nank.ai partner program closes that gap. You bring the client relationship and the systems you already manage. We bring the compliance platform, a named compliance manager and the AI agents that do the repetitive work. Your client gets audit ready. You keep the account and add a service line that renews every year.
Three ways to partner
Refer. Resell. Co-deliver.
Take a referral fee and stay out of delivery. Sell under your own agreement at your own price. Or implement the controls yourself and let our compliance manager run the program and the audit.
You can run different clients under different models.
How the model splits

You keep the client. We carry the compliance program.

Two teams, one engagement, and a line that an auditor can follow.

You bring

The client relationship, the contract where you want it, and the cloud, identity, code and device systems you already manage.

We bring

The compliance platform, one control library across twelve frameworks, a named compliance manager and the AI agents that carry the repetitive work.

Your client gets

A program that runs, evidence collected on a schedule, and an audit the client can pass. Most reach audit readiness in about three months.

The case for adding it

Why compliance belongs in your service catalogue

Compliance work lands on your desk whether you sell it or not. The client forwards the security questionnaire to you. The auditor asks you for the access review export. The renewal depends on a report you did not scope and cannot produce.
Two things follow. First, you absorb the cost of that work inside a managed services contract that never priced for it. Second, someone else wins the compliance engagement, sits beside you in the client’s environment, and starts making recommendations about the stack you built.
Adding Compliance as a Service to your catalogue turns that leak into revenue. The work you already do becomes billable. The advice stays yours.
What changes for your P&L
Unpriced questionnaire and evidence work becomes a service line that renews. Onboarding cost falls with every client, because the control patterns carry over. And the compliance conversation stays inside your account rather than opening a door for someone else.
What does not change
You do not hire a compliance lead. You do not build a control library. You do not learn to manage an audit firm. Those sit with us.
What you get

What the partnership gives you

One control library, twelve frameworks

Write a control once. It satisfies every framework that asks for it. The library covers ISO 27001, ISO 27701, ISO 42001, SOC 2, HIPAA and GDPR. It also covers PCI DSS, NIST CSF, NIST 800-53, CSA CCM, CMMC and FedRAMP.
For a partner this matters more than for a single client. Your second client costs less to onboard than your first. Your tenth costs less again, because the control patterns you built for a SaaS company in Toronto carry over to the next one.

A compliance manager who does the work

Every engagement gets a named compliance manager. That person scopes the program, plans the calendar, manages the auditor relationship and answers the questions your engineers cannot. You do not staff a compliance practice to sell compliance.
Your account manager stays the client’s main contact. The compliance manager works behind that line or in front of it, whichever the client prefers.

AI agents that carry the volume

The AI agents draft policies from the client’s real context, map those policies to controls, run risk assessments and verify that controls operate. This is the part of compliance that used to eat months of junior time. It now runs on a schedule.

A platform your team can see into

The compliance platform pulls evidence from cloud, identity, code and device management systems. Since you run most of those systems, the integration work is short. Control status reflects how the systems run today rather than what someone wrote down last quarter.
Partnership models

How partners work with us

Pick the model that matches how much of the delivery you want to own.
1

Refer

You introduce the client. We scope, price and deliver. You take a referral fee and stay out of the delivery. This suits partners who want the client served without adding a service line.
2

Resell

You sell Compliance as a Service under your own agreement at your own price. We deliver behind you. You own the contract, the invoice and the margin. Most MSPs start here.
3

Co-deliver

Your engineers implement the technical controls. Our compliance manager runs the program, the evidence and the audit. This suits MSSPs with a security practice that already handles logging, vulnerability management and incident response.
You are not locked in
You can run different clients under different models. Nothing forces one choice across your book. Partners often move a client from refer to resell once their team has watched an engagement run.
Canada

SOC 2 and ISO 27001 across Toronto, Ontario and Canada

Nank.ai works out of Toronto and serves clients across Ontario and the rest of Canada. For partners selling to Canadian buyers, three things are worth knowing.

Who signs what

A SOC 2 report comes from a licensed CPA firm. An ISO 27001 certificate comes from a certification body that the Standards Council of Canada accredits under ISO/IEC 17021-1. Neither we nor you can issue either one. We get your client ready and we manage the firm that does issue it. Any partner program that suggests otherwise is worth a second look.

Canadian data residency compliance

Client data stays in the country the client resides in. For a Canadian client, that means Canadian hosting. Buyers in health, finance and the public sector ask this question early, and a clear answer often decides the deal. Note that no SOC 2 criterion tests residency, so a report alone does not prove it. The claim has to be made and evidenced on its own.

PHIPA and provincial rules

Ontario health clients answer to PHIPA. Quebec clients answer to Law 25. Both sit beside SOC 2 and ISO 27001 rather than inside them. The control library covers them from the base you already built.
Getting started

What a partner engagement looks like

1

Week one

We meet your team, agree the model and set up your partner workspace. You get access to scoping tools, pricing guidance and the material you need to have the first client conversation.
2

First client

We run the first engagement close beside you. Your team watches how scoping, control design and evidence collection work in practice. By the end of it you can scope the next one yourself.
3

Steady state

You bring clients in as they come. Each gets a compliance manager and a workspace. You see program status across your book, so you know which client is on track and which one needs a call.
Read this before you sell it

Where the line sits

One point deserves care. If your team operates a client’s security controls, your team cannot be the objective party that audits them. ISO 27001 Clause 9.2.2 asks for internal audits that stay objective and impartial. An auditor will look at who ran the control and who tested it.
This is a reason to partner rather than a reason to worry. Our compliance manager performs that verification, which keeps your delivery role and the assurance role in separate hands. It also gives your client a cleaner story at audit time.
We say the same thing to every client. Our SOC 2 compliance service and ISO 27001 certification service pages set out how we handle the boundary.
Separation of duties, in one line
You run the control. We test the control. The audit firm or certification body forms the opinion. Three parties, three roles, and nobody marking their own homework.

Who this program fits

Does your book sit in a regulated sector? The industry solutions and compliance solutions pages show how one control base adapts by sector and by company size.
Partner questions

Frequently asked questions

Yes. Under the referral and resell models the client stays yours, including the contract and the invoice. Under co-delivery the client holds an agreement with both of us. We put the split in writing before work starts.
Partner workspaces carry your branding in client-facing views. Talk to us about the specifics for your model, since the answer differs between resell and co-delivery.
Pricing depends on scope, framework count and the number of systems in play. Our pricing page sets out the base. Partners get scoping guidance so the number you quote holds up.
Most clients reach audit readiness in about three months. A client whose systems you already manage often moves faster, because the evidence sources are known and the access is in place.
No. That is the point of the model. Your team stays in its lane and the compliance manager carries the program.
All twelve in the control library. Most partners lead with SOC 2 and ISO 27001, then add ISO 42001, HIPAA or PCI DSS as client demand appears.
Partner enquiry

Talk to us about partnering

Tell us about your book of business and what your clients now have to prove. We will come back with a model, a commercial structure and a first engagement to run together.
Prefer email? Write to [email protected], or use the general contact form.
Keep reading

Before your first partner conversation

Compliance as a Service

The service your clients buy: a compliance manager, AI agents and a platform that runs the program end to end.

SOC 2 compliance service

Scope, timeline and what a client owns when the CPA firm arrives to run the examination.

ISO 27001 certification service

Stage 1 to Stage 2, the Statement of Applicability, and the certification body relationship.
Scroll to Top