Governance and compliance
Compliance for suppliers
Your customer demanded security. We answer for you.
What this work consists of
When you are the vendor, your client's security requirements arrive as a sixty-question questionnaire, a contract clause, a scheduled audit, or a certification request, and they usually arrive holding up a sale. We take over that front: we build the answers, gather the evidence behind each one, and stay at your side in the conversation with the client.
The real gain is not in today's questionnaire, it is in the next one. With the dossier built, standard answers ready, and evidence in place, the next client gets answered in hours instead of stopping the company for two weeks. And when the problem is a missing control, we start with a gap assessment against the client's requirement, implement what is missing, and only then build the dossier.
On your side, we need the questionnaire or contract exactly as it arrived, access to the policies and evidence that already exist, and someone who knows the environment to validate the answers, because everything is reviewed with you before it goes out. In meetings and audits with your client, we are in the room.
How we conduct it, stage by stage
The stages and deliverables below describe the Build the file and keep it current modality. The other modalities appear when you request the proposal.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Building the file
We bring the policy, the evidence and the standard answers into a single set, so the next customer is answered in hours.
Answering the customer
We fill in what was asked, review it with you before it goes out and stay in the meeting when the customer wants to talk.
Continuous operation
Throughout the contract we keep what was built alive: we review it at every relevant change, run what is on the calendar and report at the agreed frequency. It is what separates a delivered document from a practice still worth something a year later.
What is not included
- A guarantee of client approval, since the client decides by its own criteria
- Signing declarations on your company's behalf, which is yours: whoever signs is accountable for the content
- The certification itself, when the client requires one: we prepare the path, but it comes in as its own project and the independent body issues it
- Answers claiming controls that do not exist: when a control is missing, the path is the remediation tier, not creative writing
- Commercial or legal negotiation of the contract with your client, which stays with your sales and legal teams
- Ongoing operation of the controls implemented during remediation, which stays with your team
- Assessing your own vendors, which is the other side of the counter and has its own engagement in the catalog
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.