Security & Compliance

Audit-Ready the First Time

SOC 2, HITRUST CSF, HIPAA, NIST CSF, PCI DSS, FISMA, ISO 27001, and ISO/IEC 42001 for AI. We run the gap assessment, write what’s missing, implement with your team, and stay in the room through the audit.

SOC 2HITRUST CSFHIPAANIST CSFPCI DSSFISMAISO 27001ISO/IEC 42001GDPR
CONTROL MAP, AI EXTENSIONCLIENT REDACTED
Existing frameworkThe AI obligation that extends itEvidence produced
SOC 2Access review extended to model, agent and API credentialsQuarterly review record naming the AI systems in scope
HITRUST CSFVendor AI features assessed before regulated data reaches them
HIPAARisk analysis covering PHI an AI system processesDocumented risk analysis with the AI data flow attached
NIST CSFDetection and response extended to prompt, output and agent activityLogging standard, plus one AI-scenario tabletop record
GLBA Safeguards RuleBoard reporting that names AI risk and who owns itAnnual report section with the AI inventory as an exhibit
Composite example. The obligation is new; most of the control environment is not. Scrolls sideways on a narrow screen.

The problem

Certification Is Rarely a Technology Problem. It’s a Documentation and Follow-through Problem

Most organizations we meet already have decent controls. What they don’t have is the written procedure describing the control, the evidence that it ran, the owner who’s accountable for it, and the twelve months of consistency an auditor will sample.

That work is unglamorous, it competes with shipping, and it’s the reason first attempts slip. It’s also most of what we do, including writing the documentation when nobody internally has the capacity, which is the point where most programs stall.

How we help

Gap to Certificate, with Your Team in the Loop

Gap Assessment

Current state against the framework, scoped honestly, with the system boundary defined before anything else.

Remediation and Control Implementation

Working alongside your engineers, not handing them a spreadsheet of findings.

Documentation

Policies, procedures, and control descriptions written to be used, not just to be shown.

Evidence Readiness

What to keep, where it lives, how it’s produced, so collection isn’t a fire drill each cycle.

Audit Support

We sit in the audit. Auditors ask us questions directly, which shortens it for everyone. Where an attestation requires an independent CPA firm, we work alongside them.

Multi-Framework Efficiency

One control set mapped across frameworks so HITRUST CSF doesn’t restart what SOC 2 already proved.

Scope

SOC 2 Type I and II readiness · HITRUST CSF readiness and assessment support · HIPAA Security Rule risk analysis and remediation · NIST CSF assessment · PCI DSS readiness · FISMA System Security Plans · ISO 27001 · ISO/IEC 42001 · control mapping across frameworks · system boundary and data flow definition · infrastructure security consulting where controls need building

What you get

The Report, and a Program That Survives It

  • A defined scope and system boundary you can defend
  • A gap assessment with a prioritized remediation plan
  • Written policies and procedures your team recognizes as theirs
  • Evidence organized the way the assessor asks for it
  • Support through the audit, and a program that holds up next year
Healthcare analytics

HITRUST CSF

First HITRUST CSF with no internal documentation capacity. We ran readiness the year before, built the roadmap, and wrote the procedures and policy updates.

Non-profit benefits organization

SOC 2

Sought a SOC 2 Type II with gaps across the control environment. We assessed, remediated with their team, and prepared them for audit.

Tax software startup

SOC 2 Type I

A tight deadline driven by client assurance requirements. We mapped controls, aligned practices, and got the evidence in place.

Continuous assurance

The Work Stays Proven after We Hand It Over

Between audits, the CyRisk platform tracks control status and certification readiness, so the next cycle starts from where you are rather than from scratch.

CyRisk is 4A’s sister platform. Where our work for CyRisk appears on this site, we disclose the affiliation.

Get Certified, and Stay Certified