ClaimsCorp
Anthony assisted the company with its SOC2 implementation over its data extraction, aggregation and data visualization system from November 2020 to November 2022.
The initial stage involved the development of the target SOC2 controls framework based on in-scope criteria and system technologies and processes in place, using a customized model framework based on best practices and AICPA guidance.
Anthony supported the company's evaluation of potential GRC compliance software tools including OneTrust Certification Automation (formerly Tugboat Logic) and Vanta. Subsequent to the selection of the OneTrust software, Anthony assisted with the incorporation of the SOC2 controls framework into the OneTrust tool, and providing guidance to company personnel how to best utilize the software.
Guidance has been provided on numerous supporting policies and procedures including draft versions of risk assessment policies, procedures and the risk framework, access policies and procedures, HR practices, and systems development/change management policies and procedures.