The Five Hubs · Compliance

Compliance Hub. One audit trail.

Control evidence that stays current, the Internal Controls Assessment, versioned Policy Management, a full Workforce Training program, and auto-issued Diligence Certificates — all sharing one data model, so cross-program work compounds instead of duplicating. Audit readiness is what the Hub produces, not what it is.

Compliance Hub capabilities

What the Hub ships with.

Auto-issued attestations

Verified Diligence by Verisq.

The Compliance Hub auto-issues program-level certificates daily. Embedded framework mappings. Always current.

Workforce Awareness Training

Issued when training-track completion crosses 80% of required workforce.

HIPAA/PHI Workforce Training

Issued at 95% completion of HIPAA track. §164.530(b) and §164.308(a)(5) coverage.

Policy Management Program

Issued when ≥1 policy is published and ≥1 acknowledgement has been collected in last 12 months.

Risk Acceptance Decision

Issued per-decision with SOX-grade signoffs. Embeds COSO and NIST CSF GV.RM-2 mappings.

SOC 2 Readiness

Issued when all TSC controls reach Operating Effectively. Becomes the bridge document for Type II audit.

GDPR Compliance Program

Issued when RoPA published, DSAR cadence meets SLA, and DPA coverage crosses threshold.

Stop running compliance ‎ as discrete projects.

One set of evidence, controls and training — read by whichever framework is asking.

See pricing SOC 2 readiness deep-dive