Skip to content

Evidence your practice can present, not a certificate delivery can't issue.

A client asks how you handle Law 25 or PIPEDA. "We take security seriously" is not an answer. Delivery can run and document the specific, named checks that feed your compliance story — the interpretation, and the attestation, stay outside this lane.

Four things this lane actually produces.

Each is a documented fact about a specific check — not a judgment about whether a client meets a specific legal obligation.

Access reviews
A recurring, dated review of who has access to what, covering the systems named in the lane definition.
Security-baseline reports
The same baseline-administration output — MFA coverage, patch status, endpoint baseline state — summarized on an agreed cadence.
Configuration-change log
What changed, when, and under whose approval, for the systems this lane actually touches.
Documentation hygiene
The service profile and request records kept in a state a practice could actually present, not reconstructed after the fact.

What this lane does not do.

  • Does not issue a compliance attestation, audit opinion, or certification of any kind.
  • Does not interpret Law 25, PIPEDA, or any other statute or regulation for the client.
  • Does not replace a privacy officer, external auditor, or legal counsel.
  • Does not claim a client "is compliant" — only that named checks ran and were documented.

See the security-baseline lane this evidence is drawn from.

Who does what, when a client asks about compliance.

Named checks and their documentationDelivery runs them and keeps the record.
What the record means for a specific obligationSelling practice, or the client's own counsel or privacy officer.
The client's regulatory relationshipStays with the client's designated role — never assumed by delivery.
Whether a finding needs an outside opinionNamed owner decides, using delivery's evidence as one input.

Ask these before promising a client "compliance support."

  1. Which specific checks will actually run, and on what cadence?"Compliance" is not a check until it is named.
  2. Who signs, or stands behind, any document a regulator might eventually see?That name should not be delivery's, and should be agreed in advance.
  3. Does "access review" mean every system, or a named subset?An unscoped review is a promise no one can actually keep.
  4. What happens to a finding delivery surfaces but cannot interpret?It should have a named next stop, not a shrug.

Evidence work still runs inside the same escalation pattern.

A finding that looks like a real risk, not a routine gap, follows the same named-owner path as any other exception.