FAQ Hub · 8 Questions

Compliance FAQ

Practical answers on compliance program design, regulatory mapping, audit readiness, and maintaining technology compliance posture for Canadian organizations.

  • What is a compliance program for technology governance? +

    A technology compliance program encompasses the policies, processes, controls, and monitoring activities that ensure an organization meets applicable legal, regulatory, and contractual obligations related to its technology operations. The program operates within the broader technology governance structure and includes:

    • A regulatory inventory identifying applicable laws, regulations, and standards
    • Control mapping linking compliance requirements to organizational controls
    • Assigned accountability for compliance activities across business functions
    • Training and awareness for relevant staff
    • Ongoing monitoring of compliance status and control effectiveness
    • Reporting to governance bodies on compliance posture

    A compliance program is not equivalent to a framework certification or a single audit. It is a continuously operating governance function that manages compliance obligations on an ongoing basis.

  • How does an organization identify all applicable technology compliance obligations? +

    Identifying applicable technology compliance obligations requires a structured regulatory mapping exercise that considers:

    • Jurisdictions of operation — federal and all applicable provincial/territorial requirements
    • Industry sector — sector-specific regulatory frameworks from OSFI, provincial health regulators, securities regulators, and equivalent bodies
    • Types of data processed — personal information triggers privacy law obligations; payment data triggers PCI DSS; health information triggers health information legislation
    • Customer and partner contracts — contractual compliance obligations including security requirements, audit rights, and certification requirements
    • International obligations — where organizations operate in or serve customers in other jurisdictions, applicable foreign requirements (e.g., EU GDPR for organizations serving European individuals)

    Regulatory mapping should be reviewed annually and when significant changes occur in organizational operations, technology environment, or regulatory landscape. Compliance and legal counsel should be engaged in initial mapping and material updates.

  • What is the difference between ISO 27001 and SOC 2 for compliance purposes? +

    ISO 27001 and SOC 2 address information security assurance from different perspectives:

    ISO 27001 is a management system standard with a certification pathway. Certification requires establishing and maintaining an Information Security Management System (ISMS) meeting standard requirements, and is assessed by accredited third-party certification bodies. ISO 27001 certification is recognized globally and is increasingly required in government and enterprise procurement.

    SOC 2 is an audit report issued by CPA firms assessing service organization controls against AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). SOC 2 reports — particularly Type II reports covering operating effectiveness over a period — are widely used in North America for vendor due diligence by enterprise customers.

    ISO 27001 provides a broader management system framework; SOC 2 focuses on specific Trust Services Criteria for service organizations. Many Canadian technology service providers maintain both, as they serve different audiences: SOC 2 for North American enterprise customers and ISO 27001 for international and public sector requirements.

  • How should organizations prepare for a regulatory technology audit? +

    Preparing for a regulatory technology audit requires advance readiness work across several areas:

    • Documentation readiness — Ensuring governance policies, procedures, and control evidence are current, accessible, and organized. Auditors typically request evidence packages; having these prepared in advance reduces disruption and demonstrates governance maturity
    • Control effectiveness testing — Conducting internal pre-audit testing to identify control gaps or evidence weaknesses before the regulatory examination
    • Prior finding remediation — Ensuring previously identified findings from internal audits, prior regulatory examinations, or independent assessments have been remediated with documented evidence
    • Stakeholder preparation — Briefing key personnel on likely audit areas and their roles in the examination process
    • Management reporting currency — Ensuring governance reporting to the board and senior management reflects current technology risk posture

    Organizations that maintain ongoing compliance programs rather than point-in-time examination preparation typically demonstrate stronger audit results.

  • What are Quebec Law 25's main technology governance implications? +

    Quebec's Law 25 (Act Respecting the Protection of Personal Information in the Private Sector), fully in effect since September 2023, introduced several technology governance requirements that exceed standard PIPEDA obligations:

    • Privacy Impact Assessments (PIAs) — Required for new technology projects involving personal information, prior to implementation. PIAs must evaluate privacy risks and identify mitigation measures
    • Privacy by Design — Organizations must implement privacy protections by default in any technology project or business process involving personal information
    • Automated decision disclosure — Individuals must be informed when decisions affecting them are made solely through automated processing, and must have the right to request human review
    • Data portability — Rights for individuals to receive their personal information in a commonly used technological format
    • Incident response — Enhanced breach notification requirements to the Commission d'accès à l'information (CAI) and affected individuals
    • Privacy officer designation — Mandatory appointment of a privacy officer with defined responsibilities
  • How is compliance monitoring different from compliance auditing? +

    Compliance monitoring and compliance auditing are complementary but distinct activities within a compliance program:

    Compliance monitoring is an ongoing, continuous activity performed by process owners and compliance staff to verify that controls and processes are operating as required. Monitoring uses automated tools, regular reviews, and exception reporting to detect deviations in near-real-time. First-line and second-line functions typically own monitoring activities.

    Compliance auditing is a periodic, independent assessment of compliance program effectiveness conducted by internal audit or external parties. Auditing provides independent assurance to governance bodies that compliance controls are designed and operating effectively. Third-line audit functions own audit activities.

    The distinction reflects the three lines of defence model: the first line owns operations and controls; the second line owns risk management and compliance oversight including monitoring; the third line (internal audit) provides independent assurance. Effective compliance governance requires all three lines to function as designed.

  • What is a unified control framework and why does it matter for compliance? +

    A unified control framework maps multiple compliance obligations — ISO 27001, SOC 2, PIPEDA, PCI DSS, and other applicable requirements — to a single consolidated set of organizational controls. Rather than maintaining separate control populations for each framework, the organization implements and tests controls once and maps evidence to multiple requirements.

    Unified control frameworks provide several governance benefits:

    • Reduced control duplication and testing overhead
    • Clearer control ownership and accountability
    • More efficient evidence collection for audits and assessments
    • Easier identification of control gaps when new regulatory requirements are added
    • Consistent reporting across compliance obligations

    Commercial governance, risk, and compliance (GRC) platforms often provide pre-built control frameworks with mapping to common standards. Organizations can also build unified frameworks manually using spreadsheet-based mapping tools, though this approach requires ongoing maintenance as standards evolve.

  • How should technology organizations handle compliance with OSFI's third-party risk guidance? +

    OSFI Guideline B-10 (Third-Party Risk Management) applies to federally regulated financial institutions and sets requirements for governing third-party relationships, including technology service providers and cloud vendors. Key compliance considerations include:

    • Due diligence — Conducting risk-based due diligence before entering material third-party technology arrangements, including assessment of financial stability, security posture, and regulatory compliance
    • Contract requirements — Ensuring contracts with material technology vendors include provisions for audit rights, security requirements, data handling obligations, incident notification, and exit provisions
    • Concentration risk — Monitoring and managing concentration risk in technology vendor relationships, particularly for critical services or shared infrastructure dependencies
    • Ongoing monitoring — Maintaining ongoing oversight of material vendor relationships through performance monitoring, incident tracking, and periodic reassessment
    • Exit planning — Maintaining documented exit strategies and transition plans for critical technology service dependencies

    FRFIs subject to B-10 should review current OSFI guidance directly, as requirements are subject to update. Technology service providers serving FRFI customers should expect due diligence inquiries and contractual requirements aligned with B-10.