Compliance
Regulatory compliance documentation and requirements
Overview
Compliance requirements and documentation for SBK operations, including data handling, privacy, and professional standards.
Compliance Areas
Data Protection
| Requirement |
Applicability |
Documentation |
| Client data handling |
All engagements |
Data handling policy |
| PII protection |
Healthcare, HR data |
Privacy procedures |
| Data retention |
All client data |
Retention schedule |
| Data disposal |
End of engagement |
Disposal procedures |
Professional Standards
| Standard |
Requirement |
Evidence |
| Confidentiality |
NDA compliance |
Signed agreements |
| Conflicts of interest |
Vendor-neutral commitment |
Disclosure process |
| Professional conduct |
Industry standards |
Code of conduct |
| Insurance |
E&O, cyber liability |
Current certificates |
Client Compliance Support
| Framework |
SBK Role |
Documentation |
| HIPAA |
Business Associate |
BAA template |
| SOC 2 |
Vendor assessment |
Vendor questionnaire |
| PCI DSS |
Service provider |
SAQ as applicable |
Key Documents
| Document |
Purpose |
Review Cycle |
| Privacy Policy |
Data handling practices |
Annual |
| Information Security Policy |
Security controls |
Annual |
| Acceptable Use Policy |
System usage standards |
Annual |
| Incident Response Plan |
Breach procedures |
Semi-annual |
Compliance Checklist
New Engagement
Ongoing