Skip to content

Compliance

Regulatory compliance documentation and requirements

Overview

Compliance requirements and documentation for SBK operations, including data handling, privacy, and professional standards.

Compliance Areas

Data Protection

Requirement Applicability Documentation
Client data handling All engagements Data handling policy
PII protection Healthcare, HR data Privacy procedures
Data retention All client data Retention schedule
Data disposal End of engagement Disposal procedures

Professional Standards

Standard Requirement Evidence
Confidentiality NDA compliance Signed agreements
Conflicts of interest Vendor-neutral commitment Disclosure process
Professional conduct Industry standards Code of conduct
Insurance E&O, cyber liability Current certificates

Client Compliance Support

Framework SBK Role Documentation
HIPAA Business Associate BAA template
SOC 2 Vendor assessment Vendor questionnaire
PCI DSS Service provider SAQ as applicable

Key Documents

Document Purpose Review Cycle
Privacy Policy Data handling practices Annual
Information Security Policy Security controls Annual
Acceptable Use Policy System usage standards Annual
Incident Response Plan Breach procedures Semi-annual

Compliance Checklist

New Engagement

  • NDA signed
  • BAA signed (if applicable)
  • Data handling agreement
  • Access controls defined
  • Insurance certificate provided

Ongoing

  • Annual policy review
  • Insurance renewal
  • Staff training completion
  • Incident response testing