knowledge

How we deliver compliance you can actually use

Emilie Løyche

Senior Compliance Officer

Share
Nobly employees working together on compliance and documentation

Compliance no longer lives only in legal documents and annual audits. It has become a fixed part of everyday work - particularly in regulated industries, where the requirements for documentation, security and supplier management have been tightened.

For us, compliance is not just about being able to answer a questionnaire. It is about having processes, documentation and accountability that work in daily operations, and that our customers can use in their own compliance.

Here are four of the ways we make that concrete.

Four concrete compliance deliverables at Nobly: contractual addenda, Statement of Applicability, support in North GRC and an ISAE 3000 report - which together provide clear answers to the customer's questions

Contractual addenda

We can describe the requirements and obligations we meet as a supplier in an addendum to our contracts. That way it is set out in black and white what the customer can expect from us, and what we commit to.

Statement of Applicability

We can document the controls that are relevant to our business, and show which ones are implemented, assessed and embedded in our compliance work. It gives a clear picture of where we stand.

Support in North GRC

Our compliance work is gathered in one tool: North GRC. Controls, documentation and assessments are structured and maintained there. That makes it possible to work systematically and to quickly find and share the documentation our customers ask for.

ISAE 3000 report

Our work on information security and controls is included in our ISAE 3000 report. It gives our customers independent assurance of our control environment - not just our own word that we have it under control.

Compliance you can use in practice

When a customer asks about DORA, information security or supplier management, we need to be able to answer clearly and concretely. Not with general statements of intent, but with documentation, controls and established processes.

That is the value we want to pass on to our customers: confidence, transparency and a stronger foundation for their own compliance.

← Back to the blog