Skip to content
GREY WING SECURITY

GRC & Compliance Program

Run the controls and evidence behind your audit.

Policies, control ownership, audit evidence, customer security reviews, and risk tracking, maintained alongside the systems your company operates.

When this program fits

For teams preparing for SOC 2 or customer security reviews, or maintaining a compliance program after the first audit.

  • An audit or customer review has a deadline, but evidence and control owners are missing.
  • Policies describe processes that no longer match how the company works.
  • Vendor reviews, exceptions, and recurring control checks need a regular review process.

The work inside the program.

We agree the systems, priorities, and depth of work with you before delivery begins.

Governance & controls

Translate the requirements in your review into policies and operating responsibilities.

  • Map agreed framework and customer requirements to current systems
  • Write and update policies to reflect actual procedures
  • Assign control owners and recurring review dates
What you receive

Requirements map, control register, and policies ready for client approval.

Audit readiness & evidence

Organize the records an auditor needs and track gaps before review.

  • Build an evidence calendar with owners and collection instructions
  • Review evidence for the agreed systems and review period
  • Coordinate auditor requests and track remediation
What you receive

Evidence index, readiness tracker, and audit request log.

Customer security reviews

Answer customer questions using documented controls and current evidence.

  • Prepare responses to agreed security questionnaires
  • Map answers to policies, controls, and supporting records
  • Flag gaps and route commitments to your decision-makers
What you receive

Response library and completed questionnaire drafts for client approval.

Risk & vendor management

Keep business risks, vendor reviews, and exceptions assigned and current.

  • Maintain risk owners, treatment plans, and review dates
  • Review agreed vendors and record security findings
  • Track exceptions, approvals, and remediation decisions
What you receive

Risk register, vendor review records, and an exception log.

What your team receives.

Plans, configuration records, and evidence are maintained in your accounts and documentation tools.

  • A compliance roadmap with milestones, owners, and evidence requirements

  • Policies and control descriptions matched to your operating environment

  • An evidence index and calendar for recurring control reviews

  • Audit and customer request trackers with open gaps and assigned actions

  • Risk, vendor, and exception registers for leadership review

From the first review to recurring work.

Start with a defined phase or an ongoing program.

  1. Map requirements

    Confirm the framework, entities, systems, and deadline. Compare requirements with existing controls and evidence.

  2. Build the control set

    Write policies, assign control owners, and coordinate the system changes needed to close gaps.

  3. Collect & prepare

    Review evidence, prepare customer responses, and coordinate requests with your auditor and control owners.

  4. Maintain & review

    Run the evidence calendar, update risk and vendor records, and review changes ahead of the next audit.

Responsibilities and scope.

Your team

  • Assign decision-makers for control ownership, risk acceptance, and policy approval.
  • Connect Grey Wing with system owners and provide the required records.
  • Approve policies, customer responses, and external submissions.

Agreed before kickoff

  • The proposal names frameworks, entities, systems, deadlines, and evidence collection periods.
  • Independent audit fees and compliance platform licenses are separate.
  • Customer questionnaires, vendor reviews, and technical remediation are included as defined in the work plan.

Fees depend on systems, deliverables, and operating requirements. How pricing works

Before we get started.

Do you issue a SOC 2 report?

No. Grey Wing supports control implementation, evidence preparation, and auditor coordination. An independent CPA firm performs the SOC 2 examination and issues the report.

Can you work in Vanta or Drata?

Yes. We can work in your existing compliance platform and document evidence collection and control ownership there. Platform licenses are separate from the program fee.

Can you help after our first audit?

Yes. Recurring work can include evidence collection, control reviews, policy updates, vendor reviews, and preparation for the next examination.

Which frameworks and questionnaires are included?

The proposal names the framework, entities, systems, audit period, and customer reviews included. We confirm requirements before committing to the work or timeline.

Discuss the GRC & Compliance Program.

Bring your systems, current gaps, and any deadline. We’ll use the conversation to define priorities and the first work plan.