Banking, financial services & insurance.
RBI-regulated banks, NBFCs and lending platforms. Engagements cover cyber security framework alignment, third-party risk management, and outsourcing / cloud governance.
The framework set is the same; the regulator-facing posture is not. ComplyGeek has operated under the following sectoral regulators and customer-due-diligence regimes — each sector below names the controls that matter to its audit.
RBI-regulated banks, NBFCs and lending platforms. Engagements cover cyber security framework alignment, third-party risk management, and outsourcing / cloud governance.
IRDAI Cyber Security audit management end-to-end. Information security committee enablement, regulatory submissions, and on-site audit support for IRDAI inspections.
Customer-due-diligence-driven posture. ISMS certification, customer security questionnaire response automation, and secure-SDLC governance for client-facing delivery teams.
PCI DSS audit coordination with QSAs, cardholder data environment scoping, tokenisation governance, and PCI-aligned secure architecture for payment platforms.
Global captive and shared-service operations subject to multiple jurisdictional regimes. Cross-jurisdictional control mapping, customer-contract security clauses, and audit-evidence reconciliation.
Telecoms, healthcare, public sector enterprises. Sectoral cybersecurity framework alignment, CERT-In compliance, and regulatory incident-reporting playbooks.