Regulatory audit services

A regulatory audit tests your controls against the text of the regulation before a regulator, examiner, or plaintiff's counsel does. We audit against GDPR, HIPAA, the GLBA Safeguards Rule, state privacy laws, and NYDFS Part 500, and we report exceptions with evidence and the exact cite.
Talk to an auditor
Definition

What is a regulatory audit?

A regulatory audit is an independent test of your controls against the text of a regulation: what the rule requires, what your organization actually does, and where the two diverge. It is not a regulator's examination, and it confers no approval. It tells you what an examiner would find while you can still fix it quietly. Organizations that handle personal data, patient records, or customer financial information need one before a regulator, a customer, or opposing counsel forces the question. The deliverable is a report that maps each requirement in scope to the control that answers it, findings keyed to the exact article or section, severity ranked by regulatory exposure, and workpapers management can hand to the board, counsel, or an examiner. We report exceptions, we do not correct them. Your team remediates, and we verify that each corrective action closed its finding.

Regulatory audits are one lane of our independent audit practice. SOC 2 is an attestation standard, not a regulation. Organizations that need a SOC 2 examination should start with our SOC 2 audit page.

Regulations

Which regulations do we audit against?

GDPR
HIPAA
GLBA Safeguards Rule
State privacy laws
NYDFS 23 NYCRR 500
Multi-regulation audits

GDPR

We test the record of processing activities against Article 30, the lawful basis claimed for each processing activity, the technical and organizational measures Article 32 requires, DPIAs for high-risk processing, processor agreements under Article 28, and how data subject requests are actually handled against the deadlines the regulation sets.

The full testing scope is on our GDPR audit page.

HIPAA

We test Security Rule and Privacy Rule safeguards against their implementation specifications, the risk analysis required under 164.308(a)(1), minimum necessary in day-to-day uses and disclosures, and patient rights handling: access, amendment, and accounting of disclosures, each against its regulatory deadline.

The full testing scope is on our HIPAA audit page.

GLBA Safeguards Rule

We test the written information security program 16 CFR Part 314 requires: the risk assessment, access controls, multi-factor authentication, encryption, monitoring and testing cadence, service provider oversight, and the annual report to the board or its designee.

The full testing scope is on our GLBA internal audit page.

State privacy laws

We test CCPA and CPRA obligations alongside the Virginia, Colorado, Connecticut, and Utah statutes: privacy notices against actual practice, opt-out and universal opt-out signal handling, sensitive data treatment, and the data protection assessments several of these laws require.

NYDFS 23 NYCRR 500

For covered financial services companies we test the cybersecurity program against Part 500: CISO reporting to the board, penetration testing and vulnerability management cadence, access privilege reviews, and the evidence behind the annual certification. Class A companies carry an independent audit expectation, and we test to it.

Multi-regulation audits

Most clients answer to more than one regime. We run one audit plan across every regulation in scope, issue one evidence request list, test once where requirements overlap, and report findings under each regulation's own cite so nothing is double-counted or missed.

Our approach

Our approach to regulatory audits

01

Applicability comes first

We start by determining which regulations actually reach you, based on the data you hold, the sectors you serve, and where your customers live. Testing against rules that do not apply wastes your budget and ours.

02

Requirements map to controls

Every requirement in scope is mapped to the control that answers it. Requirements with no control behind them surface before testing begins, which is the cheapest place to find them.

03

Evidence gets tested

We sample evidence from your environment: configurations, tickets, logs, agreements, and training records. Interviews corroborate what the evidence shows and never substitute for it.

04

Findings carry the cite

Each finding names the article or section it fails, the evidence we examined, and a severity ranked by regulatory exposure. The report is written so management can hand it to the board, counsel, or an examiner without a translation layer.

contact us

Schedule a regulatory audit

Talk to an auditor about which regulations reach you, what evidence we will request, and when the report can be in hand.

Our Advantage

Why BD Emerson for regulatory audits

Independent by design

BD Emerson's audit practice operates separately from its consulting and technology practices. The audit team does not build compliance programs, sell software, or remediate findings. That separation is what makes the report worth handing to examiners, customers, and boards.

We test, you remediate

We report exceptions with the evidence behind them, and we do not correct them. Your team remediates on its own terms. When it has, we test whether each corrective action closed the finding and say so in writing.

Depth across regimes

GDPR, HIPAA, the GLBA Safeguards Rule, CCPA and its state peers, and NYDFS Part 500, tested by auditors who work these regulations year round. One audit plan covers every regime in scope, with one evidence request list.

How We Work

How we run a regulatory audit

Ten steps, all of them testing. The sequence is the same whether the scope covers one regulation or five.
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What is a regulatory compliance audit?

How is a regulatory audit different from a SOC 2 examination?

Is a regulatory audit the same as a regulator's examination?

How often should we run a regulatory audit?

What does a regulatory audit cost?

What do you need from us?

Are audit findings privileged?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners