Home/ Resources/ Playbooks
Resources · Playbooks

Implementation guides built for GRC leads, not consultants.

Step-by-step playbooks for the frameworks your regulators, customers and board are asking about. Download free. Use in Sentrix or without it.

SaaS & technology

SOC 2 in 30 Days

The complete program for SaaS companies going from zero to Type I readiness. Control checklists for AWS, Azure, and GCP architectures, evidence templates, policy starters, and a week-by-week implementation plan.

48 pages · Updated March 2026
Download free →
Financial services

DORA Article-by-Article Implementation Guide

Full DORA breakdown for financial entities: ICT risk framework, third-party register templates, incident classification matrix, TLPT planning guide, and concentration risk analysis worksheet.

62 pages · Updated Jan 2026
Download free →
Canadian compliance

Law 25 Compliance Checklist for Quebec Organizations

Everything required to satisfy Law 25 in full: PIA process and templates, consent management framework, breach notification workflow (72-hour CAI reporting), and the 10 most commonly missed requirements.

36 pages · Updated Sept 2025 · FR / EN
Download free →
Healthcare

HIPAA Security Rule: The Technical Safeguards Checklist

All 75 HIPAA Security Rule implementation specifications mapped to the technical controls your cloud architecture needs to satisfy them. PHI data flow mapping worksheet and BAA tracking template included.

44 pages · Updated Feb 2026
Download free →
Multi-framework

SOC 2 + ISO 27001: The Dual Certification Fast Path

If you need both, here is how to structure one evidence program that satisfies both simultaneously. Crosswalk analysis showing 73% overlap, gap identification, and a sequenced 6-month implementation plan.

52 pages · Updated Dec 2025
Download free →
GRC strategy

The GRC Stack Audit: Finding Your $180K in Hidden Overlap

The methodology we use to analyze customer GRC tool stacks and identify recoverable spend. Includes the overlap analysis framework, contract review checklist, and CFO-ready savings model template.

28 pages · Updated Nov 2025
Download free →
Third-party risk

Vendor Risk Management from Scratch: A 90-Day Program

How to stand up a vendor risk program in 90 days: vendor inventory process, risk-tiering methodology, questionnaire templates (SIG Lite, CAIQ), and continuous monitoring setup for your critical suppliers.

40 pages · Updated Oct 2025
Download free →
Canadian compliance

CPCSC Readiness Guide for Canadian Defence Suppliers

Level 1 and Level 2 CPCSC certification readiness: in-scope determination, control implementation guide mapped to NIST SP 800-171, and evidence collection checklist for your first assessment.

38 pages · Updated Jan 2026
Download free →

Use Sentrix to implement any playbook automatically.

Book a demo and we will show you your current posture against the framework you are targeting.