The GRC knowledge base for teams who need to move fast.
Practical guides, framework playbooks, and recorded sessions from GRC practitioners—not vendor marketing. Use them to build your program, prepare for audits, or make the case to your CFO.
Collections
All collections →Playbooks
All playbooks →SOC 2 in 30 Days
Step-by-step program for SaaS companies going from zero to Type I readiness in 30 days. Includes control checklists, evidence templates, and auditor-ready documentation.
PlaybookDORA Compliance Guide for Financial Entities
Full DORA Article-by-Article breakdown with implementation guidance, ICT third-party register templates, and incident reporting workflow documentation.
PlaybookLaw 25 Implementation Checklist
Quebec organizations: everything you need to satisfy Law 25 by the deadline. PIA process, consent management, breach notification timelines, and CAI reporting requirements.
Blog
All posts →DORA is live. Is your ICT third-party register audit-ready?
DORA enforcement started January 2025. Here is what financial entities most commonly get wrong in their first ICT third-party oversight documentation and how to fix it before your regulator asks.
The true cost of your GRC tool stack (it is probably $640K)
Most mid-market security teams cannot tell you what they actually spend on GRC tooling across all contracts. We analyzed 200 customers’ stacks and found the same pattern everywhere.
ISO 27001:2022 vs SOC 2—which should you get first?
If your customers are asking for both, here is a decision framework for which certification to pursue first, how to structure your evidence program to satisfy both, and what the audit timelines really look like.
Webinars
All webinars →DORA in Practice: ICT Third-Party Risk for Financial Entities
45-minute session walking through DORA’s third-party requirements with a live demo of Sentrix’s ICT register. Featuring a compliance lead from a Montréal-based fintech.
On demandLaw 25 One Year On: What Quebec Organizations Are Still Getting Wrong
Live session with a Québec privacy lawyer reviewing the most common Law 25 gaps and how Sentrix automates the technical controls required by the CAI.
On demandHow to Cut Your GRC Spend in Half Without Losing Coverage
The Sentrix license optimizer in action: a live analysis of a real customer’s 6-tool GRC stack that identified $240K in recoverable spend before the first audit ran.