Part 500 requires an annual certification of compliance from senior leadership. We make sure the controls behind that signature are implemented, enforced, and documented.
The Real Problem
Part 500 is unusual among regulations because it puts a named senior officer’s signature on an annual certification. That makes the standard for “we believe we’re compliant” much higher than it is elsewhere. The person signing needs to know the controls were operating, not that a policy document says they should be.
In practice the gaps are consistent: MFA with quiet exceptions for service accounts, third-party relationships nobody inventoried, and evidence assembled in the weeks before certification rather than captured as events occurred.
What’s Included
Each obligation traced to the specific technical control satisfying it, with the proof attached.
MFA applied across the environment, including the legacy and service accounts usually exempted.
Privileged access reviewed on a schedule, with entitlements matched to current responsibilities.
A register of service providers touching firm or customer data, with obligations tracked and reviewed.
A written, tested plan with the 72-hour notification path defined before you need it.
Documentation accruing continuously, so the annual signature rests on records rather than recollection.
Common Questions
Possibly, based on headcount, revenue, and assets — but exemptions are partial, not total, and they still require filing. Worth confirming with counsel rather than assuming.
No. It’s a senior officer certification and it stays with your leadership. Our job is making sure the controls behind it hold up.
The signature is only as good as the evidence behind it. We’ll show you where the gaps sit.