Skip to content
Pillar III · Governance

Compliance & Audit

Navigate complex regulatory landscapes with expert guidance in IT audit, governance, risk management, and compliance — PCI-DSS, ISO 27001, SOC 2, LGPD/GDPR, and BACEN on a single page.

Overview

Berghem's Compliance and Governance pillar covers the entire regulatory cycle — from the IT audit that identifies the current state, to GRC consulting that structures the program, to gap analysis that prioritizes remediation, to regulatory testing that proves adherence before an external auditor or QSA.

We don't work with paper checklists. Each engagement delivers measurable posture, auditable evidence, gap-based roadmap, and sign-off ready for the main frameworks: PCI-DSS, ISO 27001, SOC 2, LGPD/GDPR, BACEN, and sector regulations.

Everything included

IT Audit — infrastructure, access, data, and BCP
GRC Consulting — governance, risk, and compliance
Gap Analysis — ISO 27001, PCI-DSS, SOC 2
LGPD/GDPR compliance and BACEN regulations
Regulatory pentest PCI-DSS and SWIFT CSP
Prioritized roadmap and QSA/auditor sign-off
Module 01 · Program

Diagnosis and Governance

Comprehensive audit of the current state and structuring of the governance, risk, and compliance program — foundation for any sustainable regulatory initiative.

ISO 27001 · BCP · Access

IT Audit

Comprehensive assessment of infrastructure, controls, and processes against industry standards and regulatory requirements — infrastructure and network audit, access control review, data protection, and business continuity assessment.

Governance · Risk · Compliance

GRC Consulting

Governance, risk management, and compliance aligning the security program with business objectives — governance framework, risk assessment, policy and procedure development, and complete compliance program design.

Module 02 · Frameworks

Adequacy and Validation

Gap identification against target frameworks and regulatory testing that produces the evidence required by external auditor, QSA, or regulator — from prioritized diagnosis to sign-off.

ISO · PCI · SOC 2 · LGPD · GDPR

Gap Analysis

Gap identification between current posture and target frameworks, with actionable and prioritized remediation plans — ISO 27001, PCI-DSS readiness, SOC 2 preparation, and LGPD/GDPR compliance review, with timeline and effort estimates.

PCI-DSS · SWIFT CSP · BACEN

Regulatory Testing

Specialized pentests and security assessments to meet specific regulatory and compliance requirements — PCI-DSS penetration testing, SWIFT CSP assessment, BACEN compliance testing, and sector regulatory testing with QSA sign-off.

Ready to get started?

In a 30-minute conversation, we'll map your regulatory landscape and design the ideal scope — from initial diagnosis to full certification.

Contact Us