US Audit Group
GLBA · HIPAA · PCI-DSS Compliance

Is Your Business Actually Compliant?

Independent compliance risk assessments for US banks, credit unions, healthcare SaaS, and payment-accepting businesses — backed by real technical testing, not a policy checkbox. Led personally by a CISA-certified auditor.

CISA CertifiedISACA MemberIIA Standards39 Years Banking AuditEx-SBI AGM (Vigilance)
Why Now

Compliance expectations are rising.
Are you ready?

GLBA's Safeguards Rule applies to any non-bank financial company, not just banks

HIPAA Security Rule violations carry real financial and reputational risk for healthcare SaaS

PCI-DSS compliance is mandatory for any business that accepts card payments

Enterprise customers and cyber insurers increasingly require proof of compliance before they'll sign

Services

Choose the framework that applies to you

Every engagement is auditor-led and individually scoped. Request a consultation for a quote tailored to your organization's size and complexity.

Lead Service
Banks · Credit Unions · Fintech

GLBA Compliance Risk Assessment

Full Safeguards Rule gap assessment for financial institutions

Best fit for
Community banks, credit unions & fintech lenders
  • Safeguards Rule gap assessment scorecard
  • Customer data flow mapping
  • Vendor & third-party review
  • Technical security testing, coordinated through our delivery network
  • Board-ready report for regulators & leadership
  • Prioritized remediation roadmap
Start a GLBA Assessment
Healthcare SaaS & Digital Health

HIPAA Security Risk Assessment

Security Rule readiness assessment, not a certification claim

Best fit for
Healthcare SaaS & digital-health startups
  • HIPAA Security Rule gap assessment (Administrative, Physical, Technical)
  • PHI data flow mapping
  • Business Associate & BAA gap check
  • Technical security testing, coordinated through our delivery network
  • Written risk assessment report for customers, investors & insurers
  • Prioritized remediation roadmap
Start a HIPAA Assessment
Payments & E-commerce

PCI-DSS Readiness Assessment

Cardholder-data compliance readiness, not a formal QSA attestation

Best fit for
Any business that accepts, processes, or stores card data
  • Gap assessment against the 12 PCI-DSS requirements
  • Cardholder data flow mapping
  • SAQ type determination & readiness support
  • Technical security testing, coordinated through our delivery network
  • Written readiness report
  • Prioritized remediation roadmap
Start a PCI-DSS Assessment

Every engagement is scoped individually based on organization size, data volume, and complexity. Not a law firm, CPA firm, or QSA — engagements are risk assessments and readiness reviews, not formal certifications or attestations.

How It Works

From evidence to signed report

A structured, repeatable 4-step process. Our audit technology does the heavy lifting — the auditor makes every compliance call.

01

Scoping Call

We identify which regulations actually apply to your business — GLBA, HIPAA, PCI-DSS, or a combination — and build a control checklist specific to your organization.

02

Evidence Intake

You submit documents, policy exports, and system evidence through a secure process. Every item is logged for a clear chain of custody, with a status dashboard showing coverage at a glance.

03

Structured Assessment

Our proprietary audit technology checks your evidence against every applicable control and flags gaps for review. It reports observations only — never conclusions — labelled "Preliminary Assessment — Auditor Judgment Required".

04

Auditor Review & Sign-Off

Ram personally reviews every control, resolves any ambiguous findings, and signs the final report — the one your regulator, insurer, or enterprise customer will actually see.

Auditor Independence — Always

In line with ISACA and IIA professional standards, all compliance determinations, materiality assessments, and audit opinions rest exclusively with Ram Dudeja. Automated tools report observations. The auditor decides.

About the Auditor

Ram Dudeja

US Audit Group is an independent audit and compliance practice. Ram brings 39 years of banking internal audit, IS audit, and fraud-investigation experience to every engagement. Every deliverable — regardless of which specialists on our delivery bench execute the technical work — is personally scoped, reviewed, and signed off by Ram before it reaches you.

CISA
Certified Information Systems Auditor — ISACA
39 Years
Banking, IS audit & fraud investigation
Ex-SBI AGM
General Manager (Vigilance), State Bank of India
ISACA / IIA
Member — follows IS Audit professional standards

US Audit Group

United States  ·  [email protected]
usauditgroup.com

Audit Coverage

Three frameworks, one audit discipline

Every engagement checks your business against the specific rulebook that applies to it — GLBA, HIPAA, or PCI-DSS — using real evidence, not a checkbox questionnaire.

  • GLBA — FTC Safeguards Rule compliance
  • GLBA — customer data flow mapping
  • HIPAA — Administrative, Physical & Technical safeguards
  • HIPAA — PHI data flow & Business Associate (BAA) gap check
  • PCI-DSS — cardholder data environment scoping
  • PCI-DSS — SAQ type determination & readiness
  • Vendor & third-party risk review
  • Technical security testing, coordinated end-to-end
3
Frameworks assessed
39
Years of experience
CISA
ISACA-certified lead
Get in Touch

Start your compliance assessment today

Send an inquiry and Ram will respond within one business day. No sales team, you speak directly with the auditor from day one.

Send an Inquiry

Please verify your email above before submitting.

Responds within 1 business day · No spam · Strictly confidential