Is Your Business Actually Compliant?
Independent compliance risk assessments for US banks, credit unions, healthcare SaaS, and payment-accepting businesses — backed by real technical testing, not a policy checkbox. Led personally by a CISA-certified auditor.
Compliance expectations are rising.
Are you ready?
GLBA's Safeguards Rule applies to any non-bank financial company, not just banks
HIPAA Security Rule violations carry real financial and reputational risk for healthcare SaaS
PCI-DSS compliance is mandatory for any business that accepts card payments
Enterprise customers and cyber insurers increasingly require proof of compliance before they'll sign
Choose the framework that applies to you
Every engagement is auditor-led and individually scoped. Request a consultation for a quote tailored to your organization's size and complexity.
GLBA Compliance Risk Assessment
Full Safeguards Rule gap assessment for financial institutions
- Safeguards Rule gap assessment scorecard
- Customer data flow mapping
- Vendor & third-party review
- Technical security testing, coordinated through our delivery network
- Board-ready report for regulators & leadership
- Prioritized remediation roadmap
HIPAA Security Risk Assessment
Security Rule readiness assessment, not a certification claim
- HIPAA Security Rule gap assessment (Administrative, Physical, Technical)
- PHI data flow mapping
- Business Associate & BAA gap check
- Technical security testing, coordinated through our delivery network
- Written risk assessment report for customers, investors & insurers
- Prioritized remediation roadmap
PCI-DSS Readiness Assessment
Cardholder-data compliance readiness, not a formal QSA attestation
- Gap assessment against the 12 PCI-DSS requirements
- Cardholder data flow mapping
- SAQ type determination & readiness support
- Technical security testing, coordinated through our delivery network
- Written readiness report
- Prioritized remediation roadmap
Every engagement is scoped individually based on organization size, data volume, and complexity. Not a law firm, CPA firm, or QSA — engagements are risk assessments and readiness reviews, not formal certifications or attestations.
From evidence to signed report
A structured, repeatable 4-step process. Our audit technology does the heavy lifting — the auditor makes every compliance call.
Scoping Call
We identify which regulations actually apply to your business — GLBA, HIPAA, PCI-DSS, or a combination — and build a control checklist specific to your organization.
Evidence Intake
You submit documents, policy exports, and system evidence through a secure process. Every item is logged for a clear chain of custody, with a status dashboard showing coverage at a glance.
Structured Assessment
Our proprietary audit technology checks your evidence against every applicable control and flags gaps for review. It reports observations only — never conclusions — labelled "Preliminary Assessment — Auditor Judgment Required".
Auditor Review & Sign-Off
Ram personally reviews every control, resolves any ambiguous findings, and signs the final report — the one your regulator, insurer, or enterprise customer will actually see.
Auditor Independence — Always
In line with ISACA and IIA professional standards, all compliance determinations, materiality assessments, and audit opinions rest exclusively with Ram Dudeja. Automated tools report observations. The auditor decides.
Ram Dudeja
US Audit Group is an independent audit and compliance practice. Ram brings 39 years of banking internal audit, IS audit, and fraud-investigation experience to every engagement. Every deliverable — regardless of which specialists on our delivery bench execute the technical work — is personally scoped, reviewed, and signed off by Ram before it reaches you.
US Audit Group
United States · [email protected]
usauditgroup.com
Three frameworks, one audit discipline
Every engagement checks your business against the specific rulebook that applies to it — GLBA, HIPAA, or PCI-DSS — using real evidence, not a checkbox questionnaire.
- GLBA — FTC Safeguards Rule compliance
- GLBA — customer data flow mapping
- HIPAA — Administrative, Physical & Technical safeguards
- HIPAA — PHI data flow & Business Associate (BAA) gap check
- PCI-DSS — cardholder data environment scoping
- PCI-DSS — SAQ type determination & readiness
- Vendor & third-party risk review
- Technical security testing, coordinated end-to-end
Start your compliance assessment today
Send an inquiry and Ram will respond within one business day. No sales team, you speak directly with the auditor from day one.
