Readiness, and the evidence that makes it real
A framework is a list of things somebody will eventually ask you to prove. Readiness work is the part before that: deciding which instrument actually applies, what it requires in substance rather than in summary, and what artifact in your own systems would satisfy a reader who does not take your word for it.
Which instrument applies is the first question, not a detail
The single most common error in circulation on Canadian privacy is treating BC PIPA, PIPEDA and FIPPA as one regime. They are not. BC PIPA imposes no mandatory privacy-breach notification duty; PIPEDA does, on the real-risk-of-significant-harm test; FIPPA binds BC public bodies. Which one applies to an organization decides what it has to do, and a readiness program built on the wrong one is work spent in the wrong place.
The instrument-to-control map sets out the provisions themselves, quoted from the official consolidations at BC Laws and Justice Laws, with the control and the evidence beside each one.
What readiness work produces
Readiness work produces a record: the instrument, the control put against it, and the artifact in your own systems that shows the control is real. That record is what a questionnaire, an insurance application or an assessor is asking for, and it is the thing that survives the person who wrote it leaving.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Who issues the report or the certificate at the end?
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs.
Is this legal advice?
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
What does readiness work actually produce?
Readiness work produces a record: the instrument, the control put against it, and the artifact in your own systems that shows the control is real.
Start from the document on your desk
Send the questionnaire, the framework or the customer requirement that started this; the reply says what a scope for it would cover.
Readiness work and reference material
Readiness
SOC 2 and ISO 27001
The preparation, done properly: scope, gaps, evidence that accumulates as a by-product of the work, and a remediation plan sequenced to the deal clock.
PCI, HIPAA and CPCSC
Three frameworks nobody chooses voluntarily — scope, gaps, evidence and a remediation plan, with the issuer of each outcome named plainly.
Canadian privacy readiness
Which instrument reaches you, what it actually requires, and the inventory, assessments and retention work that follow from the answer.
Privacy operations
Privacy impact assessments
Data flows, purpose, legal authority, risks, mitigations and residual risk, written up for sign-off under the regime that applies to you.
FIPPA PIAs and ISAs
FIPPA privacy impact assessments, information-sharing agreements and FOI-readiness of systems, for BC public bodies and their suppliers.
Records management and retention
Retention schedules, file classification plans and electronic records configuration, so records are kept as long as required, found when asked for, and disposed of defensibly.
The Evidence Pack
A two-week fixed-scope engagement that answers a questionnaire or insurance application with a written record behind every answer.
Worked exemplar
How a finding is written up, shown against a deliberately vulnerable public application. A specimen, not client work.
Instrument-to-control map
Which instrument applies, what it requires in substance, the control put against it, and the evidence that shows the control is real.