JULY 27, 2026

A Merger, a Board Deadline, and Ten Days to Close

When a 50-person construction company began consolidating operations across North America and Europe through a multi-entity merger, its compliance function was suddenly responsible for a scope it had never been built to handle. Spreadsheets and manual uploads to contractor portals were consuming staff time the company did not have, and a board meeting was weeks away. With a hard deadline, a well-prepared compliance lead, and a clear picture of what automation needed to deliver, the company moved from first conversation to signed contract in ten days.

[ The Problem ]

Manual compliance tracking that worked for one entity was breaking under the weight of three.

The merger forced the company to consolidate compliance, HR, and safety processes across US and Canadian operations simultaneously, with EU and Brazil expansion already on the roadmap. Every client portal requirement — across ISNetworld, Avetta, Ariba, and Veriforce — was being handled manually, consuming disproportionate staff time for a 50-person organization.

Field workers in safety-sensitive roles could not be deployed without verified training and current certifications. Without a centralized system, that verification was a manual process, creating not just compliance risk but direct operational risk: workers idled and projects delayed. The merger also introduced a rebranding element, with email domains and legal entity names in flux, adding configuration complexity that not every platform could absorb on a compressed timeline.

The board meeting created a hard deadline. A compliance platform decision needed to be budgeted and presented to leadership before year-end, and the cost of inaction was measured in both organizational credibility and operational continuity.

[ What they needed ]

The compliance lead arrived at the first conversation with a detailed requirements list already in hand.

  • Automate evidence collection and tracking across multiple client compliance portals
  • Map custom frameworks to contractor portal requirements without manual re-entry
  • Support multi-entity, multi-geography workspace architecture for a company mid-merger
  • Integrate with HRIS systems across Canadian and US operations
  • Enable daily client-facing compliance fulfillment without pulling staff into repetitive manual tasks
  • Prepare for ISO 27001 certification to support international expansion
  • Accommodate company rebranding and domain migration without re-platforming

[ Why Drata won ]

Selected over Vanta, the combination of Trust Center's browser extension compatibility with the compliance lead's daily workflow and the responsiveness of the sales engagement made Drata the clear choice before a formal bake-off could begin.

  1. Trust Center browser extension fit the actual workflow: the compliance lead's primary daily burden was responding to client portal requests across ISNetworld, Avetta, and Ariba. The browser extension mapped directly to that task in a way that made the value immediately tangible, not theoretical.

  2. Sales execution signaled post-sale quality: the buyer explicitly cited the depth of technical knowledge and responsiveness demonstrated during the evaluation as a reason for choosing Drata. For a company entering compliance automation for the first time, the quality of the human relationship was weighted as heavily as the platform capability.

  3. Mid-cycle scope pivot absorbed without losing momentum: when the company's president redirected the framework priority to ISO 27001, a revised quote was delivered within hours. That responsiveness converted what could have been a multi-week delay into a same-week close.

  4. Custom framework flexibility covered a non-standard ICP: contractor compliance portals are not a typical GRC use case, but Drata's custom framework mapping meant the platform could accommodate ISNetworld and Avetta requirements alongside ISO 27001, removing the need for a separate point solution.

[ How Drata solved it ]

Drata's GRC platform addressed the core requirement directly: automated compliance tracking with custom framework support for the contractor portals driving the company's day-to-day client obligations. Trust Center, with its browser extension compatibility, mapped to the compliance lead's actual daily workflow — responding to client portal requests without manual uploads or context-switching.

The workspace architecture supported the company's multi-geography structure, with a primary North American environment and a deferred EU workspace priced to activate as the merger progressed. When the company's president redirected the framework priority from SOC 2 to ISO 27001 mid-cycle based on international recognition value, Drata's flexibility absorbed the pivot without requiring a new evaluation. A revised quote was turned around within the same email thread, and the deal continued moving.

For the gap between Drata's native capability and the company's field worker certification requirements, an Open API path was scoped as the integration bridge, giving the compliance team a clear technical roadmap rather than a dead end. Audit cost clarity — correcting the buyer's assumption of $15,000 to $30,000 in audit fees down to the actual $5,000 to $7,000 range for an organization of this size — removed a significant commercial objection and reinforced confidence in the platform's fit.

[ Before and after Drata ]

Before Drata, a 50-person company managing compliance across multiple entities and contractor portals was doing it entirely by hand, with no centralized system and no path to ISO 27001 certification. After, automated tracking handles routine client portal requirements, the ISO 27001 audit path is defined and scheduled, and the platform architecture is built to expand into the EU and Brazil as the merger completes.

Before Drata
After Drata
Before DrataCompliance evidence for contractor portals collected manually across ISNetworld, Avetta, Ariba, and Veriforce, consuming staff time disproportionate to a 50-person headcount
After DrataTrust Center with browser extension handles routine client portal requests automatically, reducing manual effort to novel or complex requests only
Before DrataNo centralized system for tracking field worker certifications and safety training, creating direct operational risk and potential project delays
After DrataCustom API path scoped to connect field worker certification and safety training platforms, with a defined integration roadmap in place
Before DrataISO 27001 certification aspirational with no defined audit path or timeline
After DrataISO 27001 audit underway with a structured timeline and actual audit cost confirmed at $5,000 to $7,000
Before DrataMulti-entity merger with no platform architecture to support US, Canadian, EU, and Brazil operations under a single compliance program
After DrataMulti-geography workspace architecture live for North America, with EU workspace priced and ready to activate as merger progresses
Before DrataAudit cost assumptions of $15,000 to $30,000 creating a perceived barrier to certification
After DrataAudit cost corrected to $5,000 to $7,000, removing the financial objection that had made certification feel out of reach

[ Business outcome ]

A construction company that had never operated a formal compliance program closed a ten-day evaluation and moved directly into onboarding with a platform built to scale alongside its merger. The manual upload cycle that had consumed staff time across multiple contractor portals was replaced with automated tracking and a Trust Center that handles routine client requests without human intervention.

The ISO 27001 path is now structured and underway, giving the company a certification timeline it can present to international clients and partners as the EU expansion progresses. Contractual protections on expansion pricing mean that adding workspaces for new geographies carries no pricing uncertainty. The compliance function that was breaking under merger complexity now has the architecture to grow with the organization rather than behind it.