SEPTEMBER 19, 2026

One Subsidiary's Success Became an Enterprise Standard

A large multinational healthcare organization had already seen what modern GRC automation could do inside one of its subsidiaries. The question was whether it could replicate that success across a more complex, multi-country structure spanning Colombia and Mexico. The answer was yes, but getting there required navigating one of the more demanding cross-border procurement paths in recent memory: committee approvals, pricing parity disputes, tax documentation, and a signer process that moved on its own timeline. The platform was never in doubt. Everything else was.

[ The Problem ]

Compliance Operations Built for One Country, Stretched Across Many

The organization was managing audit evidence, risk workflows, and compliance obligations across multiple countries using email threads and spreadsheets. Fragmented, manual audit preparation was the operational reality for a team responsible for ISO 27001, SOC 2, and PCI readiness simultaneously.

The deeper problem was structural: there was no centralized GRC model that could separate evidence by country, support multiple entities, and scale without adding headcount. Without a platform decision, every new compliance obligation meant more manual coordination, more risk of inconsistency, and less time for the security team to focus on actual control management.

[ What they needed ]

The security and procurement teams were working to:

  • Standardize GRC operations across a multi-country, multi-entity organization
  • Reduce reliance on email and spreadsheets for evidence collection and audit workflows
  • Support simultaneous progress on ISO 27001, SOC 2, and PCI DSS
  • Separate compliance evidence by country where regulatory or operational boundaries required it
  • Replicate a proven internal deployment model at enterprise scale
  • Stay within an allocated budget window to avoid triggering a new approval cycle
  • Build a foundation for future frameworks including HIPAA and additional regional requirements

[ Why Drata won ]

An existing internal deployment removed technical skepticism entirely, making Drata the default standardization candidate before the evaluation formally began.

  1. Internal proof point eliminated platform risk: a subsidiary's live Drata deployment gave the parent organization direct evidence that the platform could support its operating model. The conversation was never about whether Drata could work; it was about how to scale what was already working.

  2. Multi-workspace architecture matched the actual org structure: the ability to separate evidence and workflows by country was not a nice-to-have. It was a prerequisite for a multi-entity buyer managing compliance obligations across Colombia and Mexico under different regulatory contexts.

  3. Breadth of framework coverage supported a platform decision, not a point solution: ISO 27001, SOC 2, PCI DSS, and a credible roadmap to HIPAA meant the organization could consolidate its entire compliance program rather than procure separate tools for each certification.

  4. Commercial persistence preserved the win through a complex procurement cycle: pricing alignment to the internal reference deployment, payment-term flexibility, and proactive documentation support kept the deal moving through committee approvals, legal review, and cross-border tax mechanics that could have broken it.

[ How Drata solved it ]

Drata's multi-workspace architecture gave the organization a direct answer to its most pressing structural problem: the ability to separate evidence and compliance workflows by country without fragmenting the overall GRC program. That aligned precisely with the need to manage Colombia and Mexico operations under a single platform while maintaining appropriate boundaries between entities.

Drata's automated evidence collection connected to the organization's existing stack, including Azure AD, Microsoft Azure, Jira, and GitHub, replacing manual audit preparation with continuous, automated control monitoring. The security team could redirect capacity from inbox management to actual compliance work.

Audit Hub gave the team a structured path to SOC 2 and ISO 27001 readiness that was credible enough to present to internal stakeholders and external auditors alike. Combined with PCI DSS support, the platform covered the full scope of the organization's immediate certification roadmap in a single deployment.

[ Before and after Drata ]

Before Drata, the security team managed audit evidence and compliance workflows manually across multiple countries, with no centralized platform and no way to separate obligations by entity without duplicating effort.

After, automated evidence collection runs continuously against the existing cloud stack, and the organization has a single GRC platform supporting its full certification roadmap across entities and geographies.

Before Drata
After Drata
Before DrataAudit evidence managed through email and spreadsheets across Colombia and Mexico with no centralized system
After DrataCentralized GRC platform with multi-workspace architecture managing evidence across entities and countries in a single deployment
Before DrataNo path to simultaneous ISO 27001, SOC 2, and PCI readiness without significant manual coordination overhead
After DrataSOC 2, ISO 27001, and PCI DSS readiness running in parallel on a structured, auditor-ready timeline
Before DrataCompliance obligations siloed by country with no shared platform to enforce consistency or separate evidence where required
After DrataCountry-level evidence separation built into the platform architecture, meeting regulatory and operational boundaries without manual workarounds
Before DrataSecurity team capacity consumed by repetitive audit preparation instead of control management
After DrataAutomated evidence collection connected to Azure AD, Microsoft Azure, Jira, and GitHub, replacing manual audit workflows
Before DrataGRC standardization aspirational across the parent organization, with no replicable model beyond one subsidiary
After DrataSubsidiary deployment model formalized as the enterprise standard, with HIPAA and additional regional workspaces already in the expansion roadmap

[ Business outcome ]

The organization closed its first enterprise GRC deployment covering SOC 2, ISO 27001, and PCI DSS across its primary operating entities, with a clear expansion path to HIPAA and additional country workspaces already scoped.

Manual audit operations gave way to automated evidence collection tied directly to the existing cloud and development stack, freeing the security team from the coordination overhead that had defined compliance work before. The internal reference model that had proven itself inside one subsidiary became the operational standard for the broader organization, reducing adoption risk and accelerating the path to a centralized compliance posture across multiple countries.

More Wins to Explore