JULY 19, 2026

Spun Out, Exposed, and Racing to Certify

When a fintech subsidiary was carved out from its parent bank's compliance umbrella, it inherited a hard deadline and nothing else: no policies, no dedicated security resource, and no SOC 2 of its own. The team needed a compliance platform that could model a subsidiary structure today and grow into a multi-entity architecture tomorrow. After a 44-day evaluation across five competing solutions, they chose the only platform whose workspace architecture matched the organizational reality they were actually living in.

[ The Problem ]

The parent bank's SOC 2 no longer covers you. Now what?

The subsidiary's separation from its parent bank removed the compliance shelter it had always relied on. Standing up a SOC 2 Type II certification from scratch meant building policies, collecting evidence, and managing vendor risk with no CISO, no existing program, and a co-mingled Microsoft tenant that complicated every integration decision.

The team's CCO, CTO, and Head of Technology were already stretched. Manual processes were explicitly ruled out as unsustainable at their scale. And for a fintech operating in regulated financial services, the cost of inaction was not inconvenience — it was the inability to function as a standalone entity.

[ What they needed ]

The team needed to accomplish several things simultaneously, with no dedicated compliance staff:

  • Stand up a SOC 2 Type II program from a greenfield starting point
  • Model a subsidiary structure independently while preserving a path to parent-entity governance
  • Integrate with a Microsoft-heavy stack including Azure, Intune, Entra, and DevOps
  • Replace manual policy and evidence workflows the existing tooling could not automate
  • Identify an audit partner with credible credentials for a regulated financial services context
  • Build a compliance foundation extensible to HIPAA, PCI, and NIST as future requirements

[ Why Drata won ]

Selected over Vanta, Drata's multi-workspace architecture was the only solution that cleanly matched the subsidiary carve-out structure the buyer was actually operating in.

  1. Multi-tenancy mapped to the organizational reality: the buyer needed to scope a subsidiary independently today and add a parent entity later without re-architecting. Vanta and every other evaluated platform could not demonstrate equivalent workspace isolation for this specific carve-out model.

  2. Audit partner credibility held under competitive attack: both Vanta and a lower-cost competitor challenged Drata's audit partner quality. Drata countered with AICPA peer review documentation and exposed the economics behind the low-cost alternative, giving the buyer a defensible rationale for the audit path they would eventually present to their banking partner.

  3. Engagement continuity through the holiday window compressed the cycle: while competing vendors went quiet between mid-December and early January, Drata maintained near-daily contact. The relationship equity built during that period survived a month-long legal review that might otherwise have stalled the deal.

  4. Scoping expertise reduced perceived implementation risk: the recommendation to focus exclusively on the subsidiary's tenant and defer the co-mingled parent tenant to a later phase gave the buyer a concrete, low-friction starting point rather than a dependency on an unresolved infrastructure project.

[ How Drata solved it ]

Drata's multi-workspace architecture was the capability that separated it from every other platform in the evaluation. The team could scope the subsidiary as a standalone workspace, pursue SOC 2 independently, and add the parent entity as a separate workspace later — without re-architecting the entire program. No competing solution demonstrated equivalent flexibility for this carve-out model.

Drata's native integrations with Azure, Intune, Azure DevOps, Entra, and Microsoft 365 matched the team's existing stack directly, and a phased scoping recommendation focused on the subsidiary's tenant alone gave the team a pragmatic path forward without waiting for the broader tenant separation to complete.

Drata's AIQA offering and audit partner ecosystem addressed the team's concern about audit credibility head-on, providing access to AICPA peer-reviewed firms and a structured SOC 2 readiness timeline the team could act on immediately. TPRM and the Trust Center extended the platform's value beyond the initial audit scope, positioning Drata as the foundation for the multi-framework program the team was already planning.

[ Before and after Drata ]

Before Drata, the subsidiary had no independent compliance program, no automation, and no audit path — operating entirely under a parent bank's SOC 2 umbrella that would not survive the carve-out. After, the team has a structured SOC 2 program underway, a defined audit timeline, and a workspace architecture that scales to the parent entity without rebuilding from scratch.

Before Drata
After Drata
Before DrataCompliance coverage borrowed from the parent bank. Carve-out would eliminate it entirely with no replacement in place.
After DrataSubsidiary operating under its own independent SOC 2 program. No longer dependent on the parent bank's compliance umbrella.
Before DrataNo SOC 2 program, no policies, no evidence collection. Certification was a requirement with no execution path.
After DrataSOC 2 audit path defined and underway. Audit completion targeted for June 2026.
Before DrataCompliance workload distributed informally across CCO, CTO, and Head of Technology with no dedicated tooling.
After DrataCompliance operations centralized in Drata with a designated owner. Executive bandwidth freed from manual GRC tasks.
Before DrataExisting policy tooling required manual effort and could not automate evidence collection or control monitoring.
After DrataAutomated evidence collection and control monitoring replace manual policy workflows across the Microsoft stack.
Before DrataMulti-entity governance had no viable model. Any future expansion to the parent entity would require re-architecting the compliance program.
After DrataParent entity can be added as a second workspace when the tenant separation completes. No re-architecture required.

[ Business outcome ]

The subsidiary closed a 44-day evaluation and entered its SOC 2 program with a defined audit timeline targeting completion by June 2026. The compliance workload that had been distributed informally across three executives now has a structured platform and a clear owner.

The workspace architecture means the parent entity can be added later without rebuilding the program, preserving the expansion path the team had planned from the start. And by selecting a platform with native Microsoft integrations and a credible audit partner ecosystem, the team positioned itself to operate as a fully independent fintech — not a subsidiary sheltering under someone else's certification.

More Wins to Explore