Dera Delune Consulting helps Canadian organizations build GRC and AI governance programs that are audit-ready, regulator-facing, and built to grow — including SOC 2, ISO 27001, PIPEDA, and AI governance readiness.
From your first compliance assessment to ongoing fractional GRC support, Dera Delune Consulting covers every stage of your compliance journey.
Comprehensive GRC and AI Governance consulting across six practice areas — tailored to your industry, size, and regulatory obligations.
A comprehensive assessment of your compliance posture across 8 domains and 50+ global frameworks. We identify exactly which laws apply to your organization, score your current maturity, and deliver a prioritized gap analysis with a 90-day action plan. Available as a free self-service tool or as a facilitated engagement with a detailed consulting report.
SOC 2 is the de facto standard for enterprise B2B software companies in North America. We prepare your organization for SOC 2 Type I and Type II audits — from initial gap assessment through policy development, control implementation, evidence collection, and auditor engagement. We do the heavy lifting so your team can stay focused on building your product.
ISO 27001 certification demonstrates to customers, regulators, and partners that your organization manages information security systematically. We guide you through every phase of implementation — from gap analysis and risk assessment through the Statement of Applicability, Annex A control implementation, internal audit, and Stage 1 and Stage 2 certification audits.
Organizations deploying or procuring AI systems face growing regulatory and commercial pressure to demonstrate responsible governance. We build AI governance programs aligned to the major frameworks — NIST AI RMF, ISO 42001, the EU AI Act, and Canada's AIDA — covering AI policy, system inventory, risk assessment, human oversight, and transparency reporting.
Not every organization needs a full-time Chief Compliance Officer — but every organization needs someone owning compliance. Our fractional GRC service embeds an experienced compliance professional into your team on a part-time, retainer basis. We own your compliance program so your leadership can focus on growth.
Privacy compliance is no longer optional. Whether you are subject to PIPEDA, Quebec Law 25, GDPR, or HIPAA, we build the privacy program your organization needs — data mapping, consent management, breach response procedures, privacy impact assessments, and data subject request processes.
GRC and AI Governance expertise built for organizations that are scaling, regulated, and serious about compliance.
Dera Delune Consulting was founded to address a clear gap in the market: Canadian startups and growing organizations are deploying AI, handling personal data, and chasing enterprise clients — without the compliance programs those clients and regulators require.
We bring senior GRC and AI Governance expertise to organizations that need it, without the overhead of a full internal compliance team. From your first gap assessment to your first external audit, we are with you every step of the way.
Based in Ontario, Canada. Serving clients across Canada.
Dera Delune Consulting is the first entity under the Dera Delune Group — a growing structure of purpose-driven organizations in compliance, governance, and social impact.
Our team holds recognized certifications across cybersecurity, GRC, cloud security, and AI governance.
We are here to help. Reach out through any of the channels below or book a free 30-minute strategy call directly.
Dera Delune Consulting ("Dera Delune Consulting") is committed to protecting your privacy. This Privacy Policy explains how Dera Delune Consulting collects, use, and safeguard information when you visit the Dera Delune Consulting website at deradelune.com or engage Dera Delune Consulting services.
Dera Delune Consulting may collect the following types of information:
We use the information Dera Delune Consulting collects to:
Dera Delune Consulting does not sell, rent, or share your personal information with third parties for marketing purposes.
Dera Delune Consulting is a Canadian business subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect and use personal information only with your knowledge and consent, or as otherwise permitted by law. You may withdraw consent at any time by contacting Dera Delune Consulting.
Dera Delune Consulting retains your personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. When information is no longer needed, we delete or anonymize it securely.
Dera Delune Consulting uses a small number of trusted third-party tools to operate the Dera Delune Consulting website:
Each of these providers has their own privacy policy governing how they handle data.
You have the right to access, correct, or request deletion of your personal information. To exercise these rights, contact Dera Delune Consulting at hello@deradelune.com. Dera Delune Consulting will respond within 30 days.
Dera Delune Consulting takes reasonable technical and organizational measures to protect your information from unauthorized access, disclosure, or loss. However, no method of transmission over the internet is 100% secure.
Dera Delune Consulting may update this Privacy Policy from time to time. Dera Delune Consulting will notify you of material changes by updating the effective date at the top of this page.
For questions about this Privacy Policy, please contact Dera Delune Consulting at:
Dera Delune Consulting
Ontario, Canada
hello@deradelune.com
Welcome to Dera Delune Consulting. By accessing or using the Dera Delune Consulting website at deradelune.com (the "Site"), you agree to be bound by these Terms of Use. If you do not agree, please do not use the Site.
You may use this Site for lawful purposes only. You agree not to:
All content on this Site — including text, graphics, logos, and assessment tools — is the property of Dera Delune Consulting and is protected by applicable intellectual property laws. Nothing on this Site grants you any license or right to use Dera Delune Consulting content without express written permission.
Our GRC and AI Governance Readiness Assessment is provided for informational purposes only. Results generated by the tool do not constitute legal, regulatory, or professional compliance advice. You should consult a qualified professional before making compliance decisions based on assessment results.
Use of this website does not create a consulting or professional-client relationship between you and Dera Delune Consulting. A formal engagement is only established through a signed service agreement.
This Site and its content are provided "as is" without warranties of any kind, express or implied. We do not warrant that the Site will be uninterrupted, error-free, or free of viruses or other harmful components.
To the fullest extent permitted by applicable law, Dera Delune Consulting shall not be liable for any indirect, incidental, special, or consequential damages arising from your use of or inability to use the Site or its content.
The Site may contain links to third-party websites. We are not responsible for the content, accuracy, or practices of those sites. Links do not constitute endorsement.
These Terms of Use are governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Any disputes shall be subject to the exclusive jurisdiction of the courts of Ontario.
Dera Delune Consulting reserves the right to update these Terms of Use at any time. Continued use of the Site after changes are posted constitutes your acceptance of the revised terms.
For questions about these Terms, please contact Dera Delune Consulting at:
Dera Delune Consulting
Ontario, Canada
hello@deradelune.com