GRC & AI Governance Consulting

Your trusted partner
for compliance
that scales.

Dera Delune Consulting helps Canadian organizations build GRC and AI governance programs that are audit-ready, regulator-facing, and built to grow — including SOC 2, ISO 27001, PIPEDA, and AI governance readiness.

Take the Free Assessment →
50+
Frameworks covered
8
Compliance domains
6
Service areas
🛡️
SOC 2 & ISO 27001
End-to-end audit readiness from gap assessment to certification.
🤖
AI Governance
EU AI Act, NIST AI RMF, ISO 42001, and Canada AIDA compliance programs.
🔐
Privacy Compliance
PIPEDA, GDPR, Quebec Law 25 — data mapping, breach response, and DSARs.
📋
Fractional GRC
Senior GRC expertise embedded in your team — without the full-time hire.
SOC 2 Readiness
ISO 27001 Implementation
AI Governance Programs
PIPEDA & GDPR Compliance
Fractional GRC Support
Risk Management
Why Dera Delune

Compliance built for
organizations that are growing.

🎯
Audit-Ready Focus
Every engagement is designed with your first external audit in mind. We do not just document — we prepare you to pass.
🇨🇦
Canadian Expertise
Deep knowledge of Canadian regulations — PIPEDA, Quebec Law 25, OSFI, FINTRAC — alongside global frameworks.
Without the Overhead
Senior GRC expertise at a fraction of the cost of a full internal team. Scalable engagement models that fit your stage.
Our Services

Six disciplines.
One trusted partner.

From your first compliance assessment to ongoing fractional GRC support, Dera Delune Consulting covers every stage of your compliance journey.

01
GRC Readiness Assessment
A comprehensive review of your compliance posture across 50+ global frameworks.
02
SOC 2 Readiness Program
End-to-end preparation for SOC 2 Type I and Type II audits.
03
ISO 27001 Implementation
Full implementation support from gap analysis to certification audit.
04
AI Governance Program
Governance frameworks for AI systems aligned to NIST AI RMF, EU AI Act, and ISO 42001.
05
Fractional GRC Support
An experienced GRC professional embedded in your team on a retainer basis.
06
Privacy Compliance
PIPEDA, Quebec Law 25, GDPR, and HIPAA compliance programs built for your context.
Not sure where your gaps are?

Take our free GRC and AI Governance readiness assessment. Answer 40 questions across 8 compliance domains and receive your score, your applicable laws, and your 5 most critical gaps — instantly.

Take the Free Assessment →
What We Do

Our Services

Comprehensive GRC and AI Governance consulting across six practice areas — tailored to your industry, size, and regulatory obligations.

01
GRC Readiness Assessment
Free Tool Available

A comprehensive assessment of your compliance posture across 8 domains and 50+ global frameworks. We identify exactly which laws apply to your organization, score your current maturity, and deliver a prioritized gap analysis with a 90-day action plan. Available as a free self-service tool or as a facilitated engagement with a detailed consulting report.

What's included
Compliance maturity score across 8 domains
Full list of applicable laws and frameworks by jurisdiction
Top 5 critical gaps with fine amounts and business impact
Personalized 90-day action plan
12-month roadmap to audit readiness
Take the Free Assessment →
02
SOC 2 Readiness Program
Most Requested

SOC 2 is the de facto standard for enterprise B2B software companies in North America. We prepare your organization for SOC 2 Type I and Type II audits — from initial gap assessment through policy development, control implementation, evidence collection, and auditor engagement. We do the heavy lifting so your team can stay focused on building your product.

What's included
SOC 2 gap assessment against all five Trust Service Criteria
Policy and procedure development
Control design and implementation guidance
Evidence collection framework and audit-ready documentation
Auditor selection support and pre-audit readiness review
SOC 2 Type ISOC 2 Type IIAICPA TSCNIST CSF
03
ISO 27001 Implementation
International Standard

ISO 27001 certification demonstrates to customers, regulators, and partners that your organization manages information security systematically. We guide you through every phase of implementation — from gap analysis and risk assessment through the Statement of Applicability, Annex A control implementation, internal audit, and Stage 1 and Stage 2 certification audits.

What's included
ISO 27001:2022 gap analysis and risk register
Statement of Applicability (SoA) development
Annex A control implementation across all 93 controls
Internal audit and management review facilitation
Certification body selection and audit preparation
ISO 27001:2022Annex AISO 27002ISO 27701
04
AI Governance Program
Emerging Requirement

Organizations deploying or procuring AI systems face growing regulatory and commercial pressure to demonstrate responsible governance. We build AI governance programs aligned to the major frameworks — NIST AI RMF, ISO 42001, the EU AI Act, and Canada's AIDA — covering AI policy, system inventory, risk assessment, human oversight, and transparency reporting.

What's included
AI system inventory and risk classification
AI governance policy and acceptable use framework
EU AI Act risk tier assessment and compliance roadmap
Bias, fairness, and explainability assessment processes
Human oversight and accountability structures
NIST AI RMFISO 42001EU AI ActCanada AIDA
05
Fractional GRC Support
Retainer Based

Not every organization needs a full-time Chief Compliance Officer — but every organization needs someone owning compliance. Our fractional GRC service embeds an experienced compliance professional into your team on a part-time, retainer basis. We own your compliance program so your leadership can focus on growth.

What's included
Ongoing compliance program management and oversight
Policy maintenance, review cycles, and staff attestation
Vendor risk management and third-party assessments
Regulatory change monitoring and impact assessment
Board and leadership compliance reporting
Monthly RetainerFlexible HoursBoard Reporting
06
Privacy Compliance
Canadian & Global

Privacy compliance is no longer optional. Whether you are subject to PIPEDA, Quebec Law 25, GDPR, or HIPAA, we build the privacy program your organization needs — data mapping, consent management, breach response procedures, privacy impact assessments, and data subject request processes.

What's included
Data inventory and data flow mapping
Privacy policy and consent mechanism review
Privacy Impact Assessment (PIA) and DPIA facilitation
Breach notification procedures and regulator contact mapping
Data Subject Access Request (DSAR) process design
HIPAA Privacy Rule and Security Rule compliance programs for health data
PIPEDAQuebec Law 25GDPRHIPAACPRAPHIPA (Ontario)
Ready to get started?

Book a free 30-minute strategy call and we will identify the right service for your organization's needs and compliance stage.

About Us

About Dera Delune Consulting

GRC and AI Governance expertise built for organizations that are scaling, regulated, and serious about compliance.

"Dera Delune is your go-to for security, GRC, and AI governance — built for Canadian organizations that cannot afford to get compliance wrong."
Our Mission

Dera Delune Consulting was founded to address a clear gap in the market: Canadian startups and growing organizations are deploying AI, handling personal data, and chasing enterprise clients — without the compliance programs those clients and regulators require.

We bring senior GRC and AI Governance expertise to organizations that need it, without the overhead of a full internal compliance team. From your first gap assessment to your first external audit, we are with you every step of the way.

Based in Ontario, Canada. Serving clients across Canada.

Our Values

What we stand for.

🎯
Precision
We do not produce generic compliance documents. Every deliverable is tailored to your industry, your size, your jurisdictions, and your regulatory obligations.
🤝
Partnership
We work alongside your team — not above it. We transfer knowledge and build internal capability so your compliance program outlasts our engagement.
🔍
Transparency
We tell you what your gaps are, what the risks are, and what it will take to close them — clearly and without jargon.
Urgency
Compliance gaps have real consequences — lost deals, regulatory fines, and reputational harm. We move with the urgency the stakes demand.
🌐
Global Reach
Canadian expertise. Global coverage. We understand the regulatory landscape across Canada, the US, the EU, and beyond.
📈
Growth Minded
Compliance is not a blocker — it is a growth enabler. SOC 2 and ISO 27001 open enterprise sales doors. We help you get there.
The Dera Delune Group

A growing family
of organizations.

Dera Delune Consulting is the first entity under the Dera Delune Group — a growing structure of purpose-driven organizations in compliance, governance, and social impact.

Live Now
Dera Delune Consulting
GRC and AI Governance consulting for Canadian startups and growing organizations. SOC 2, ISO 27001, PIPEDA, AI governance, fractional GRC support.
Coming Soon
Dera Delune Foundation
A social impact arm focused on governance, accountability, and safety. More details to be announced.
Credentials

Our qualifications.

Our team holds recognized certifications across cybersecurity, GRC, cloud security, and AI governance.

CompTIA Security+
CompTIA CASP+
Google Cybersecurity Certificate
AWS Cloud Security
GRC Bootcamp
AI Governance Bootcamp
Let's work together.

Book a free 30-minute strategy call and tell us about your compliance needs. We will identify the right path forward for your organization.

Get in Touch

Contact Us

We are here to help. Reach out through any of the channels below or book a free 30-minute strategy call directly.

Contact Information
General Enquiries
Consulting Engagements
Book a Free Strategy Call
A free 30-minute call with our team. We will review your compliance gaps and identify the right path forward — no commitment required.
Book on Calendly →
Location Ontario, Canada
Serving clients across Canada and internationally.
Send Us a Message
Fill in the form below and we will respond within one business day.
Thank you. Your message has been sent. We will be in touch within one business day.