MODULE IRED-CMP-01
COMPLIANCE FRAMEWORK
Regulatory Compliance

Governed by rules.
Driven by trust.

IRED-TECH operates under a strict multi-framework compliance programme. Every process — from procurement to post-sale support — is designed, audited and maintained in accordance with internationally recognised standards, ensuring accountability across every level of our operations.

ISO 27001
Certified
Information Security Management System
Audited annually by accredited third party
Active Frameworks // Enforced
GDPR — General Data Protection Regulation (EU) 2016/679
Active
ISO 27001 — Information Security Management
Certified
SOC 2 Type II — Security, Availability & Confidentiality
Attested
NIST CSF — Cybersecurity Framework v1.1
Aligned
PCI DSS — Payment Card Industry Data Security Standard
Compliant
Risk Assessment

Structured risk identification, evaluation and mitigation cycles conducted on a quarterly basis across all business units.

Audit Trail

Immutable event logging for all critical system actions, policy changes, and data access events with tamper-evidence controls.

Access Control

Role-based access management with least-privilege enforcement and multi-factor authentication on all internal systems.

Incident Response

Documented IR procedures with defined SLAs, escalation paths and mandatory breach notification within 72 hours per GDPR Article 33.

Certification

Third-party audit certifications reviewed and renewed on a scheduled basis with findings remediated within agreed timelines.

CHIEF COMPLIANCE OFFICER // DIRECT
Compliance inquiries & regulatory requests
Include your organisation name, the relevant regulatory framework, and a detailed description of your inquiry. Our CCO team will respond within 5 business days. For urgent regulatory matters, escalate via your designated account manager.
!
REGULATORY SCOPE NOTICE: this compliance framework applies to all operations, subsidiaries and third-party processors engaged by IRED-TECH. Vendor onboarding requires mandatory completion of our Supplier Compliance Assessment prior to any data exchange or system integration. Non-compliant suppliers will be suspended pending remediation.
IRED-TECH // CMP ◆ COMPLIANCE FRAMEWORK