← Back to Home

Internal Policies

Anaza Advisory Inc. · We practice what we advise

As a privacy, security, and compliance advisory firm, we hold ourselves to the same standard of governance we build for our clients. Anaza Advisory maintains an internal policy framework aligned with recognized standards including ISO 27001, SOC 2, PIPEDA, PHIPA, GDPR, and HIPAA safeguard requirements. Policies are reviewed at least annually, approved by leadership, and reinforced through role based training.

Our Policy Framework

Information Security Policy

Defines our overall security objectives, governance structure, risk appetite, and the administrative, technical, and physical safeguards protecting our systems and client information.

Data Protection & Privacy Policy

Governs the collection, use, retention, and disposal of personal information in line with PIPEDA, PHIPA, GDPR, and applicable jurisdictional requirements, embedding privacy by design in how we work.

Access Control & Acceptable Use Policy

Enforces least privilege access, multi-factor authentication, and clear rules for acceptable use of systems, devices, and collaboration tools used in client engagements.

Client Confidentiality & Data Handling Policy

Establishes classification, encryption, secure transfer, and segregation requirements for client materials, including regulated data such as PHI and PII, throughout the engagement lifecycle.

Incident Response & Breach Notification Policy

Defines our structured process for detecting, containing, investigating, and reporting security incidents, including notification obligations to affected clients and regulators.

Vendor & Third Party Risk Management Policy

Requires due diligence, contractual safeguards, and periodic review of the tools and service providers in our own supply chain, including GRC platforms and cloud infrastructure.

Business Continuity & Resilience Policy

Ensures continuity of client service through backup, recovery, and contingency arrangements proportionate to the criticality of engagement commitments.

Records Retention & Disposal Policy

Sets defined retention periods for engagement records and mandates secure, verifiable disposal of information that no longer serves a business or legal purpose.

Code of Conduct, Ethics & Independence Policy

Commits our team to professional integrity, objectivity, conflict of interest disclosure, and independence in every advisory relationship.

Security Awareness & Training Policy

Requires ongoing, role based privacy and security training for all personnel, reflecting the same programs we design for clients.

Requesting Policy Information

Summaries of specific policies, or evidence of our internal practices relevant to a due diligence or vendor assessment process, are available to clients and prospective clients under NDA. Contact hasan@anazaadvisory.com to request documentation.