Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 42% off.
Price
$169
Individually $296 — save 42%
Delivered immediately after checkout — your template and guide links are emailed to you with your receipt.
Built for risk and compliance teams at financial-services organizations
◆ Quick buying summary
What you get and when you can use it
- Good fit if
- You're preparing for a SOC 2 Type 1 or Type 2 audit and need to close gaps across incident response and BCP
- Format
- Editable workbook plus PDF/supporting guide materials where included. Instant download after checkout.
- Time to value
- Start reviewing, editing, and assigning owners the same day; customize to your organization before sharing outputs externally.
- After purchase
- After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account required.
◆ What's included
- ◆ Data Privacy Compliance Kit
- ◆ Incident Response & Breach Notification Kit
- ◆ Business Continuity & Disaster Recovery (BCP/DR) Kit
- ◆ SOC 2 Compliance Checklist
Use rights: customize for internal business use and use outputs with your auditors, customers, bank partners, and regulators. Do not resell or redistribute the template files.
◆ What's in the bundle
Products in this bundle.
Template
Data Privacy Compliance Kit
Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.
View →
Template
Incident Response & Breach Notification Kit
Run an incident and every notice clock it starts: bank partner, the bank regulators' 36-hour rule, NYDFS, FTC, SEC and breach laws in 54 states and territories. Workbook, guide, four playbooks, tabletop kit and Word plan templates.
View →
Template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
View →
Template
SOC 2 Compliance Checklist
151 readiness checks cross-referenced to the AICPA Trust Services Criteria, with evidence collection guidance.
View →
◆ FAQ
Frequently asked questions.
Why do these 4 domains get bundled together?
Data privacy, incident response, BCP/DR, and SOC 2 are interconnected in practice. Your incident response plan should reference your data privacy notification procedures. Your BCP should document the recovery requirements for systems in scope for SOC 2. Your SOC 2 audit will review your incident response and BCP as part of the Availability and Privacy Trust Service Criteria. Having consistent, professionally documented programs across all 4 avoids gaps that show up during audits.
Do these templates cross-reference each other?
In places. State breach notification lives in the Incident Response kit (54 jurisdictions); the Data Privacy Kit covers state privacy laws and the GLBA Safeguards Rule, including its FTC notice, and points to the Incident Response kit for breach notices. The incident response plan template lists your business continuity plan, information security program and third-party risk policy as related documents. The BCP template references SOC 2 Availability controls as recovery requirements. The SOC 2 checklist maps to incident response and BCP procedures as evidence for Availability criteria. They're designed to read as one coherent compliance program.
Is this bundle appropriate for a fintech preparing for its first SOC 2 audit?
Yes — and for most first-time SOC 2 engagements, having strong data privacy, incident response, and BCP documentation materially reduces audit gaps, particularly for the Availability and Privacy Trust Service Criteria. Auditors will ask to see your incident response plan and BCP as part of SOC 2 fieldwork.
Does this bundle cover breach notification in every state?
Yes. The Incident Response & Breach Notification Kit's State Reference covers 54 jurisdictions (50 states, DC, Puerto Rico, Guam and the U.S. Virgin Islands): consumer deadlines, regulator notice thresholds and timing, and credit bureau notice, with a source URL on each row, verified as of September 30, 2026. Confirm obligations with counsel before relying on any deadline.
What if I only need 2 or 3 of these 4 products?
The bundle saves you 42% vs. buying all 4 individually ($296 vs. $169). If you only need 2 products, buying individually is more economical. If you need 3 out of 4, the bundle likely still makes sense given the 42% savings — and the 4th product will probably become useful when a bank partner or auditor asks about it.
Can I share completed outputs externally?
Yes. You can use completed outputs with auditors, customers, bank partners, regulators, and internal stakeholders. Customize the template for internal business use — just don't resell or redistribute the source template files.
How do I receive the files?
Checkout is handled through Stripe. After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account is required.
What if it's not a fit?
Email within 30 days for a full refund, no questions asked. The guarantee is meant to remove purchase risk while you evaluate whether the template fits your use case.
● First-time buyer offer
Get 20% off your first template.
Drop your email and we'll send the code.
◆ Not ready to buy?
Start with the free Risk Register.
141 pre-populated fintech risks across 21 categories. ISO 31000 structure.
Download free Risk Register →◆ Ready when you are
Get the Compliance Essentials.
Start building a defensible risk program today.