Compliance explained for CFOs

Know what the acronym changes.

Compliance is a business obligation with owners, evidence, deadlines and consequences. A badge on a proposal does not answer those questions.

Reviewed October 10, 2026 · Educational guidance, not legal advice

SOC 2 Type II

An independent CPA report about whether a service organization’s described controls were suitably designed and operated over a stated period. It is not a government certification, a guarantee, or a substitute for reading exceptions and scope.

GDPR

A European privacy law that can apply when an organization processes personal data in covered EU or EEA contexts. It governs lawful use, transparency, individual rights, security, vendors, transfers and breach response.

California privacy

The CCPA, as amended by the CPRA, gives covered California consumers rights over personal information and places duties on covered businesses. Applicability and obligations depend on the facts, not simply where the server sits.

SOC 2 Type II: assurance for customers

SOC 2 is an examination framework for service organizations. The report addresses controls relevant to security, availability, processing integrity, confidentiality or privacy. Type II looks at control operation over a defined review period, while a point-in-time description cannot show months of operation. The exact system, services, criteria, dates, auditor opinion, exceptions and customer responsibilities matter.

What it changes for the business: customers may request the report during vendor review or contract renewal. Without suitable assurance, a supplier may face longer questionnaires, extra contract conditions, delayed deals or lost opportunities. SOC 2 itself does not impose a government fine. The commercial consequence comes from customer requirements and from any underlying security or contractual failure.

Evidence to request: the complete current report under appropriate confidentiality, bridge letter when the period is old, management response to exceptions, subservice organizations, and complementary user-entity controls your company must perform.

AICPA: System and Organization Controls resources · AICPA: Trust Services Criteria

GDPR: rules for covered European personal data

GDPR is not a security certificate. It requires a lawful basis for processing, clear notices, data minimization, support for individual rights, appropriate security, vendor governance, transfer safeguards and breach handling. Whether it applies depends on the organization’s activities and people whose data is processed.

Business impact example: Ireland’s Data Protection Commission found Meta Ireland had infringed GDPR transfer requirements, imposed a €1.2 billion administrative fine, ordered suspension of future covered transfers, and required processing to be brought into compliance. The operational orders mattered alongside the fine.

European Commission: data protection in the EU · Irish Data Protection Commission: Meta transfer decision

California privacy: consumer rights and operating duties

California privacy law can require covered businesses to explain data practices, respond to consumer requests, honor qualifying opt-out signals, control service-provider and contractor relationships, limit certain uses, and protect personal information. Marketing technology, connected products, HR data and website tracking can all create cross-functional work.

Business impact examples: California’s Attorney General announced a $1.2 million Sephora settlement involving alleged failures to disclose data sales and honor opt-out requests. In 2025, the California Privacy Protection Agency required Honda to change business practices and pay $632,500 over alleged consumer-request and contracting violations.

California Attorney General: privacy enforcement actions · California Privacy Protection Agency: Honda enforcement

What the CFO should askWhich legal entity and data are in scope? Who owns the data inventory and request deadlines? Which vendors receive personal information? What evidence shows the process works? Who tells finance when a contract, control gap or enforcement issue could affect revenue, cost or disclosure?

How to operate the requirement

Turn a compliance acronym into an operating decision

Start with the commercial or legal trigger. A customer request, a market expansion, a privacy complaint, a regulated data set, an insurance application or a contract clause may put the question on the table. Then establish scope before buying a tool or hiring an assessor: which legal entity, system, people, data, vendors and locations are included?

1. Name an accountable executive

Technology can implement controls, but leadership must decide the business objective, acceptable risk, budget and deadline. A compliance project without an executive owner tends to become a list of technical tickets with no decision path.

2. Map the data and service boundary

List what information is processed, where it moves, which systems store it, which vendors receive it and who administers it. This is the foundation for privacy notices, vendor terms, access reviews, insurance answers and audit scope.

3. Test the process, not just the document

Policies, assessment reports and contract clauses matter only when daily activity follows them. Test a sample of access approvals, device enrollment, backup restoration, vendor review, training completion and incident escalation.

4. Keep exceptions visible

Older equipment, acquired businesses, temporary accounts and customer requirements often create real exceptions. Record the owner, business reason, compensating control, target date and approval. An unrecorded exception is difficult to manage or explain.

Who normally owns the work

WorkAccountable business ownerTypical contributorsWhat to retain
Customer assurance and SOC 2 responseExecutive responsible for the service or customer relationshipIT, security, finance, legal, operations and external assessorScope, current report, exceptions, bridge letter and customer commitments
Privacy governance and data subject requestsPrivacy or legal owner, with executive accountabilityIT, marketing, HR, product, records and vendorsData map, notices, request log, vendor terms and decision records
Security controls and incident readinessTechnology or security leaderSystem administrators, MSP, operations, HR, legal and insurer contactsCoverage reports, tests, incident plan, exceptions and remediation tracking
Material risk acceptanceExecutive with authority to accept the consequenceCFO, IT, legal and relevant business ownerRisk statement, alternatives, approval, review date and expiration

What a useful update to the CFO looks like

  • The trigger and scope: why this obligation matters now, which entities and systems are included, and what remains outside scope.
  • The decision required: approve budget, choose a path, accept a documented risk, or remove a blocked dependency.
  • The operating evidence: what was tested, how much of the environment is covered, what exceptions exist, and when the evidence was last refreshed.
  • The business exposure: customer commitments, contract timing, insurance representations, possible operational interruption and the owner of the next action.
Important limitationWhether SOC 2, GDPR or California privacy law applies, and what it requires in a specific situation, is a legal and factual question. This guide is designed to improve executive conversations, not replace qualified legal, privacy, insurance or audit advice.