Module / Topic: Compliance
Browse Mergen content
-
Specialty Retailer: PCI-DSS + Customer-Data-Protection Programme
A specialty retailer hardened PCI-DSS posture across e-comm + 800 stores. PCI audit zero findings; customer-data incidents down 89%.
-
3PL: Data Governance for Cross-Border Customs + Compliance
A 3PL provider built data governance covering cross-border customs + trade-compliance data across 60 countries. Customs-clearance delays down 31%.
-
Hospital System: Operational Resilience Programme on ServiceNow
A multi-state hospital system built an operational-resilience programme on ServiceNow. Critical-service recovery objectives validated quarterly.
-
Energy Major: Cybersecurity for Operational Technology + IT
An integrated energy major built unified cybersecurity covering both IT and OT environments. NERC-CIP audits passed first-time; visibility into OT incidents tripled.
-
Pharma Manufacturer: MES + ITOM Integration for FDA-Validated Operations
A global pharma manufacturer integrated MES + ServiceNow ITOM with full 21 CFR Part 11 audit trail. Validated-systems uptime sustained at 99.99%.
-
Aerospace Manufacturer: MES + Quality on ServiceNow + AS9100D Alignment
An aerospace component manufacturer integrated MES + quality on ServiceNow with full AS9100D + DoD audit alignment. Defect-escape rate down 67%.
-
Why Compliance-as-Code Wins — And How to Get There
Manual compliance reviews don’t scale. The path forward: encode controls as code, audit continuously, automate evidence collection.
-
The DORA Reality Check for Financial Services Engineering
DORA is here. Most financial-services organizations are underprepared. The pragmatic path forward in 90 days.
-
Global Bank: DORA Operational-Resilience Compliance Programme
A global bank achieved DORA compliance across 24 jurisdictions with continuous-evidence collection. First-time audit pass.
-
Mergen Launches Public-Sector Compliance Practice — FedRAMP, FISMA, CJIS Focused
A new specialty practice for federal, state, and local government clients — focused on FedRAMP-aligned architectures, FISMA continuous monitoring, and CJIS-compliant law-enforcement workloads.