Skip to content
One Compliant

Services

Services

Four pillars covering the audit a regulator requires and the security work that makes the audit worth passing.

01

Compliance & Regulatory Audit

Meet the mandate. Strengthen the foundation.

Pillar detail

NEPSE IS Audit

End-to-end Information Systems Audit for NEPSE-licensed trading members under the January 2026 IT Audit Guidelines: scope definition, control testing, evidence collection, and regulator-ready reporting.

NRB IT Audit Support

IT audit and control assessments aligned to Nepal Rastra Bank's IT guidelines for banks and financial institutions.

ISO 27001 Readiness & Gap Assessment

Structured gap analysis, documentation support, and certification-readiness advisory for organizations pursuing ISO/IEC 27001.

Continuous Compliance Advisory

Ongoing monitoring and advisory so compliance status doesn't lapse between audit cycles.

02

Offensive Security

Find the gaps before someone else does.

Pillar detail

Vulnerability Assessment & Penetration Testing (VAPT)

Web application, network, and infrastructure penetration testing to identify exploitable weaknesses.

Secure Code Review

Manual and tool-assisted review of application source code for security flaws before deployment.

Network Security Assessment

Firewall, server, and network device configuration review against hardening benchmarks.

Threat Modeling & Architecture Review

Security-by-design review of system architecture for new platforms and trading infrastructure.

03

Data Protection & Risk

Know your data. Control your risk.

Pillar detail

Information Security Risk Assessment

Structured risk identification, scoring, and treatment planning across people, process, and technology.

Data Privacy Consulting

Data handling, storage, and disclosure practices reviewed against emerging Nepali data protection expectations and global frameworks (GDPR-informed methodology).

Business Continuity & Resilience Review

Assessment of continuity and disaster recovery readiness for critical financial systems.

04

Digital Forensics & Incident Response

When something goes wrong, respond fast — and prove it.

Pillar detail

Incident Response Support

Rapid-response investigation for suspected security incidents affecting trading or financial systems.

Forensic Investigation

Evidence-grade digital forensics for post-incident root-cause analysis and reporting.

Incident Readiness Assessment

Pre-incident review of detection and response capability, so an incident doesn't become a crisis.

How It Works

Five steps, from scope to submission

  1. 01

    Scoping

    Define audit/assessment scope against applicable regulatory guideline.

  2. 02

    Assessment

    On-site and remote testing, control evaluation, evidence gathering.

  3. 03

    Findings & Risk Rating

    Clear, prioritized findings — not a 200-page unreadable report.

  4. 04

    Remediation Support

    Practical guidance to close gaps before re-audit or regulatory submission.

  5. 05

    Regulator-Ready Reporting

    Documentation formatted for direct submission to NEPSE/NRB/SEBON as required.

Get Audit-Ready Before Your Deadline

Whether you're preparing for your first NEPSE IS Audit under the 2026 guidelines or need a security partner for ongoing compliance, One Compliant is ready to scope your engagement.

Request a Consultation