1 platform managing 5 active compliance frameworks

90 vendors on automated scheduled reviews

Up from 23% to 60% test pass rate in under 9 months

"I don't think I'd be able to survive without Vanta now. It's helped scale my GRC program way beyond what I could have done just on my own."

Josephine Robinson
Information Security Director, Codat

TL;DR

  • Challenge: As Codat's enterprise banking customer base grew, the team needed to move from point-in-time compliance to a continuous, structured GRC program.
  • Solution: Codat's four-person team now runs a fully unified GRC program—compliance, risk, vendor management, and access reviews—from a single platform.
  • ROI: Test pass rate jumped from 23% to 60% in under 9 months, 90 vendors moved to automated scheduled reviews, and the team reclaimed the headspace to lead strategic trust initiatives across the business.

The company

Building advisory intelligence for commercial banking

Codat is an advisory intelligence platform for modern commercial banking. It transforms client financial data into forward-looking insights that help banking teams spot opportunities, deepen relationships, and grow revenue. Codat is growing fast while serving some of the largest banks—meaning its entire business runs on a foundation of trust. 

The challenge

Five frameworks and zero visibility 

Codat's bank customers demand strong security to do business. But for Codat’s four-person team, demonstrating trust across multiple compliance frameworks meant juggling a patchwork of tools and manual processes that were never built to scale together.

What Codat tried first: SOC 2 and ISO 27001 lived on separate platforms, with a local auditor managing ISO independently. Vendor assessments ran through Google Forms and Excel spreadsheets. Access reviews meant screenshots and manual tracking. Auditors emailed, Slack pinged, and Josephine Robinson, Information Security Director at Codat, was left constantly context-switching with no centralized GRC home.

Codat's pivot point: After three years of fragmented tools and manual processes, Josephine needed a single platform where compliance, risk, vendor management, and access reviews could finally talk to each other.

Why Codat chose Vanta: Three years ago, Josephine evaluated Vanta and moved on, as the product wasn't where her program needed it to be. When she returned, the product had matured into something meaningfully different: a platform that didn't just organize compliance but actively guided her entire GRC program—from compliance to risk, access reviews, and more. Her auditor's familiarity with Vanta sealed the deal.

{{quote-2}}

The Vanta impact

From fragmented tools to a single scalable GRC program

Rather than replacing one set of point tools with another, Codat consolidated its entire GRC program onto Vanta, where compliance data, vendor risk, access reviews, and organizational risk feed into a single, continuously updated view. Now, Josephine's team can see the full picture.

Here's how Codat deployed Vanta:

Vanta tools and solutions ROI
Automated Compliance: Codat runs SOC 2, ISO 27001 (2022), GDPR, ISO 42001, and a custom framework in one place — with continuous control monitoring that replaced manual, point-in-time checks.
  • Up from ~23% to ~60% of controls passing in under 9 months, meaning the majority of Codat's program is now continuously verified and audit-ready
  • Plain-language test guidance means engineers and app security teams can now remediate controls independently
  • Added ISO 42001 to get ahead of AI governance requirements before banking customers start asking
  • 90% of program test items remediated by their due date over the past 12 months
Risk and Third-Party Risk Management: Codat replaced manual processes with automated scheduled vendor reviews across its full vendor portfolio. The integrated risk register, fed by TPRM data, creates a unified, continuously updated view of organizational risk.
  • 90 vendors managed on automated review cycles
  • All active vendors now have both a business owner and a security owner assigned, with reviews running on automated schedules rather than requiring manual tracking
Trust Center and Questionnaire Automation: Codat’s Vanta Trust Center replaces reactive, one-off security disclosures with always-on security transparency for bank customers and data partners. With Questionnaire Automation, auditors go directly into Vanta to complete assessments.
  • Supports Codat's external trust narrative and go-to-market positioning
  • Cuts context switching and audit-season bottlenecks
  • 87 out of 93 requests to access Trust Center were auto-approved
  • 4,121 Trust Center visits and 5,486 page views over the past 12 months, with 1,309 resource downloads/views
Access Reviews: Automated access reviews via an HR platform integration lets Codat run reviews without manual coordination.
  • Access reviews now run on a risk-based cadence instead of ad hoc manual tracking
  • Reviewed 1,000+ accounts across ~80 vendors and changed roles/revoked 116 instances of inappropriate or excessive access—directly reducing attack surface.
  • Enabled all business department leads (IT, Data, Finance, People, Engineering, RevOps) to complete reviews asynchronously, without dedicated project management.

With the operational work handled by the platform, Josephine shifted from managing compliance to leading GRC strategy—partnering with marketing on how Codat articulates its security posture, contributing to the product roadmap, and getting ahead of frameworks like ISO 42001 before customers start asking. That's what a mature GRC program makes possible.

{{quote-3}}

"I’ve only been a customer for about a year, and in that time, the level of innovation I’ve seen I’ve literally never seen anywhere before. I see it trending in that direction of saving me even more time, and really being able to allow me to spend more time on those strategic initiatives."

Josephine Robinson
Information Security Director, Codat

"What would I do if Vanta didn't exist anymore? Probably quit my job."

Josephine Robinson
Information Security Director, Codat