CASE STUDY
ÉTUDE DE CAS
How Codat runs an enterprise-grade GRC program with Vanta
SOC 2, ISO 27001 (2022), GDPR, ISO 42001, custom frameworks, Trust Center, Third-Party Risk Management, Questionnaire Automation, Risk Management, Access Reviews
.webp)
"I don't think I'd be able to survive without Vanta now. It's helped scale my GRC program way beyond what I could have done just on my own."
TL;DR
- Challenge: As Codat's enterprise banking customer base grew, the team needed to move from point-in-time compliance to a continuous, structured GRC program.
- Solution: Codat's four-person team now runs a fully unified GRC program—compliance, risk, vendor management, and access reviews—from a single platform.
- ROI: Test pass rate jumped from 23% to 60% in under 9 months, 90 vendors moved to automated scheduled reviews, and the team reclaimed the headspace to lead strategic trust initiatives across the business.
The company
Building advisory intelligence for commercial banking
Codat is an advisory intelligence platform for modern commercial banking. It transforms client financial data into forward-looking insights that help banking teams spot opportunities, deepen relationships, and grow revenue. Codat is growing fast while serving some of the largest banks—meaning its entire business runs on a foundation of trust.
The challenge
Five frameworks and zero visibility
Codat's bank customers demand strong security to do business. But for Codat’s four-person team, demonstrating trust across multiple compliance frameworks meant juggling a patchwork of tools and manual processes that were never built to scale together.
What Codat tried first: SOC 2 and ISO 27001 lived on separate platforms, with a local auditor managing ISO independently. Vendor assessments ran through Google Forms and Excel spreadsheets. Access reviews meant screenshots and manual tracking. Auditors emailed, Slack pinged, and Josephine Robinson, Information Security Director at Codat, was left constantly context-switching with no centralized GRC home.
Codat's pivot point: After three years of fragmented tools and manual processes, Josephine needed a single platform where compliance, risk, vendor management, and access reviews could finally talk to each other.
Why Codat chose Vanta: Three years ago, Josephine evaluated Vanta and moved on, as the product wasn't where her program needed it to be. When she returned, the product had matured into something meaningfully different: a platform that didn't just organize compliance but actively guided her entire GRC program—from compliance to risk, access reviews, and more. Her auditor's familiarity with Vanta sealed the deal.
{{quote-2}}
The Vanta impact
From fragmented tools to a single scalable GRC program
Rather than replacing one set of point tools with another, Codat consolidated its entire GRC program onto Vanta, where compliance data, vendor risk, access reviews, and organizational risk feed into a single, continuously updated view. Now, Josephine's team can see the full picture.
Here's how Codat deployed Vanta:
With the operational work handled by the platform, Josephine shifted from managing compliance to leading GRC strategy—partnering with marketing on how Codat articulates its security posture, contributing to the product roadmap, and getting ahead of frameworks like ISO 42001 before customers start asking. That's what a mature GRC program makes possible.
{{quote-3}}
