CASE STUDY
ÉTUDE DE CAS

Despite an exploding compliance footprint, Perk cuts questionnaire time by 50% with Vanta

COMPANY
ENTREPRISE
Perk
LOCATION
EMPLACEMENT
London, UK
INDUSTRY
INDUSTRIE
Business Travel / Fintech
PARTNER
PARTENAIRE
EMPLOYEES
EMPLOYÉS
1,800+
VANTA CUSTOMER SINCE
ANNÉES AVEC VANTA
2024
50% reduction in security questionnaire response time

Saved time equivalent of 2 additional team members

Almost all questionnaires managed without security involvement

“Now, as a travel and spend management platform, our reimbursement process requires increased regulatory responsibilities. Vanta handles that complexity for us. Without it, we'd easily need two more full-time hires just to stay on top of frameworks.”

Bas Groeneweg
Information Security Manager, Perk

TL;DR

  • Challenge: Perk's information security team was buried in manual questionnaire responses and audit prep while simultaneously managing an exploding compliance footprint after becoming a regulated financial institution.
  • Solution: Perk deployed the Vanta Agent, a Trust Center, custom frameworks, and automated access reviews to unify compliance operations and remove the security team as a bottleneck in the sales process.
  • ROI: Questionnaire response time dropped 50%, 49 of 50 questionnaires now resolve without security involvement.

The company

Perk is redefining how businesses manage travel and spend

Perk (formerly TravelPerk) is an intelligent AI-native platform serving businesses that need full visibility and control over travel and spend without the operational overhead of managing disconnected tools. The company entered regulated financial services territory by acquiring a banking entity, which fundamentally raised the stakes for its compliance and security program.

The challenge

From manageable compliance to operational overload

Perk started as a travel management company with a relatively contained compliance scope. That changed quickly after acquiring a banking entity and expanding its capabilities to spend management. The information security team suddenly had to support a much broader and more complex set of frameworks, including SOC 2, ISO 27001, PCI DSS, GDPR/ISO 27701, DORA, and NIS 2—raising both the stakes and the operational burden.

What Perk tried first: What had previously been manageable workflows—security questionnaires, access reviews, and audit preparation—became increasingly time-consuming and difficult to scale. The security team found itself pulled into repetitive, manual work that slowed down both compliance progress and sales cycles.

Perk's pivot point: As framework requirements and questionnaire volume grew, manual processes became a clear bottleneck. Perk needed a way to automate responses, support complex frameworks, and enable sales to self-serve without relying on security.

Why Perk chose Vanta: Perk evaluated several vendors and selected Vanta for its breadth of integrations (including AWS, Okta, and HubSpot), intuitive interface, strong audit mapping, and Trust Center capabilities that could offload work from the security team.

{{quote-2}}

The Vanta impact

Building a scalable, automated compliance engine

Perk implemented Vanta as the centralized system to manage compliance, automate manual work, and remove the security team from day-to-day operational bottlenecks. By integrating directly with core systems like AWS, Okta, and Hibob, Vanta enabled continuous monitoring, streamlined workflows, and greater visibility across frameworks.

Here's how Perk deployed Vanta:

Vanta tools and solutions ROI
Custom Frameworks: Enables Perk to operationalize and manage emerging fintech frameworks like DORA, NIS 2, and PCI DSS within a single system.
  • Achieved SOC 2 Type I in 3 months
  • Accelerated compliance across multiple frameworks
Vanta Agent: Automatically generates responses to security questionnaires using existing compliance data, shifting the team’s role from manual completion to final review.
  • 50% reduction in time spent answering questionnaires
Trust Center: Provides a centralized, customer-facing hub with pre-approved answers and documentation, allowing sales to respond to security requests independently.
  • Almost all questionnaires completed with minimal security involvement
Risk Management: Maintains a live risk register tied to controls and frameworks, improving internal visibility and simplifying audit preparation.
  • Clear, real-time view of risk posture across frameworks
  • Reduced manual effort required for audit readiness
Access Reviews: Uses identity provider integrations to automate and scope access reviews, ensuring accurate and up-to-date user data.
  • Eliminated reliance on manual, error-prone access data
  • Reduced time spent on recurring review cycles

By consolidating compliance operations into Vanta, Perk's information security team can focus on the more complex parts of their role and automate repetitive manual tasks, enhancing speed, accuracy, and overall internal efficiency.

{{quote-3}}

“As an AI-native platform, we’re always looking for ways to use the technology to remove complexity and repetitive, manual work so we can focus on supporting customers. We are really happy with Vanta. The way Vanta is being actively developed and actively improved has been impressive to us… Almost every week, we are surprised by a new feature that helps us.”

Bas Groeneweg
Information Security Manager, Perk

"When we first introduced reimbursements, our frameworks were significantly more complex. Without Vanta, navigating that transition would have stalled our roadmap and overwhelmed our team.”

Bas Groeneweg
Information Security Manager, Perk