Case Studies
When compliance is the product: how STAT built its GRC foundation in under a month
STAT built an ISO 27001, NIST CSF and SOC 2 GRC foundation with ORCA Opti in under a month, cutting partner security questionnaires from 50 questions to single digits.
- Organisation
- STAT
- Location
- Sunshine Coast, Queensland
- Sector
- Health technology, practitioner and pharma engagement
- Frameworks
- ISO 27001, NIST CSF, SOC 2
- Timeframe
- Four sessions across three weeks
- Outcome
- A structured, documented GRC environment with policies, procedures, controls, a risk register and a custom ISO 27001 auditor workspace configured and live
From first session to a live, documented GRC environment
Seeded and assigned across the founding team
Partner security-questionnaire length, before and after

Government, enterprise medtech and pharma partners already expect this level of compliance. Since we built this out with ORCA, questionnaires that used to run 50 questions deep are down to single digits. We've got the evidence to point to.
The challenge
STAT is a digital platform that connects AHPRA-registered healthcare practitioners with healthcare organisations for learning, market research, and networking. Practitioners earn income for sharing clinical insight through compliant engagements, and complete CPD-eligible reflection through CLARA, STAT's AI reflection tool. Organisations get verified, compliant access to practitioner insight. Every interaction is designed to be transparent, trackable and aligned with the standards governing industry-to-practitioner engagement in Australia, with global alignment on the roadmap.
Compliance, in other words, is not a back-office function at STAT. It is the product.
That sets the bar higher than it sits for most early-stage technology businesses. As STAT moved from development into active enterprise partnerships, the requirements sharpened. Partners needed to see that sensitive practitioner data was handled responsibly, with assurance across ISO 27001 for information security, NIST CSF for cybersecurity risk management, and SOC 2 for operational controls.
For a founder-led team, meeting that bar usually means one of two things: an enterprise GRC platform priced for organisations several times the size, or a compliance consultant building the environment from scratch over a period of weeks. Neither fits a lean team moving quickly with partnerships in the pipeline.
What happened
Chris Risby, Co-Founder and CEO of STAT, onboarded with ORCA Opti across four sessions over three weeks, working with Kathryn Giudes and Paige Harkness from the ORCA Pod.
The first sessions established the foundations. STAT's Google Workspace directory was connected, frameworks selected, and the onboarding wizard run to seed the environment with the relevant standards. ORCA configured ISO 27001, NIST CSF and SOC 2 across policies, procedures, controls and a baseline risk register, tailored to STAT's context as a health technology business working with practitioners rather than handling patient records directly.
What happened between sessions is the part worth noting.
Before the third session, Chris had already been back in the platform on his own. Drawing on material he had built up about STAT's business, team structure, roles and operations, he assembled a Knowledge Pack and uploaded it into ORCA. He then used Ask Opti, ORCA's built-in assistant, to bulk-update every policy and procedure in the environment with STAT-specific context.
"All of our policies look good. They've taken our context and put in our business structure. They know who our team is. They know what we do in our roles. That was really intuitive."
What would typically take a consultant days of manual drafting took an afternoon, and Chris did it himself without being walked through it.
He applied the same approach to control ownership, using Ask Opti to assign owners across the co-founding team based on their technical responsibilities.
"Instead of manually changing 139 of them, I was like, let's start with this. And sure enough, it just did it."
By the fourth session, the team built a custom ISO 27001 auditor workspace inside ORCA: a dedicated Pearl and Agent configured to run an internal pre-audit, interrogate STAT's policies and procedures, and surface gaps ahead of any formal certification review. Chris ran the auditor conversationally, received a structured set of findings and left with a clear improvement plan.
"I'm starting to feel a little more familiar and comfortable with the system. I can just go and get my fingers into it again and see what it can do for us."
The outcome
In under a month, STAT built a structured and documented GRC environment, with:
- ISO 27001, NIST CSF and SOC 2 frameworks configured and live
- All policies reviewed, updated with business-specific context, and published
- All procedures reviewed, linked to their related policies and published
- 139 controls seeded and assigned across the team
- 12 baseline risks assessed, with ratings, owners and review schedules set
- A custom ISO 27001 auditor workspace built and operational
- A risk register reflecting STAT's real commercial environment, including revenue, regulatory, information security and key person risk
What is next
The environment is built to grow with the business. As STAT's partnerships scale, US privacy requirements for international partnerships, and deeper automation of incident and workflow management are all on the roadmap, with the foundations already in place.
"There's lots of subscriptions I'll probably be able to get rid of and bundle into ORCA."
As STAT's Earn and Learn model gains traction with professional development providers, and as enterprise partnerships move from pipeline to contracted, the compliance posture becomes a direct commercial asset rather than a cost of doing business.
"This is pretty valuable. Just gives me some peace knowing that this ball's rolling."
About STAT
STAT is a digital platform that turns the free time practitioners spend learning and sharing insights into funding for better healthcare. It connects AHPRA-registered healthcare practitioners with pharmaceutical, medtech, digital health, not-for-profit and government health organisations, through structured, CPD-eligible reflection and compliant, fair-market-value payments. CLARA, STAT's AI reflection tool, turns any engagement into a piece of genuine clinical reasoning, captured in the practitioner's own words and eligible for CPD. Practitioners earn fair-market-value income for their time and insight, and can direct a separate, STAT-funded contribution to a cause of their choosing through the Giving Balance. STAT is currently partnering with professional development providers representing thousands of practitioners, with healthcare enterprise market research engagements expanding through the second half of 2026.