Warning

Work in Progress: This page is currently under construction. Content may be incomplete or subject to change. To contribute, see the contribution guide.

Compliance

Regulatory and framework obligations that affect how the Technology team builds and operates systems at Patria Investments.


Applicable regulations and frameworks

Regulation / FrameworkApplicabilityOwner
LGPDAll systems processing personal data of Brazilian residentsDPO + Security team
CVM Instruction 558/2015Portfolio management and reporting systemsCompliance team
ANBIMA Code of RegulationDistribution and investment advisory platformsCompliance team
ISO 27001 (alignment)Information security management baselineSecurity team
SOC 2 Type II (roadmap)SaaS services delivered to institutional clientsSecurity team

Controls mapping

Security and privacy controls are mapped to requirements in a central register maintained by the Security & Compliance team. Access to this register can be requested via ServiceNow.


Audit & evidence

  • Evidence for compliance audits is collected continuously via automated tooling where possible
  • Manual evidence requests are coordinated by the Security & Compliance team
  • Teams are expected to respond to evidence requests within 3 business days

Sections


Contact

Security & Compliance team — see Contacts