Managing compliance in a healthcare SaaS organization: Internal and external audit practices at Therap
| bracu.degree.level | Postgraduate | |
| bracu.type.group | Student Works | |
| datacite.rights | Open Access | |
| dc.contributor.advisor | Akhtar, Afsana | |
| dc.contributor.author | Touhid, Md. Touhiduzzaman | |
| dc.contributor.department | BRAC Business School | |
| dc.date.accessioned | 2026-08-19T05:41:32Z | |
| dc.date.available | 2026-08-19T05:41:32Z | |
| dc.date.copyright | 2026 | |
| dc.date.issued | 2026-05 | |
| dc.description | This internship report is submitted in partial fulfillment of the requirements for the degree of Master of Business Administration, 2026. | |
| dc.description | Cataloged from PDF version of internship report. | |
| dc.description | Includes bibliographical references (page 40). | |
| dc.description.abstract | This report mainly examines how compliance functions and audit activities are performed at Therap (BD) Ltd., a healthcare SaaS company that deals with sensitive health related information. I did this on my internship between November 2025 and April 2026, where I was working on audit prep, evidence validation, document review, training compliance tracking, aiding with vendor risk, and answering auditors. The report examines how such tasks create actual governance in a regulated technological sector, rather than viewing compliance as a formality. The investigation follows a qualitative paradigm methodologically because it has relied on first-hand involvement, systematic observation, and the examination of non-confidential records. The subject of discussion is the interaction of audit processes, documentation procedures, risk management, and controls, which relate to training in a multi-framework setting due to regulatory requirements, including HIPAA, SOC 2, and others. It also reflects on the overall organizational environment of Therap, where secure systems, coordination, and discipline of processes are essential to the day-to-day affairs. The results indicate that Therap maintains a fairly effective compliance environment, with frequent review cycles, centralized documentation procedure, and team interdependence. Simultaneously, the analysis reveals the following real-world issues, such as delays in evidence gathering, the need to manually map similar requirements across frameworks, cross-team dependencies, and time zone coordination. The issues are not indicative of a weak control environment but rather are a mirror of the complications of multi-framework compliance in a real organizational setting. Lastly, audit work at Therap is not lower than what the outside world requires. They contribute to a better system of governance and risk management within the organization, a high level of accountability, disciplined documentation, and continuous improvement. The report suggests enhancing evidence aggregation, implementing AI automation to eliminate redundant activities, formalizing pre-audit activities, specifying response timelines, and improving monitoring through visualization in the form of dashboards, among other measures. | |
| dc.description.degree | Masters of Business Administration | |
| dc.description.statementofresponsibility | Md. Touhiduzzaman Touhid | |
| dc.format.extent | 43 pages | |
| dc.identifier.other | ID 22264067 | |
| dc.identifier.uri | https://hdl.handle.net/10361/29302 | |
| dc.language.iso | en_US | |
| dc.publisher | BRAC University | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | en |
| dc.rights | BRAC University internship reports are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. | |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | Audit compliance | |
| dc.subject | Healthcare | |
| dc.subject | Internal and external audit | |
| dc.subject | Evidence validation | |
| dc.subject | Risk management | |
| dc.subject | Review cycles | |
| dc.subject | Pre-audit | |
| dc.subject.lcsh | Auditing. | |
| dc.subject.lcsh | Auditing, Internal. | |
| dc.subject.lcsh | Risk management. | |
| dc.subject.lcsh | Corporations--Auditing. | |
| dc.title | Managing compliance in a healthcare SaaS organization: Internal and external audit practices at Therap | |
| dc.type | Internship Report |