Great-West Lifeco · Trust Center

Great West Lifeco Trust Center

Trust center

Great-West Lifeco maintains a public trust center documenting SOC 2 Type 2, ISO 27001, NIST 800-53, NIST CSF, and OWASP compliance.

InsuranceCanadaLife InsuranceHealth InsuranceEmployee BenefitsRetirementWealth ManagementReinsuranceAnnuitiesPartner Gated
Trust center: https://www.empower.com/financial-professionals/about-empower/cybersecurity

Certifications & Compliance

SOC 2 Type 2ISO 27001NIST 800-53NIST CSFOWASP

Source

Trust Center

great-west-lifeco-trust-center.yml Raw ↑
generated: '2026-07-25'
method: searched
probe: false
source: https://www.empower.com/financial-professionals/about-empower/cybersecurity
url: https://www.empower.com/financial-professionals/about-empower/cybersecurity
note: >-
  The mechanical probe (0-working/probe-security-programs.py) found nothing: no
  trust.<domain> host, no security.<domain> host and no /trust or /compliance
  path on greatwestlifeco.com or empower.com. The group's published security
  and compliance posture instead lives on the Empower Cybersecurity page, which
  names a third-party attestation and three control frameworks explicitly. That
  page is recorded here as the group's trust surface, with the caveat that it
  belongs to the U.S. retirement subsidiary - Great-West Lifeco itself and
  Canada Life publish no equivalent.
entity: Empower (U.S. retirement subsidiary of Great-West Lifeco)
scope: subsidiary
certifications:
- name: SOC 2 Type 2
  status: attested
  evidence: '"Unqualified SOC 2 Type 2 third-party attestation"'
- name: ISO 27001
  status: aligned
  evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"'
- name: NIST 800-53
  status: aligned
  evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"'
- name: NIST CSF
  status: aligned
  evidence: '"Cybersecurity policies aligned with NIST 800-53, NIST CSF, and ISO 27001"'
- name: OWASP
  status: aligned
  evidence: '"Application security testing (SAST/DAST) aligned to OWASP standards"'
not_claimed:
- PCI DSS
- HITRUST
- FedRAMP
- CSA STAR
- ISO 27017
- ISO 27018
governance:
- Enterprise risk management framework
- Information security policies reviewed at least once a year and approved by the Information Security Board, including the CISO and company leadership
- Regulatory supervision and audit oversight (internal and external audit)
- Annual risk assessments
- Formal AI Governance Committee, AI Risk Management Policy and Standards, documented AI risk assessments
related_pages:
- name: Empower Security Center
  url: https://participant.empower-retirement.com/participant/#/articles/securityCenter
  detail: >-
    Consumer-facing security tips and the Empower security guarantee - account
    protection guidance, not a compliance artifact repository.
- name: Great-West Lifeco Internet Security Statement
  url: https://www.greatwestlifeco.com/internet-security.html
  detail: >-
    Holding-company consumer statement covering encryption, cookies, 25-minute
    session timeouts and phishing. Names no certification and no security
    contact.
evidence:
- source: https://www.empower.com/financial-professionals/about-empower/cybersecurity
  keywords: [soc 2 type 2, iso 27001, nist 800-53, nist csf, owasp, penetration testing, independent audits]
  fetched: '2026-07-25'
  status: 200
transparency_gaps:
- No downloadable or NDA-gated artifact repository (no SOC 2 report request flow published).
- No sub-processor list.
- No uptime/SLA commitment.
- No vulnerability disclosure or bug bounty program - see security/great-west-lifeco-domain-security.yml and the well-known index.