Compliance Automation Toolby Agent Trust Cloud

Compliance automation tool

Pick the frameworks you need and the systems you already run. See which controls each framework needs, which controls serve several at once, how much of the evidence your systems can collect automatically, and a prioritised list of what to fix.

Free, no sign-up, nothing leaves your browser. 29 controls mapped across 6 frameworks.

1. Frameworks you need
2. Systems you already run

Each can supply evidence automatically once connected to a compliance platform.

3. Where each control stands (optional)

Governance

Security policies are approved by management, published and acknowledged by staff, and reviewed at least yearly.

An approved AI policy says how AI is developed, bought and used, and who decides.

Named owners for security, privacy and AI risk, with authority and a reporting line to leadership.

Risk

Risks are assessed with a defined method at least yearly and on major change, and each has an owner and a treatment.

The effects of each AI system on people, groups and society are assessed before use and when it changes.

Assets

Hardware, software and cloud resources are inventoried with an owner, and the list stays current.

Every AI system and agent in use is listed with its owner, purpose, data and permissions.

Access

Access is requested, approved and granted by role; admin rights are limited and separately approved.

Everyone has their own account and MFA protects every system that holds sensitive data.

Access is revoked promptly (typically within a day) when someone leaves or changes role.

Owners review who has access to key systems at least quarterly and remove what isn't needed.

Data

Sensitive data is encrypted where stored and when it moves over networks.

Operations

Company devices have malware protection, disk encryption, screen lock and current updates.

Systems and dependencies are scanned, and findings are fixed within set timeframes by severity.

Security-relevant activity is logged centrally, retained and reviewed, with alerts on anomalies.

A tested plan says how incidents are reported, triaged, contained, communicated and learned from.

AI operations

AI systems and agents log their inputs, actions and outputs, and their behaviour is monitored in production.

People can understand, intervene in and override AI outputs and agent actions where it matters.

Users and deployers are told when they deal with AI, what it is for and its limits.

Engineering

Production changes are reviewed, tested and approved before release, and emergency changes are reviewed after.

Code is reviewed and security-tested before release, and environments are separated.

Resilience

Critical data is backed up on a schedule and restores are tested.

A continuity and recovery plan exists, is tested at least yearly, and lessons are acted on.

Third parties

Vendors (including AI model and data suppliers) are assessed before use and reviewed, with security terms in contracts.

People

Staff complete security training at onboarding and yearly; people who build or use AI also learn its risks.

New staff are screened as the role requires and sign confidentiality terms.

AI development

Data used to build or tune AI systems has a known source, meets quality criteria and is prepared in a documented way.

AI systems are validated before release and after changes, including robustness, security and prompt-injection testing.

Assurance

The programme is audited internally on a schedule and leadership reviews results and decides on improvements.

How it works

  1. Frameworks: each control carries its reference in every framework it answers. Picking frameworks filters the 29 controls to the ones you need.
  2. Systems: each control lists the systems whose data can evidence it automatically. 24 controls can be automated this way; 5 always need documents or sign-offs.
  3. Status: readiness counts 2 points for a control in place, 1 for partly in place and 0 otherwise, out of 2 per control.

The full map is on compliance control mapping.

Questions

Is this compliance automation tool free?

Yes. The full result (control map, automation coverage, gap list and CSV) is free with no sign-up. It runs in your browser and nothing you enter is sent anywhere.

Which frameworks does it cover?

AICPA Trust Services Criteria (2017, revised points of focus 2022); ISO/IEC 27001:2022 information security management systems (clauses and Annex A); HIPAA Security Rule, 45 CFR Part 164 Subpart C; ISO/IEC 42001:2023 AI management system (clauses and Annex A); NIST AI Risk Management Framework 1.0 (NIST AI 100-1); Regulation (EU) 2024/1689 (the AI Act), articles.

How is 'automatable now' worked out?

Each control lists the systems that can supply its evidence automatically. A control counts as automatable now when at least one system you picked is on that list. 5 of the 29 controls always need manual evidence.

How are gaps prioritised?

A control that is not in place and serves two or more of your frameworks is high priority, because one fix closes several requirements. Other controls not in place, and partly in place controls, are medium. Unanswered controls are low.

Is the mapping official?

No. It is our own mapping to the official framework references. Auditors and certification bodies make their own judgement.

Compliance automation guides

Sources