Compliance automation tool
Pick the frameworks you need and the systems you already run. See which controls each framework needs, which controls serve several at once, how much of the evidence your systems can collect automatically, and a prioritised list of what to fix.
Free, no sign-up, nothing leaves your browser. 29 controls mapped across 6 frameworks.
Your control map
By framework
| Framework | Controls | Requirements | Shared | Automatable now | Readiness |
|---|
Gap list
| Priority | Control | Status | Frameworks | What good looks like |
|---|
Automation opportunities
Control map
How it works
- Frameworks: each control carries its reference in every framework it answers. Picking frameworks filters the 29 controls to the ones you need.
- Systems: each control lists the systems whose data can evidence it automatically. 24 controls can be automated this way; 5 always need documents or sign-offs.
- Status: readiness counts 2 points for a control in place, 1 for partly in place and 0 otherwise, out of 2 per control.
The full map is on compliance control mapping.
Questions
Is this compliance automation tool free?
Yes. The full result (control map, automation coverage, gap list and CSV) is free with no sign-up. It runs in your browser and nothing you enter is sent anywhere.
Which frameworks does it cover?
AICPA Trust Services Criteria (2017, revised points of focus 2022); ISO/IEC 27001:2022 information security management systems (clauses and Annex A); HIPAA Security Rule, 45 CFR Part 164 Subpart C; ISO/IEC 42001:2023 AI management system (clauses and Annex A); NIST AI Risk Management Framework 1.0 (NIST AI 100-1); Regulation (EU) 2024/1689 (the AI Act), articles.
How is 'automatable now' worked out?
Each control lists the systems that can supply its evidence automatically. A control counts as automatable now when at least one system you picked is on that list. 5 of the 29 controls always need manual evidence.
How are gaps prioritised?
A control that is not in place and serves two or more of your frameworks is high priority, because one fix closes several requirements. Other controls not in place, and partly in place controls, are medium. Unanswered controls are low.
Is the mapping official?
No. It is our own mapping to the official framework references. Auditors and certification bodies make their own judgement.
Compliance automation guides
- Compliance platforms compared: How to compare compliance platforms and compliance software solutions.
- Automated compliance platform: what gets automated: What an automated compliance platform automates.
- SOC 2 compliance automation: SOC 2 compliance automation.
- AI regulatory compliance: AI regulatory compliance in 2026.
- Compliance control mapping: A free compliance control mapping across SOC 2, ISO/IEC 27001:2022, the HIPAA Security Rule, ISO/IEC 42001, the NIST AI RMF and the EU AI Act.
Sources
- AICPA & CIMA, SOC 2: SOC for Service Organizations: Trust Services Criteria
- ISO/IEC 27001:2022 Information security management systems (ISO)
- 45 CFR Part 164 Subpart C, the HIPAA Security Rule (eCFR)
- ISO/IEC 42001:2023 Artificial intelligence management system (ISO)
- NIST AI Risk Management Framework (released 26 January 2023)
- Regulation (EU) 2024/1689, the AI Act (EUR-Lex)
- Checked 1 October 2026.