Automated compliance platform: what gets automated
An automated compliance platform does three jobs: it maps one set of controls to several frameworks, it pulls evidence from the systems you already run, and it re-checks that evidence on a schedule so a control that breaks shows up before the audit does. The counts below come from the 29-control map behind our free tool, across 6 frameworks.
Which systems supply which evidence
| System | Examples | Controls | Control IDs |
|---|---|---|---|
| Identity provider or SSO | Okta, Microsoft Entra ID, Google Workspace | 4 | ACCESS, MFA, OFFBOARD, ACCESS-REVIEW |
| Cloud platform | AWS, Microsoft Azure, Google Cloud | 6 | ASSETS, AI-INV, ENCRYPT, VULN, LOGGING, BACKUP |
| Code repository and CI/CD | GitHub, GitLab, Bitbucket | 4 | VULN, CHANGE, SDLC, AI-TEST |
| Ticketing and change tracking | Jira, Linear, ServiceNow | 4 | RISK, ACCESS, INCIDENT, CHANGE |
| Device management and endpoint protection | Intune, Jamf, Kandji, an EDR | 3 | ASSETS, ENCRYPT, ENDPOINT |
| Vulnerability scanner | a cloud, container or dependency scanner | 1 | VULN |
| Central logging or SIEM | a log platform or SIEM | 2 | LOGGING, AI-MONITOR |
| HR system | Rippling, BambooHR, Workday | 5 | SEC-POL, ROLES, OFFBOARD, TRAINING, SCREENING |
| Security awareness training platform | a training platform with completion records | 1 | TRAINING |
| Vendor inventory | a vendor or procurement register | 1 | VENDOR |
| Backup service | cloud-native or third-party backups | 1 | BACKUP |
| AI system and agent inventory | a register or gateway listing AI systems, agents and their owners | 5 | AI-INV, AI-MONITOR, AI-DATA, AI-TEST, AI-OVERSIGHT |
24 of the 29 controls can be evidenced from at least one of these systems.
What stays manual
5 controls need people, documents and sign-offs, whatever platform you use:
- AI-POL AI policy: Approved AI policy; record that it was communicated.
- AI-IMPACT AI system impact assessment: Impact assessments per AI system, stored with dates and sign-off.
- BCDR Business continuity and disaster recovery: BC/DR plan; test report with findings.
- AI-TRANSPARENCY Information for users about AI: User documentation; AI notices; instructions for use.
- AUDIT Internal audit and management review: Internal audit reports; management review minutes; corrective actions.
Some controls marked automatable are only partly so: a platform can show that a risk register exists and was updated, not that the risk decisions were sound.
Cross-framework mapping
29 of the 29 controls serve two or more frameworks. Access reviews, for example, answer SOC 2, ISO/IEC 27001 and HIPAA requirements at once. See the full compliance control mapping, or the SOC 2 view.
Continuous checks versus point-in-time evidence
An auditor samples evidence for a period. If evidence is collected once, before fieldwork, a control that failed in month three is found late or not at all. Scheduled checks against the source systems turn that into a ticket the same week.
Sources
Questions
What can compliance automation collect on its own?
Configuration and activity that lives in systems with an API: MFA enforcement, user lists and leavers, encryption settings, code review and deployment records, device status, scan results, backup jobs and training completion.
What stays manual?
Decisions and tests that happen between people: risk acceptance, AI impact assessments, continuity tests, management review and information you give users about AI. A platform can track them, but someone has to do them.