§ CAPABILITY

Compliance Automation and Evidence Pipelines

Evidence that accumulates as a side effect of normal work. Access reviews, change records and configuration checks collected continuously, so the next audit is a report rather than a project.

Who
Delivered by a senior team assembled for the engagement, against a defined scope.

What you're seeing

The week before fieldwork is spent assembling screenshots.
Usually means Evidence is collected on demand rather than continuously. It works once, costs a fortnight each time, and produces snapshots rather than the operating record an auditor actually wants.
A leaver still has access to something three weeks later.
Usually means Offboarding is a checklist somebody remembers rather than a process driven from the identity provider. It is the most common finding in this area and among the cheapest to remove permanently.
A control was true at the last audit and nobody knows whether it still is.
Usually means There is no drift detection. Configuration changes quietly during incidents and migrations, and the discovery point is the next audit — eleven months too late to fix quietly.
You bought a compliance platform and the dashboard is mostly amber.
Usually means The tool is reporting accurately that controls do not exist. Automation collects evidence; it cannot manufacture the practice the evidence is supposed to be of.

The second audit is the real one

Passing once can be done with effort. Passing every year without a scramble is a property of how evidence is produced.

The difference shows up in the eleven months between audits. In the durable version, access reviews run on a schedule and record themselves, change history comes out of the pipeline, and configuration is checked continuously. The audit is somebody reading what is already there. In the fragile version, the control environment is reassembled annually by whoever is available, and eventually a control fails a test because nobody operated it in between.

This is why the work is framed as building a pipeline rather than as preparing for an audit. Preparation is a project with an end date. A pipeline is a property of the system.

Map before you automate

For each applicable control, the first question is which system already proves it.

The answer is usually one you already run. Your identity provider knows who has access and when it changed. Your repository knows what was reviewed and by whom. Your cloud knows what the configuration is. Very little of a standard control set requires evidence nobody is currently producing — it requires evidence nobody is currently collecting.

That mapping decides everything after it, including whether a platform subscription is worth buying. It also finds the controls that genuinely have no evidence source, which are the ones that need new mechanism rather than new queries.

Joiners, movers, leavers

If one thing gets automated first, it is this.

Access review is the most frequently failed control and the most reliably automatable. Driven from the identity provider, joining grants the right set, moving revokes what is no longer justified, and leaving removes everything on the same day rather than whenever someone remembers. Periodic recertification routes to an owner who is a real person with a stake, not to a shared inbox.

The compounding benefit is that this removes the manual step people forget under pressure — and the leaver who kept access for three weeks is almost always a leaver who departed during a busy month.

Where it sits

This is a capability inside SOC 2 Readiness, where it is what makes the difference between a first report and a durable one.

It runs directly alongside ISO 27001 Readiness — the control sets overlap heavily and the evidence pipeline should be built once to serve both — and alongside Vendor Risk Management, which is the one part of the control set whose evidence lives outside your own systems and therefore needs its own cycle.

How the work runs

  1. Map controls to evidence sources

    For each control, the system that already proves it. Most are already produced by your identity provider, your repository and your cloud.

  2. Automate the collection

    Continuous rather than quarterly, so nobody assembles screenshots in the week before fieldwork.

  3. Automate access review

    Joiners, movers and leavers driven from the identity provider, with periodic recertification that routes to a real owner.

  4. Detect drift

    Configuration checks that alert when a control stops being true, rather than discovering it at the next audit.

What arrives

  • A control-to-evidence map covering the applicable set
  • Continuous evidence collection wired into existing systems
  • Automated joiner, mover and leaver handling with recertification
  • Drift alerts on the controls that can silently lapse

What it costs your team

Around two hours a week during implementation, near zero afterwards, which is the point.

How we decide

  • Controls are mapped to evidence sources that already exist

    Costs It takes a mapping exercise before anything is automated, and the mapping is unglamorous.

    Most of what an auditor wants is already produced by your identity provider, your repository and your cloud. Building new evidence-producing processes when the record already exists doubles the operating cost of the control for no gain. The mapping is what tells you which controls genuinely need new mechanism and which need a query.

  • Collection is continuous, never quarterly

    Costs It costs more to set up than a recurring calendar reminder.

    Quarterly collection produces snapshots, and a Type II opinion is about operation over a period. It also concentrates the whole cost into the weeks before fieldwork, which is when the organisation can least afford it. Continuous collection is more work once and almost none afterwards, which is the entire argument for automating anything.

  • A platform is recommended only where it earns the subscription

    Costs Saying a tool is unnecessary ends a straightforward piece of implementation work.

    Platforms are genuinely good at evidence collection across several frameworks, and for most teams at this stage they pay for themselves. But where the same evidence already comes out of infrastructure you run, a subscription buys a dashboard over data you had. The honest version of this advice occasionally costs us the implementation.

Frequently Asked Questions

Collecting the evidence that controls are operating, continuously and from the systems that already record it, rather than assembling it by hand before an audit. In practice it covers access reviews, change records, configuration checks and vendor tracking — the four things that otherwise consume the fortnight before fieldwork.
They earn their cost when you carry several frameworks or have few people to spare, because evidence collection is most of the recurring work. Where the same evidence already comes out of your identity provider and your cloud, we say so rather than adding a subscription over data you already hold.
Collection and monitoring. It does not create a control that does not exist — a platform will report accurately and repeatedly that you have no access review process. Buying one before the controls exist buys a very clear list of what has not been done, which is useful but is not what anyone thought they were purchasing.
Access reviews and evidence assembly, by a distance. Both are automatable, and together they are most of what makes an annual audit feel like a project rather than a report. Everything else is comparatively fixed.
Generally it is preferred, because it is continuous rather than a snapshot someone assembled the week before. What auditors reject is evidence that cannot be traced back to a system of record — a spreadsheet asserting that reviews happened is weaker than a log showing them happening.

Sources

Page reviewed