Compliance Automation and Evidence Pipelines
Evidence that accumulates as a side effect of normal work. Access reviews, change records and configuration checks collected continuously, so the next audit is a report rather than a project.
- Who
- Delivered by a senior team assembled for the engagement, against a defined scope.
What you're seeing
- The week before fieldwork is spent assembling screenshots.
- Usually means Evidence is collected on demand rather than continuously. It works once, costs a fortnight each time, and produces snapshots rather than the operating record an auditor actually wants.
- A leaver still has access to something three weeks later.
- Usually means Offboarding is a checklist somebody remembers rather than a process driven from the identity provider. It is the most common finding in this area and among the cheapest to remove permanently.
- A control was true at the last audit and nobody knows whether it still is.
- Usually means There is no drift detection. Configuration changes quietly during incidents and migrations, and the discovery point is the next audit — eleven months too late to fix quietly.
- You bought a compliance platform and the dashboard is mostly amber.
- Usually means The tool is reporting accurately that controls do not exist. Automation collects evidence; it cannot manufacture the practice the evidence is supposed to be of.
The second audit is the real one
Passing once can be done with effort. Passing every year without a scramble is a property of how evidence is produced.
The difference shows up in the eleven months between audits. In the durable version, access reviews run on a schedule and record themselves, change history comes out of the pipeline, and configuration is checked continuously. The audit is somebody reading what is already there. In the fragile version, the control environment is reassembled annually by whoever is available, and eventually a control fails a test because nobody operated it in between.
This is why the work is framed as building a pipeline rather than as preparing for an audit. Preparation is a project with an end date. A pipeline is a property of the system.
Map before you automate
For each applicable control, the first question is which system already proves it.
The answer is usually one you already run. Your identity provider knows who has access and when it changed. Your repository knows what was reviewed and by whom. Your cloud knows what the configuration is. Very little of a standard control set requires evidence nobody is currently producing — it requires evidence nobody is currently collecting.
That mapping decides everything after it, including whether a platform subscription is worth buying. It also finds the controls that genuinely have no evidence source, which are the ones that need new mechanism rather than new queries.
Joiners, movers, leavers
If one thing gets automated first, it is this.
Access review is the most frequently failed control and the most reliably automatable. Driven from the identity provider, joining grants the right set, moving revokes what is no longer justified, and leaving removes everything on the same day rather than whenever someone remembers. Periodic recertification routes to an owner who is a real person with a stake, not to a shared inbox.
The compounding benefit is that this removes the manual step people forget under pressure — and the leaver who kept access for three weeks is almost always a leaver who departed during a busy month.
Where it sits
This is a capability inside SOC 2 Readiness, where it is what makes the difference between a first report and a durable one.
It runs directly alongside ISO 27001 Readiness — the control sets overlap heavily and the evidence pipeline should be built once to serve both — and alongside Vendor Risk Management, which is the one part of the control set whose evidence lives outside your own systems and therefore needs its own cycle.
How the work runs
-
Map controls to evidence sources
For each control, the system that already proves it. Most are already produced by your identity provider, your repository and your cloud.
-
Automate the collection
Continuous rather than quarterly, so nobody assembles screenshots in the week before fieldwork.
-
Automate access review
Joiners, movers and leavers driven from the identity provider, with periodic recertification that routes to a real owner.
-
Detect drift
Configuration checks that alert when a control stops being true, rather than discovering it at the next audit.
What arrives
- A control-to-evidence map covering the applicable set
- Continuous evidence collection wired into existing systems
- Automated joiner, mover and leaver handling with recertification
- Drift alerts on the controls that can silently lapse
What it costs your team
Around two hours a week during implementation, near zero afterwards, which is the point.
How we decide
Controls are mapped to evidence sources that already exist
Costs It takes a mapping exercise before anything is automated, and the mapping is unglamorous.
Most of what an auditor wants is already produced by your identity provider, your repository and your cloud. Building new evidence-producing processes when the record already exists doubles the operating cost of the control for no gain. The mapping is what tells you which controls genuinely need new mechanism and which need a query.
Collection is continuous, never quarterly
Costs It costs more to set up than a recurring calendar reminder.
Quarterly collection produces snapshots, and a Type II opinion is about operation over a period. It also concentrates the whole cost into the weeks before fieldwork, which is when the organisation can least afford it. Continuous collection is more work once and almost none afterwards, which is the entire argument for automating anything.
A platform is recommended only where it earns the subscription
Costs Saying a tool is unnecessary ends a straightforward piece of implementation work.
Platforms are genuinely good at evidence collection across several frameworks, and for most teams at this stage they pay for themselves. But where the same evidence already comes out of infrastructure you run, a subscription buys a dashboard over data you had. The honest version of this advice occasionally costs us the implementation.
Where this has run
Frequently Asked Questions
Sources
- AICPA — SOC 2 and the Trust Services Criteriaaicpa-cima.com
- NIST — Cybersecurity Frameworknist.gov
- OWASP — Software Assurance Maturity Modelowaspsamm.org
- Regulation (EU) 2016/679 — GDPReur-lex.europa.eu
Page reviewed
