GRC Migrate

Home › Basics

Basics · reviewed July 2026

What compliance automation actually does

Short answer

Compliance automation automates evidence collection, not compliance. Software can read your cloud and identity systems on a schedule and record what it finds. It cannot decide which controls apply to your business, and it cannot make your colleagues finish their security training. Knowing which layer you are buying is the difference between a platform that pays for itself and one nobody opens.

Three layers, and who does each one

Every vendor in this category sells automation. It is worth knowing precisely which layer is automated, because the automated layer is not the layer that stalls your project.

  1. 01

    Evidence collection, which really is automated

    API reads against cloud, source control, identity provider and device fleet, on an hourly or daily schedule, each result timestamped. This works, it works well, and it is the reason the category exists. Your part is connecting the integrations and noticing when one quietly disconnects, because a stale integration reads as a passing control until somebody looks.

  2. 02

    Human evidence, which is only nudged

    The platform knows who has not signed the policy or finished the training, and it sends the reminder. It cannot make anyone respond. No software has solved this and none of them claim to in writing. This is the most common reason a project sits at sixty percent for a quarter.

  3. 03

    Judgement, which is not automated at all

    Which controls apply to your business. What your risk assessment concludes. What scope your report covers. Which exceptions you are willing to explain to an auditor. This is what a vCISO or an implementation partner is for, and it is the work no platform absorbs regardless of what the demo shows.

WHAT THE SOFTWARE CARRIESEvidence collectionCloud, identity, devices, source control, on a scheduleAutomated, and it worksPolicy signatures and trainingIt knows who has not done it. It sends a reminder.Nudged, not doneJudgementWhich controls, what scope, which exceptionsA person decides thisProjects stall below the top bar, never on it
The bar shrinks as you go down. So does what you can buy.

The words on the demo, translated

Continuous monitoring
Tests run hourly or daily instead of once a year
Control framework
The vendor's opinionated list of what you must prove
Cross mapping
One piece of evidence counted toward two frameworks
Trust center
A public page showing your security posture to buyers
Auditor portal
Where your audit firm reads the evidence
Readiness
All the work that happens before an audit can start
Type 1
Controls were designed properly on one day
Type 2
Controls operated properly across a period
The one that sets your date

Enterprise buyers almost always want Type 2, which means the observation window has to start before you can finish. That timing, not the software, is what usually decides when you can hand over a report.

Three questions to ask on any demo

  1. 01

    Check my top ten systems against your integration list, now

    Not the headline number. Your ten. Do it live on the call. Do not take the count on trust.

  2. 02

    What happens to a control when its integration disconnects?

    You are asking whether silent failure is possible. The answer tells you how much supervision the thing needs.

  3. 03

    Who at my company responds to the reminders?

    Ask yourself, not the vendor. If there is no name, buy the help before you buy the software.

Common questions

Does compliance automation replace a compliance person?

No, and the vendors do not claim it does. It replaces the evidence gathering a compliance person would otherwise do by hand, which is a large share of the hours but a small share of the judgement. Companies without anyone owning compliance internally tend to stall regardless of which platform they bought.

What percentage of SOC 2 can actually be automated?

Nobody should give you a single number, because it depends entirely on how much of your control set is technical. Controls that live in cloud configuration, identity and device management automate well. Controls that depend on a person doing something, or on a decision being documented, do not. A technical infrastructure heavy control set automates far more than a process heavy one.

Why do compliance platform implementations stall?

Almost always for one of three reasons: nobody internally owns the project by name, the integrations were connected but never monitored, or the remaining work is human follow through that no reminder fixes. The platform is rarely the cause, so switching platforms rarely fixes it.