Compliance

Compliance Automation: What It Automates, What It Costs, and What It Cannot Do

Which compliance processes automate, which do not, and how to tell whether the automation is working.

Author
Dr. Kilian Schmidt
Date
16.7.2025
Updated on
3.9.2026
Compliance Automation: What It Automates, What It Costs, and What It Cannot Do

Key Takeaways

  • Compliance automation takes over the repeating parts of a compliance program: evidence collection, control monitoring, policy distribution, and audit preparation. People still own the risk assessment and the audit judgment.
  • Automation does not shorten the audit. The certification body sets audit time from the number of people in scope: the ISO/IEC 27006 audit-time table allows 10 days for an initial certification at 46 to 65 people, and surveillance audits are usually scoped at roughly a third of that. What gets shorter is the preparation.
  • An ISO 27001 certification on the traditional consulting route costs EUR 23,000 to 49,000 in year one for a company under 50 people, and EUR 37,000 to 80,000 for 50 to 200 people. The annual surveillance audit from year two adds EUR 4,000 to 10,000.
  • Annex A of ISO 27001 contains 93 controls in four categories: 37 organizational, 8 people, 14 physical, and 34 technological. A large share maps onto SOC 2 criteria and onto GDPR Art. 32, which is why the payoff from automation grows with every framework you add.
  • NIS2 has applied in Germany since 6 December 2025. For high-risk AI systems under the EU AI Act, Regulation (EU) 2026/1744 of 8 July 2026 moved the obligations to 2 December 2027 and 2 August 2028.

What compliance automation actually automates

Compliance automation means your evidence, control checks, and documentation come out of the systems your company already runs, instead of being assembled by hand once a year. A platform reads state from your identity provider, your code repository, your cloud, and your HR system, compares it against a framework's requirements, and records the result with a timestamp.

The change that matters most is the cadence. Traditional compliance is a point-in-time assessment: a control counts as effective because it was effective during the audit window. Between two audits the state can drift, and nobody notices. That gap explains why teams preparing for an audit keep finding deviations that are months old.

Four areas absorb most of the benefit. Evidence collection comes first: access lists, joiner and leaver records, backup logs, and training records. Control monitoring comes second, meaning the continuous check on whether a configuration still matches its documented target state. Policy management comes third, covering versioning, distribution, and read receipts. Audit preparation comes fourth, because a single evidence repository cuts the auditor's follow-up requests to a fraction.

Judgment does not automate. Whether a risk is acceptable, whether an exception is defensible, whether a measure is appropriate within the meaning of GDPR Art. 32: someone has to decide those, and document the decision. A platform can prepare the decision. It cannot make it.

Compliance automation at a glance
What it isEvidence and control checks generated automatically from source systems rather than by hand
What automatesEvidence collection, control monitoring, policy management, audit preparation
What does notScope definition, risk assessment, policy content, audit judgment
Typical frameworksISO 27001, GDPR, NIS2, SOC 2, TISAX, C5, ISO 42001
Where the payoff sitsIn preparation and in day-to-day operation, not in the audit itself
PreconditionA defined scope and clear ownership

Compliance management system, ISMS, and platform: three different things

People use these three terms interchangeably, and that confusion causes a good share of failed rollouts.

A compliance management system is the organizing structure. It records who owns which requirement, which controls exist, how evidence is produced, and how deviations get handled. It is not a product. An information security management system, an ISMS under ISO 27001, applies the same principle to information security; clauses 4 to 10 of the standard set out the parts it must have. A platform is the tool you run the system in.

A clean compliance management system pays off in three specific ways: every requirement has exactly one owner, every piece of evidence exists once and gets reused, and every change leaves an auditable history. Get those three right and automation becomes a question of connecting systems. Get them wrong and the platform automates a mess. So build the system first, then pick the tool. Our guide to ISO 27001 certification covers how to cut the scope before you start.

Which compliance processes automate and which do not

The short answer: anything that queries a checkable system state automates, and anything that requires a judgment does not. That dividing line beats any feature list, because it still holds when a new framework arrives.

TaskAutomatesStays with people
Collecting evidence (access, backups, training)Fully, from the source systemsChoosing which sources are in scope
Monitoring controlsContinuously, with drift alertsDefining the target state
Distributing policies and collecting acknowledgmentsFully, reminders includedWriting and approving the policy
Maintaining the risk registerStructure, reminders, links to controlsScoring likelihood and impact
Records of processing under GDPR Art. 30Capture, versioning, deadlinesLegal basis and purpose
Answering customer security questionnairesPre-filling from the evidence baseApproving the answer
Audit judgment and certification decisionDoes not automateAccredited certification body

One misconception comes up in almost every first conversation: that automation replaces the auditor. It does not, and it must not. An accredited certification body issues an ISO 27001 certificate, an auditor issues a SOC 2 report, and a C5 attestation follows the BSI's criteria. A platform improves the evidence you bring into that process. It does not shorten the process.

The second mistake is a sequencing error. Teams buy a tool and define the scope afterward. That reliably produces evidence for systems nobody needed and gaps in systems that mattered, because the scope determines which systems are relevant in the first place.

Automating compliance audits: what actually changes in the audit cycle

This is where the category oversells itself, so it pays to be precise. Your maturity does not set the length of an external audit. The number of people in scope does. The ISO/IEC 27006 audit-time table sets the frame for the initial certification, and the certification body can adjust it in practice by up to 30 percent. The surveillance figures in the right-hand column are not separate published values; they reflect the customary practice of scoping a surveillance audit at roughly a third of the initial audit time.

People in scopeInitial certification (audit days)Surveillance audit (about one third)
1 to 1051.7
11 to 2572.3
26 to 458.52.8
46 to 65103.3
66 to 85113.7
86 to 125124.0
126 to 175134.3

Automation therefore acts on everything around the audit rather than on the audit. Before: the evidence already exists instead of taking four to six weeks to assemble. After: drift surfaces during operation rather than at the next assessment cycle.

The second effect is how the load spreads. In a manual program the compliance team does not carry it alone; every department that sits interviews and digs out records carries part of it too. Once those records live in one place, most of that disruption leaves the business. Teams that have been through several cycles recognize the pattern, which we cover separately in our piece on audit fatigue.

What automated compliance monitoring actually checks

"Continuous monitoring" stays abstract until you look at the queries behind it. Each one compares a state against a defined target, and most of them fall within the 34 technological controls of Annex A.

Eight checks do most of the work. The reconciliation between the HR system and the identity provider, so a departure surfaces within hours instead of at the next access review. Multi-factor authentication coverage, measured across all accounts rather than administrator accounts alone. Disk encryption on the endpoints in scope. Backup success and, checked far less often, the result of the last restore test. Patch currency against your own deadline rather than an industry average. Cloud configuration, meaning publicly reachable storage, open ports, and use of privileged access. Role separation in the code repository, especially whether anyone can merge their own changes without review. And policy and training acknowledgment per person.

A platform covers those eight without manual work, and those eight are exactly what an annual sampling exercise keeps failing. An account still active three months after someone left shows up as a finding in an annual review. In continuous monitoring it shows up on the day they leave.

The reverse matters just as much. Monitoring cannot cover physical controls such as building access, cannot establish the effectiveness of supplier controls where you depend on third-party evidence, and cannot tell you whether people actually follow a documented process. Nothing technical substitutes for that third one. It is why the internal audit stays a distinct job even in a heavily automated program, and our guide to internal audits goes into how to run one.

Reconciling documented process against real process is also the one part of audit preparation that stays manual. Someone has to sit with the people who run the process and check whether the runbook matches what they actually do, and no integration produces that answer.

Rolling it out in four phases

Rollouts rarely fail on the technology. They fail when the sequence slips. The figures below describe a company of 30 to 80 people implementing one framework; the duration moves with the size of the scope and the number of systems you connect.

PhaseContentGuide valueOwner
1. Scope and inventoryFix the sites, systems, and people in scope; review existing evidence and policies2 to 3 weeksManagement, compliance owner
2. Connect systemsConnect identity, cloud, code repository, HR, and device management1 to 2 weeksIT
3. Close gapsStand up missing controls, approve policies, roll out training, score the risk register4 to 6 weeksDepartments, with expert support
4. Operate and prepareContinuous control monitoring, internal audit, management review, book the auditongoingCompliance owner

Phase 3 is the one better software cannot compress. A missing control has to be built and then run, and the certification body expects evidence from live operation. ISO 27001 itself sets no minimum operating period before the audit. A floor still exists indirectly: a completed internal audit and a management review have to precede the certification decision, and both need a period to look back over. In practice auditors expect several weeks to three months of operating evidence, depending on the control.

One note on the order of phases 1 and 2. Connecting systems first is tempting, because it produces visible results fast. But the scope decides which systems matter, and it later drives both the audit time and the audit fee. Correcting the scope afterward means repeating parts of phases 2 and 3.

Phase 4 is where most teams want a checklist rather than a principle, and our external audit checklist walks the preparation through step by step.

We are already certified: is switching still worth it?

Yes, and the calculation is different from a first certification. Once the certificate is in hand you are no longer buying a certification; you are replacing the manual work that keeps running behind it. That makes the tooling question a different decision from building the programme in the first place. It is not about the 8.5 or 10 audit days in the table above, but about the four to six weeks of evidence gathering that a manually run programme repeats every year.

A manually run programme has three tells. Systems and vendors sit in several separate spreadsheets, because each department keeps its own. New joiners enter the compliance process only when somebody remembers to add them. And most of the coordination runs over email and PDF, because there is no shared place where the current state can be read off.

One Kertos customer in the personal finance app space, on the platform for close to three years, came through exactly that route. Data protection had previously been handled by an external provider working only from PDF documents and email, which according to the company meant well over a hundred emails a week arriving in one inbox at peak. Two things changed the most. Automated discovery of systems and vendors replaced the round through the departments, where every spreadsheet used to be collected separately. And because the HR system is connected, new joiners appear in the process on their own and can be invited straight from there, with nobody keeping a list.

A common misconception at this point: that switching shortens the next surveillance audit. It does not. Audit time follows the number of people in scope, not the form your documentation takes. What shortens is the preparation, and in a running programme that is the item which comes back every year.

The switch itself costs effort, and it lands in one nameable place. The existing record has to be migrated once: records of processing, risk assessment, policies, and evidence from the last audit cycle. That is weeks of work rather than months, because the content already exists and is only changing address. Whether the route holds depends mostly on whether your systems can be connected, and Kertos covers more than 100 integrations for that. What the ongoing work looks like afterward, if the role stays filled from outside, is set out in our piece on the external data protection officer.

What compliance automation costs

Reliable figures exist where you buy something externally: consulting, implementation, and audit fees. The breakdown below covers the traditional consulting route to an ISO 27001 certification, which is where most European mid-market companies first meet the numbers. Our analysis of the ROI of automation sets the manual and automated routes side by side on the investment case.

Cost blockStart-up (under 50)Scale-up (50 to 200)
Gap analysis and preparationEUR 5,000 to 15,000EUR 10,000 to 25,000
ImplementationEUR 10,000 to 20,000EUR 15,000 to 35,000
Certification audit feesEUR 8,000 to 14,000EUR 12,000 to 20,000
Total year 1 (traditional consulting route)EUR 23,000 to 49,000EUR 37,000 to 80,000
Annual surveillance audit (from year 2)EUR 4,000 to 7,000EUR 6,000 to 10,000

Two things are deliberately missing. The table excludes internal staff cost, which is the largest line item in a manual program. And the surveillance audit falls in year two, which is why it sits below the annual total. Budget the audit fee alone and you will underestimate the project by a factor of three to four.

Here is the shape of it in practice. A 45-person SaaS company goes for ISO 27001 because two enterprise deals depend on it. It assigns one internal owner at 50 percent of their time, runs on a platform rather than a consulting project, and pays a low five-figure sum for the certification audit. The audit-time table puts the initial audit at 8.5 days. The difference against the consulting route shows up in the gap analysis and implementation blocks, not in the audit fee.

How to measure whether it works

The usual measurement asks two questions: did we get the certificate, and how many findings did we have? Both are annual numbers, and both arrive too late to change a decision. Introduce automation and you need measures that move monthly.

Five hold up in practice:

  1. Share of controls under continuous monitoring. Most companies select 60 to 80 of the 93 Annex A controls. What matters is how many of those get checked automatically rather than by sampling. This ratio is the most direct read on maturity.
  2. Time to evidence. How long does it take to produce a specific record on request? That number drives audit effort and sales velocity alike.
  3. Open deviations in operation. Not audit findings, but the drift you catch and fix between audits. A rising number here is a good sign at first, because it means you can see more.
  4. Time spent on security questionnaires. In B2B sales the security questionnaire is often the bottleneck. Turnaround time is a measure people outside the compliance team understand.
  5. Time to first certification. Measurable once, and the number budget decisions rest on.

All five measure state rather than activity. A measure like "documents maintained" rewards busywork. A measure like "share of controls checked automatically" rewards effectiveness. Our piece on how AI is changing risk management carries the same logic into risk scoring.

Running several frameworks at once

With a single framework the payoff from automation is modest. It grows with each additional one, because the evidence overlaps.

Annex A of ISO 27001 contains 93 controls in four categories: 37 organizational, 8 people, 14 physical, and 34 technological. A large share of them maps directly onto the criteria behind a SOC 2 report, and another share covers GDPR requirements, particularly the technical and organizational measures under Art. 32. An access log is an access log, whatever framework asks for it.

European companies also work against two fixed dates. NIS2 has applied in Germany since 6 December 2025 and brings registration and reporting duties for entities in scope. For high-risk AI systems under the EU AI Act, Regulation (EU) 2026/1744 moved the obligations to 2 December 2027 and 2 August 2028. Both push the arithmetic the same way: the more frameworks run at once, the more expensive it gets to run them separately.

We cover how to bring those frameworks together rather than side by side in our piece on one platform for ISO 27001, GDPR, and SOC 2. The framework-specific guides sit separately: the NIS2 Directive and GDPR.

A word on terminology, because proposals and RFPs get it wrong constantly. ISO 27001 produces a certification. SOC 2 produces a report, not a certificate. The BSI's C5 produces an attestation, a Testat. TISAX produces an assessment and a label. NIS2, GDPR, and the EU AI Act are regulations you comply with; none of them contains a certification, whatever some vendors imply. Use the wrong word in a customer conversation and you lose credibility with exactly the people who know the difference.

Compliance in automated business processes: the reverse question

Everything above is about automating compliance. The reverse question comes up in the same words: what do you need to watch when you automate a business process that touches personal data? That is a different problem, and no platform answers it.

Three points carry most of the weight. Documentation comes first: any automated process handling personal data belongs in your records of processing under GDPR Art. 30, with purpose, legal basis, recipients, and retention periods. Traceability comes second: automated flows need a log showing what happened, when, and on what basis, or you cannot evidence the processing at all. The limit in Art. 22 comes third: decisions taken solely by automated means that produce legal effects for a person, or similarly significantly affect them, are permitted only on narrow grounds. A credit decision or an automated candidate rejection falls inside that; an automated invoice check does not.

Bring an AI system into the process and the EU AI Act applies alongside, where the classification decides how much you owe. Whether a system counts as high-risk is the first question to settle, not the last.

The practical connection back to this article: both draw on the same evidence. Automate a process and keep its documentation in the same system as your controls, and the evidence exists once. Keep them apart and it exists twice, then diverges within six months. That shows up most sharply in the most common case, handling data subject access requests, where statutory deadlines are running.

Common mistakes

The most expensive mistake is automating a broken process. If nobody knows who approves a policy, automating its distribution will not fix that; it will surface it faster. Settle ownership before the rollout, not after.

The second most common is expecting the platform to define your scope. It does the opposite: it assumes one. Which sites, which systems, and which people fall in scope is a management decision, and it determines both audit time and cost later.

The third sits in the selection itself. Most comparisons run on feature lists, when the practical difference usually comes down to two other questions: which of your systems actually connect, and who does the work the platform does not do. Our buyer's guide to ISO 27001 compliance tools sets out what to weigh. If you have no structure yet, start with the guide to building an ISMS.

Compliance automation with Kertos

Kertos is a European compliance automation platform that runs information security and data protection in one system. The platform collects evidence from your existing systems, monitors controls continuously, and maps ISO 27001, GDPR, NIS2, SOC 2, TISAX, and C5 onto a shared evidence base, so one record counts for several frameworks.

What separates this from a pure software approach is the division of labor. Certified experts come with the platform and take on the work that does not automate: scope, risk assessment, policy content, and support through the audit. In practice that cuts manual compliance effort by around 80 percent, and the audit success rate stands at 100 percent.

The work with AskUI shows the shape of it: ISO 27001 certification in 8 to 10 weeks, without external consultants, with ISO 42001 as the next step. To see what that looks like for your scope, book a demo.

Frequently asked questions

What is compliance automation?

Compliance automation means evidence, control checks, and documentation are generated automatically from the systems a company already runs, rather than collected by hand. It covers the repeating work: evidence collection, control monitoring, policy management, and audit preparation. Assessments and decisions stay with people.

Which compliance processes can be automated?

Anything that queries a checkable system state automates: access lists, backup logs, joiner and leaver records, training records, configuration checks, and pre-filling security questionnaires. Risk assessments, policy approval, scope definition, and the audit judgment do not automate.

Does automation make an audit shorter?

No. Certification bodies set audit time from the number of people in scope, not from your level of automation. The ISO/IEC 27006 audit-time table allows 10 audit days for an initial certification at 46 to 65 people, and the body can adjust that by up to 30 percent in practice. Surveillance audits are usually scoped at about a third of that time. Preparation gets shorter; the audit does not.

What does an ISO 27001 certification cost?

On the traditional consulting route, year one runs EUR 23,000 to 49,000 for companies under 50 people and EUR 37,000 to 80,000 for 50 to 200 people. That covers gap analysis, implementation, and certification audit fees, and excludes internal staff cost. The annual surveillance audit from year two adds EUR 4,000 to 10,000.

Is compliance automation worth it for a single framework?

With one framework the benefit is limited and sits mainly in continuous monitoring replacing annual sampling. The payoff grows with each additional framework, because the evidence overlaps: a large share of the 93 Annex A controls in ISO 27001 maps onto SOC 2 criteria and onto the requirements of GDPR Art. 32.

The Founder's Guide about NIS2: Prepare your company Now before

Protect your startup: Discover how NIS2 can impact your business and what you need to consider now. Read the free white paper now!

Ready, your compliance to put on autopilot?
Dr. Kilian Schmidt

Dr. Kilian Schmidt

CEO & Co-Founder at Kertos

Kilian had a strong focus on legal processes from an early age and began his career at Home24 as a Senior Legal Counsel and Data Protection Officer for the Home24 group. After a stint at Freshfields Bruckhaus Deringer, he moved to TIER Mobility, where he expanded the company's legal and public policy departments from one to 65 cities and from 50 to 800 employees. Driven by the lack of technology in the legal field and confirmed by his consulting work at Gorillas Technologies, he decided to found Kertos to develop the next generation of compliance – made in Europe.

About Kertos

Kertos is the modern backbone of the data protection and compliance activities of scaling companies. We enable our customers to implement integrated data protection and information security processes in accordance with GDPR, ISO 27001, TISAX®, SOC2 and many other standards quickly and cheaply through automation.

Ready to simplify GDPR compliance?

CTA Image

📅 Schedule Your 5min Compliance Check

Please enter your business email to continue. We require a company email address to ensure we can best serve your organization.

📞 5min Compliance Check