The automation ceiling vendors won’t tell you about

compliance

Automated evidence collection has become a fixture of modern compliance programmes, pulling data from cloud consoles, identity providers, endpoint tools and code repositories on a set schedule rather than relying on manual screenshots gathered in a last-minute scramble before an audit.

According to Copla, every artefact collected this way carries a source and a timestamp, which matters because provenance is precisely what an auditor is trying to establish when they assess whether evidence is complete and unaltered.

Copla recently discussed automated evidence collection, and what it can and cannot do and why it matters. 

The systems that feed this pipeline typically fall into six categories: identity and access, infrastructure configuration, endpoint management, change management, vulnerability scanning and personnel or HR records. Each integration returns machine-readable facts, such as MFA enforcement status, encryption settings, patch levels or merge approvals, that map directly onto specific controls. That is the boundary of what automation can do: verifying a condition that a machine can check by querying an API.

Beyond that boundary sits a substantial share of any compliance file that no integration will ever reach. Board minutes, contractual exit clauses, risk acceptance rationales, change advisory board discussions and third-party attestations such as a supplier’s SOC 2 report all depend on a human decision being recorded somewhere, not a system state being read. AI and model governance decisions fall into the same bracket, since sign-off has to happen before there is anything to log at all.

How much of a compliance programme can realistically be automated also depends heavily on the framework in question. SOC 2 Type II and PCI DSS sit closest to full automation because their criteria map onto technical configuration.

DORA and NIS2 sit at the opposite end, leaning on contractual arrangements, registers and board-level oversight that automation cannot touch. ISO 27001 splits the difference, with its Annex A controls automating well while the surrounding ISMS layer behaves more like DORA.

Even where automation works, collected evidence is not automatically valid. Evidence expires: a policy reviewed over a year ago or a training record for a departed employee may still sit in the repository looking current when it is not. A passing automated test also confirms only that a defined condition holds, not that the underlying control was scoped correctly in the first place.

For these reasons, evidence still needs a person to confirm it is sufficient and relevant before it reaches an auditor, with AI increasingly used to flag stale or mismatched evidence rather than replace that final human review.

Read the full Copla post here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.