Automation

Automated compliance evidence hits a hard limit at 40-60%

Technical controls map to APIs, but board decisions, contracts, and risk rationales still require human documentation.

Omega Editorial· August 20, 2026· 3 min read

The promise and boundary of automated evidence

Automated evidence collection has become standard practice in compliance programs, continuously pulling data from cloud platforms, identity systems, endpoint tools, and code repositories. Every artifact carries a timestamp and source attribution—exactly what auditors need to verify completeness and integrity.

But according to compliance platform Copla, which recently analyzed the practical limits of automation, these systems can only verify conditions that machines can check through API queries. That boundary defines where automation ends and manual work begins.

What automation can and cannot reach

The systems feeding automated compliance pipelines typically span six categories: identity and access management, infrastructure configuration, endpoint management, change management, vulnerability scanning, and HR records. Each integration returns machine-readable facts—MFA enforcement status, encryption settings, patch levels, merge approvals—that map directly to specific controls.

Beyond that technical perimeter sits a substantial portion of any compliance file that no integration will capture. Board meeting minutes, contractual exit clauses, risk acceptance rationales, change advisory board discussions, and third-party attestations like SOC 2 reports all depend on human decisions being documented, not system states being queried. AI and model governance decisions require sign-off before there's anything to log.

Framework-specific automation ceilings

How much of a compliance program can realistically be automated varies dramatically by framework. SOC 2 Type II and PCI DSS sit closest to full automation because their criteria map directly onto technical configuration.

DORA and NIS2 occupy the opposite end, relying heavily on contractual arrangements, registers, and board-level oversight that automation cannot touch. ISO 27001 splits the difference: its Annex A controls automate well, while the surrounding Information Security Management System layer behaves more like DORA.

When automated evidence fails

Even where automation works, collected evidence isn't automatically valid. Evidence expires—a policy reviewed 13 months ago or training records for departed employees may appear current in the repository when they're not. A passing automated test confirms only that a defined condition holds, not that the underlying control was scoped correctly.

For these reasons, evidence still requires human review to confirm sufficiency and relevance before reaching an auditor. AI is increasingly used to flag stale or mismatched evidence, but it doesn't replace that final human judgment.

Why it matters

Vendors selling compliance automation often imply near-complete coverage, but the reality is that 40-60% of most frameworks—especially newer regulations like DORA and NIS2—resist automation entirely. Organizations building compliance programs need to budget for the manual documentation, governance processes, and human review that automation will never eliminate. Understanding this ceiling prevents over-investment in tools that can't deliver what's promised and ensures resources are allocated to the human processes that still matter most.

These details were first reported by FinTech Global, based on analysis published by Copla.

#compliance automation#regtech#evidence collection#governance#audit readiness#dora

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Automation

Automation· 4 min read

Cities Deploy AI to Cut Housing Permit Delays by Half

Federal funding is accelerating adoption of tools that scan applications for errors, reducing review cycles from months to weeks.

Via AI Watch · Aug 20, 2026
Automation· 3 min read

PTC Brings Natural Language AI to CAD Automation via Onshape

Engineers can now describe custom CAD features in plain English and let AI generate the underlying FeatureScript code.

Via Automation Watch · Aug 20, 2026
Automation· 3 min read

Hays Pivots Recruitment Strategy Toward AI-Resistant Roles

The global staffing firm cites AI disruption, platform disintermediation, and economic uncertainty as it repositions its hiring focus.

Via AI Watch · Aug 20, 2026