Automation

Automated compliance evidence hits a hard limit at 40-60%

Technical controls map to APIs, but board decisions, contracts, and risk rationales still require human documentation.

Omega Editorial· August 20, 2026· 3 min read

The promise and boundary of automated evidence

Automated evidence collection has become standard practice in compliance programs, continuously pulling data from cloud platforms, identity systems, endpoint tools, and code repositories. Every artifact carries a timestamp and source attribution—exactly what auditors need to verify completeness and integrity.

But according to compliance platform Copla, which recently analyzed the practical limits of automation, these systems can only verify conditions that machines can check through API queries. That boundary defines where automation ends and manual work begins.

What automation can and cannot reach

The systems feeding automated compliance pipelines typically span six categories: identity and access management, infrastructure configuration, endpoint management, change management, vulnerability scanning, and HR records. Each integration returns machine-readable facts—MFA enforcement status, encryption settings, patch levels, merge approvals—that map directly to specific controls.

Beyond that technical perimeter sits a substantial portion of any compliance file that no integration will capture. Board meeting minutes, contractual exit clauses, risk acceptance rationales, change advisory board discussions, and third-party attestations like SOC 2 reports all depend on human decisions being documented, not system states being queried. AI and model governance decisions require sign-off before there's anything to log.

Framework-specific automation ceilings

How much of a compliance program can realistically be automated varies dramatically by framework. SOC 2 Type II and PCI DSS sit closest to full automation because their criteria map directly onto technical configuration.

DORA and NIS2 occupy the opposite end, relying heavily on contractual arrangements, registers, and board-level oversight that automation cannot touch. ISO 27001 splits the difference: its Annex A controls automate well, while the surrounding Information Security Management System layer behaves more like DORA.

When automated evidence fails

Even where automation works, collected evidence isn't automatically valid. Evidence expires—a policy reviewed 13 months ago or training records for departed employees may appear current in the repository when they're not. A passing automated test confirms only that a defined condition holds, not that the underlying control was scoped correctly.

For these reasons, evidence still requires human review to confirm sufficiency and relevance before reaching an auditor. AI is increasingly used to flag stale or mismatched evidence, but it doesn't replace that final human judgment.

Why it matters

Vendors selling compliance automation often imply near-complete coverage, but the reality is that 40-60% of most frameworks—especially newer regulations like DORA and NIS2—resist automation entirely. Organizations building compliance programs need to budget for the manual documentation, governance processes, and human review that automation will never eliminate. Understanding this ceiling prevents over-investment in tools that can't deliver what's promised and ensures resources are allocated to the human processes that still matter most.

These details were first reported by FinTech Global, based on analysis published by Copla.

#compliance automation#regtech#evidence collection#governance#audit readiness#dora

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Automation

Automation· 3 min read

WhatsApp Commerce Drives $530M in Revenue Across 317 Brands

Meta partner Zefir releases benchmark data showing 88% average open rates and double-digit ROI across customer lifecycle automation.

Via Automation Watch · Sep 24, 2026
Automation· 3 min read

Five Million Industrial Robots Now Operating Worldwide

China accounts for 59% of global deployments as Asia drives adoption, while Europe lags and the U.S. overtakes Japan in market size.

Via Automation Watch · Sep 24, 2026
Automation· 4 min read

Simbe's 3,000 Tally Robots Mark Shift to Public-Space Automation

The retail inventory robot's commercial milestone signals robotics moving beyond controlled factory floors into unpredictable human environments.

Via Automation Watch · Sep 24, 2026