Automated compliance evidence hits a hard limit at 40-60%
Technical controls map to APIs, but board decisions, contracts, and risk rationales still require human documentation.
The promise and boundary of automated evidence
Automated evidence collection has become standard practice in compliance programs, continuously pulling data from cloud platforms, identity systems, endpoint tools, and code repositories. Every artifact carries a timestamp and source attribution—exactly what auditors need to verify completeness and integrity.
But according to compliance platform Copla, which recently analyzed the practical limits of automation, these systems can only verify conditions that machines can check through API queries. That boundary defines where automation ends and manual work begins.
What automation can and cannot reach
The systems feeding automated compliance pipelines typically span six categories: identity and access management, infrastructure configuration, endpoint management, change management, vulnerability scanning, and HR records. Each integration returns machine-readable facts—MFA enforcement status, encryption settings, patch levels, merge approvals—that map directly to specific controls.
Beyond that technical perimeter sits a substantial portion of any compliance file that no integration will capture. Board meeting minutes, contractual exit clauses, risk acceptance rationales, change advisory board discussions, and third-party attestations like SOC 2 reports all depend on human decisions being documented, not system states being queried. AI and model governance decisions require sign-off before there's anything to log.
Framework-specific automation ceilings
How much of a compliance program can realistically be automated varies dramatically by framework. SOC 2 Type II and PCI DSS sit closest to full automation because their criteria map directly onto technical configuration.
DORA and NIS2 occupy the opposite end, relying heavily on contractual arrangements, registers, and board-level oversight that automation cannot touch. ISO 27001 splits the difference: its Annex A controls automate well, while the surrounding Information Security Management System layer behaves more like DORA.
When automated evidence fails
Even where automation works, collected evidence isn't automatically valid. Evidence expires—a policy reviewed 13 months ago or training records for departed employees may appear current in the repository when they're not. A passing automated test confirms only that a defined condition holds, not that the underlying control was scoped correctly.
For these reasons, evidence still requires human review to confirm sufficiency and relevance before reaching an auditor. AI is increasingly used to flag stale or mismatched evidence, but it doesn't replace that final human judgment.
Why it matters
Vendors selling compliance automation often imply near-complete coverage, but the reality is that 40-60% of most frameworks—especially newer regulations like DORA and NIS2—resist automation entirely. Organizations building compliance programs need to budget for the manual documentation, governance processes, and human review that automation will never eliminate. Understanding this ceiling prevents over-investment in tools that can't deliver what's promised and ensures resources are allocated to the human processes that still matter most.
These details were first reported by FinTech Global, based on analysis published by Copla.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call