Why compliance automation has a hard ceiling

compliance

Compliance teams have leaned hard into automation, connecting cloud consoles, identity providers, endpoint tools and code repositories to pull evidence on a schedule rather than screenshotting their way through audit season.

According to Copla, the appeal is obvious: continuous monitoring catches misconfigurations before an auditor does, and it removes the manual re-gathering that eats hours every quarter. But the technology has a ceiling, and it sits in a fixed place regardless of how sophisticated the platform claims to be.

Copla recently discussed automated evidence collection, and what it can and cannot do and why it matters. 

What automates well is anything that reduces to a machine-readable fact about a system state: MFA enforcement, encryption at rest, patch levels, merge approvals, offboarding status. Six categories, roughly, cover most of what an integration returns, each tagged with provenance, source, timestamp, and collector, which is precisely what gives an auditor confidence a screenshot never could.

What does not automate is anything that represents a human decision rather than a system state. Board minutes, contractual exit clauses, risk acceptance rationales, and sign-off on what an AI model is allowed to do before it reaches a customer all sit on the far side of that line. No integration can confirm someone weighed a risk and accepted it; that record only exists if a person wrote it down.

Crucially, the size of that ceiling shifts by framework. SOC 2 Type II and PCI DSS map closely onto technical configuration, so automation reaches furthest there. DORA sits at the opposite end, built on contractual arrangements, register-based reporting and board-level ICT oversight, which is governance work an API cannot touch. ISO 27001 splits down the middle, with Annex A automating cleanly while the ISMS layer behaves more like DORA.

A vendor quoting 90% automation on a SOC 2 estate may be entirely accurate and still say nothing useful about a DORA assessment.

Even within what does automate, collected evidence is not automatically valid. Evidence expires, whether that’s a training record for someone who left months ago or a penetration test now a year stale.

A passing test can also confirm the wrong thing, checking that MFA is switched on tenant-wide without catching the one unrotated admin account that actually matters. That is why platforms such as Copla pair automated collection with an AI validity review that flags stale or thin evidence, alongside an in-house team to handle the governance work automation was never going to reach, while still requiring a person to confirm before anything counts as reviewed.

The practical takeaway for buyers: ask what percentage of your specific framework’s control set automates, not the vendor’s best-case customer, and ask what happens to everything left over.

Read the full Copla post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.