Cyber GovernanceISO Certification4-minute read·Marcin Pajdzik·May 2026

Governing a Compliance Platform

Compliance platforms like Drata centralise the control framework, evidence and ownership structure that an auditor interrogates. Their value depends entirely on whether what is in them reflects the organisation's actual control environment.

Management operates the platform day to day. The board's separate need is assurance that the compliance position it represents can actually be relied upon.

Platform as audit record

Many ISO 27001 and SOC 2 programmes use compliance automation platforms to organise controls, evidence and audit activity. Drata, Vanta and their equivalents centralise the control framework, collect evidence and provide a structured record for audit. The auditor assesses the control environment against the applicable criteria, with the platform providing a structured source of controls and supporting evidence.

When the platform is configured and then left largely unchanged, it begins to describe an earlier version of the organisation. Controls accurate at launch may no longer map to current systems, team structures or supplier relationships. The resulting gap between the recorded and actual control environment undermines both management assurance and audit readiness.

What strategic oversight covers

Three areas determine whether that assurance can be relied upon.

Control structure
The controls in the platform need to be correctly scoped to the organisation's actual environment and mapped to the applicable framework requirements. Mapping one control to several framework requirements is not itself a problem, and cross framework mapping is one of the advantages these platforms offer. The governance question is whether those mappings remain clear enough for the auditor to determine what is satisfied and for management to rely on the compliance position the platform presents.
Ownership
Named control owners need to be the people actually responsible for maintaining those controls in practice. Ownership that does not correspond to operational accountability can leave controls without effective oversight and create gaps when evidence is required. Ownership requires regular confirmation as responsibilities change.
Evidence quality
Evidence should arise naturally from the normal operation of functioning processes. An experienced auditor will assess whether it demonstrates consistent operation over time or was prepared for the audit window.

The auditor and the platform

Where the platform is used as the audit workspace, the auditor may review controls and evidence directly within it. Where platform related friction arises, two common causes are configuration that makes evidence retrieval difficult and limited auditor experience with the platform in use.

Both can be addressed. Configuring the platform so that evidence can be retrieved and traced efficiently reduces the first. Selecting an auditor with relevant experience of the platform reduces the second. Both are easier to resolve before the next audit cycle begins.

How this affects your organisation

If a compliance platform sits at the centre of your audit programme, the board's assurance is only as good as the review process that keeps the platform current. The board should therefore expect clear accountability for that review, authority to confirm or reassign control ownership, and an effective working relationship between the compliance function and the auditor.

If the current auditor cannot work efficiently with the platform, the resulting friction has a cost that does not improve the organisation's underlying compliance position.

If you are reviewing how your compliance platform is governed or considering a change of auditor, I can help you structure that decision.

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.