Compliance tools

Automated evidence collection: what access it needs

7 September 2026 · 8 min read · CertAssist

What a compliance platform reads from your systems to automate evidence, which controls it can never cover, and when a small team is better off without it.

Automated evidence collection is a compliance platform reading your live systems on a schedule and saving what it finds as audit evidence. To do that, the platform holds standing credentials into your cloud account, your identity provider, your code repository and often your HR system. Vanta, for example, assumes a read-only IAM role inside your AWS account. That standing access is the real price of automation, and for a team of ten it usually buys less than the marketing suggests.

What is automated evidence collection?

Automated evidence collection is the practice of having a compliance platform connect to your production systems, query them at intervals, and file the results as dated evidence against a control. Instead of a person taking a screenshot of your multi-factor authentication settings every quarter, the platform reads the identity provider every day and records the answer.

The value is real and it is narrow. Automated evidence collection is good at facts a machine can observe: which accounts have MFA turned on, whether disk encryption is enforced, whether a storage bucket is public, whether backups ran. It is useless for anything requiring a decision, a signature or a judgement.

What access does automated evidence collection require?

Automated evidence collection requires long-lived, read-level credentials into every system it monitors. This is not a criticism of any vendor, it is simply how the technique works: to read your configuration continuously, something has to be permanently authorised to read it.

Vanta documents its AWS integration as a cross-account IAM role, usually named vanta-auditor, with a trust policy allowing Vanta's AWS account to assume it. The role carries the AWS managed SecurityAudit policy plus a vendor-specific additional policy, and Vanta states the access is read-only with sensitive data actions explicitly denied. That is a well-designed integration. It is also a live path from a third party into your production account that persists for the length of the subscription.

Table of the access automated evidence collection requires: cross-account read-only role for AWS Azure or GCP, directory and audit log read for the identity provider, organisation and repo read for the code repository, employee record read for the HR system, an installed agent on the endpoint fleet, and project and issue read for the ticketing system

Multiply that by the number of connectors you switch on. Vanta advertises integrations with more than 400 tools. Every one you enable is another credential, another vendor holding a key to a system you care about, and another thing to review when someone asks how your compliance tooling is secured.

Which controls can automated evidence collection actually cover?

Automated evidence collection covers the machine-readable slice of a framework and leaves the rest to you. ISO 27001:2022 sets out 93 Annex A controls across four themes: 37 organisational, 8 people, 14 physical and 34 technological. The technological theme is where automation earns its keep. The organisational theme, which is the largest, is almost entirely documents and decisions.

Two-column comparison showing what automation can read, including MFA enforcement, disk encryption, public bucket checks, logging, backups and branch protection, against what you produce either way, including the Statement of Applicability, risk assessment, policy set, management review minutes, internal audit report and supplier due diligence

The same holds for SOC 2. The common criteria include control environment, communication, risk assessment, monitoring and change management. An integration can show you that change management tickets exist. It cannot decide whether your risk assessment is credible, and no auditor will accept a machine reading in place of one. See what auditors really look for in your evidence for what actually gets a finding raised.

Is a compliance platform with integrations a security risk?

A compliance platform with integrations adds a vendor to the list of third parties with standing access to your production environment, so it belongs in your own vendor risk register alongside every other supplier. Third-party access is a well-documented breach path: a compromise at a supplier becomes a compromise at every customer whose systems that supplier can reach.

This is not a reason to avoid automation. Reputable platforms scope access tightly, deny sensitive data actions and publish their own audit reports. It is a reason to answer three questions before you connect anything:

For a company with 2,000 employees and a sprawling cloud estate, the answer to the third question is usually yes. For a company with fifteen people and one AWS account, it very often is not.

What does automated evidence collection cost?

Automated evidence collection is the feature the major compliance platforms charge for, and most of them will not tell you the figure without a sales call. As at 7 September 2026, Vanta's pricing page publishes no list price and asks you to book a demo. Secureframe publishes a Fundamentals package starting at US$7,000 a year. CertAssist publishes its full price on the page: US$225 per month as a limited-time launch offer, normally US$375 per month, or US$3,999 a year.

What you are buyingPublished price, 7 September 2026System access required
VantaNo list price published; demo requestedCross-account IAM role, identity provider, and other connectors as enabled
SecureframeFundamentals from US$7,000 per yearCloud, identity and device integrations
CertAssistUS$225 per month launch price, normally US$375 per month, or US$3,999 per yearNone. CertAssist connects to no systems
Your certification body or CPA firmCharged separately by the auditor, never included in any platform feeRead-only review access you grant for the audit

None of these figures includes the audit itself, your own team's time, or a consultant if you use one. For a fuller breakdown of the numbers behind a first certification, see compliance software pricing.

When should a small team skip automated evidence collection?

A small team should skip automated evidence collection when the environment is small enough that a person can observe it faster than an integration can be configured and maintained. If you have one cloud account, one identity provider, thirty laptops and a single product, the evidence for your technological controls is perhaps two hours of work per quarter. Automation does not save two hours per quarter once you count the setup, the exception triage and the vendor review.

Skip it when any of the following are true:

Conversely, keep automated evidence collection when you run multiple cloud accounts across several business units, when you maintain three or more frameworks at once, or when continuous monitoring is itself a customer requirement. Those are real problems and automation genuinely solves them.

How do you collect evidence without granting system access?

You collect evidence without granting system access by fixing the evidence list first and then gathering artefacts by hand against it. The reason manual collection has a bad reputation is not the gathering, it is the not knowing what to gather. A control board that states the required documentation and evidence for each control turns a vague chore into a finite checklist.

CertAssist works this way by design. It lays out every control in the framework with the documentation and evidence expected against each one, gives you editable policy and evidence templates so you are not writing from a blank page, handles the Statement of Applicability, and gives your auditor read-only access to review it all in one place. CertAssist requires no integrations, holds no credentials to your systems and pulls no data from them, so there is nothing to configure and nothing for an attacker to reach through. The trade is explicit: you take the screenshots yourself, and you do not hand anyone a key to production.

If your environment is large and complex enough that the screenshots are genuinely the bottleneck, an integrated platform is the better tool and you should buy one. For most companies of 5 to 200 people chasing a first certification, the bottleneck is knowing what the auditor wants, not fetching it.

Frequently asked questions

How do I collect compliance evidence automatically?

You connect a compliance platform to the systems that hold the evidence, then it reads them on a schedule. Typically that means a read-only role in AWS, Azure or GCP, directory access to your identity provider, and read access to your code repository and HR system. The platform stores each reading as a dated artefact against a control. It automates observation, not judgement.

How do you automate evidence collection for SOC 2 compliance?

For SOC 2 you map each Trust Services Criterion to a system that can prove it, then let the platform sample that system across the observation window. Automation suits access control, encryption, logging and change management. It cannot produce your risk assessment, vendor reviews or management review minutes, so a SOC 2 Type II still needs a person assembling the narrative evidence by hand.

What is evidence collection in a compliance management platform?

Evidence collection is the act of gathering and storing proof that a control is in place and operating. In a compliance management platform it means attaching dated artefacts to each control: a screenshot, an exported configuration, a signed policy, an approval record or a log extract. Some platforms fetch those artefacts automatically. CertAssist gives you a checklist and a place to upload them instead.

How do you simplify evidence collection for an ISO 27001 compliance audit?

Decide the evidence for each Annex A control before you start collecting, so nothing is gathered twice or missed. ISO 27001:2022 has 93 Annex A controls, and most of the effort sits in documents you write once: the Statement of Applicability, the risk treatment plan and the policy set. Fixing the list first removes far more work than automating the screenshots.

Is a SOC 2 evidence collection spreadsheet good enough?

A spreadsheet works for a first Type I in a small company, and plenty of teams have passed with one. It fails once you have several frameworks, a Type II observation window or staff turnover, because the spreadsheet holds the index but not the artefacts and nobody can tell which version the auditor saw. A structured control board with the evidence attached solves that without needing integrations.

Related guides

Get certified without handing over the keys

CertAssist lays out every control with the evidence expected against it, gives you editable policy and evidence templates, and lets your auditor review it all in one place. No integrations, no system access, US$225 a month.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat US$225 a month launch price (normally US$375), or US$3,999 a year (12 months for the price of 11). All prices in USD.