Governance, Risk and Compliance
SOC 2 and Compliance Automation: from Spreadsheets to AI agents
SOC 2 and compliance automation has moved from spreadsheets, screenshots and consultant-run annual audits to SaaS platforms like Vanta and Drata that pull evidence through integrations. Since 2025, AI agents collect and evaluate evidence, map controls across frameworks, and draft security questionnaire answers, while humans still own risk decisions and a licensed auditor still signs the opinion.
Autonomy level
2.8 of 5 · Supervised agents
launch score
Projected 4.0 by 2031
- Tasks automated
- 3.0
- Approval load
- 2.5
- Production maturity
- 3.0
Overall is the mean of the three sub-scores. How scores work
The same job, five eras
Drag across the eras to see who did the work, with what, and what broke.
What job does SOC 2 and compliance automation software do?
Compliance software exists to prove one thing to someone who does not trust you yet: that your security controls exist, work, and keep working. The buyer's security team wants a SOC 2 report. The regulator wants evidence. The auditor wants a sample of access reviews from last March.
The job breaks into five chores: define controls, collect evidence that they ran, watch for drift, hand the package to an auditor, and answer the endless security questionnaires that sales deals trigger. For most of the history of this category, every one of those chores was done by a person with a spreadsheet.
Era 1 · Before SaaS · 2002-2017
How did SOC 2 and compliance automation work before SaaS?
Compliance before automation was a calendar event. Sarbanes-Oxley in 2002 made internal controls a board-level problem for public companies, PCI DSS arrived in 2004 for anyone touching card data, and in 2011 the AICPA's SOC reports replaced SAS 70 as the way a service provider proved its controls to customers. Each framework meant a fresh binder of policies and a fresh round of evidence.
The evidence was screenshots. Someone logged into the firewall, the HR system and the cloud console, captured a screen, pasted it into a Word document, and filed it in a shared drive named for the audit year. Control status lived in Excel. Consultants wrote the policies, and the auditor sampled whatever the team could find in the weeks before fieldwork.
I lived this. As Product and Compliance Manager at Sageworks, I built the SOC 2, PCI and ISO programs, and the hard part was never the controls. It was proving, months later, that each control had actually run. If you are starting today, my simple guide to SOC 2 for startups covers what the report asks for.
Large enterprises bought on-prem GRC suites like Archer, which EMC acquired in 2010 and folded into RSA. Those tools organized risk registers and policy libraries well, but they did not collect evidence. A human still fed them, so they mostly gave the spreadsheet a better database.
- Sarbanes-Oxley Act signed, making internal control reporting mandatory for US public companiessource
- PCI DSS 1.0 released by the card brandssource
- EMC agrees to acquire Archer Technologies and folds it into RSAsource
- SSAE 16 takes effect and AICPA SOC 2 reports replace SAS 70 for service providerssource
Era 2 · The Cloud Move · 2018-2022
What changed when SOC 2 and compliance automation moved to the cloud?
The shift started with a founder who hated her own audit. Vanta launched in 2018 after Christina Cacioppo went through a manual SOC 2 at Dropbox Paper. Drata and Secureframe followed in 2020, and Sprinto joined the same wave. The pitch was simple: connect your cloud, identity provider, code repository and HR system, and the platform pulls the evidence for you.
That changed the unit of work. Instead of screenshots, an API call checked that MFA was on, that disks were encrypted, that offboarded employees lost access. Continuous monitoring replaced the pre-audit scramble, and one set of evidence could map to SOC 2, ISO 27001 and HIPAA at once. I compare how the main platforms differ today in Vanta vs Drata vs Sprinto vs Secureframe.
The second shift was on the sales side. Trust centers from vendors like SafeBase put the SOC 2 report, policies and subprocessors behind a self-serve page, so buyers stopped emailing for the same PDF. Pricing settled into annual contracts sized by framework count and headcount.
What did not change: policies still needed a human writer, auditors still sampled evidence by hand, and the integrations only covered what had an API. Anything outside the cloud stack, like board minutes or vendor reviews, was still an upload.
Era 3 · The Copilot Years · 2023-2024
What did AI copilots change in SOC 2 and compliance automation?
Generative AI arrived in compliance through the most hated chore: writing. Secureframe shipped Comply AI in June 2023, which generated infrastructure-as-code fixes for failing cloud tests. Within a year most platforms offered AI policy drafting, control explanations and suggested questionnaire answers drawn from past responses and the trust center.
Questionnaire automation was the clearest win. A 300-question spreadsheet from an enterprise buyer could be pre-filled in minutes from a knowledge base, then reviewed by the security lead. Conveyor, Vanta and Drata all sold this. The human still read every answer, because a wrong answer in a security review becomes a contractual representation.
Policy drafting got faster too, but it exposed a trap I write about in what founders actually need in SOC 2 policies: a generated policy that describes controls you do not run is worse than no policy, because the auditor will test it.
Meanwhile the scope grew. ISO/IEC 42001, the first AI management system standard, was published in December 2023, and the EU AI Act entered into force in August 2024. Compliance teams now had AI to govern as well as AI to help them.
Era 4 · The Agentic Shift · 2025-2026
The Agentic Shift: What do AI agents do in SOC 2 and compliance automation today?
In 2025 the vendors stopped selling suggestions and started selling workers. Drata agreed to buy SafeBase in February 2025 to own the trust center. Conveyor shipped Sue in April 2025, an agent that triages inbound security reviews, drafts answers, chases subject matter experts in Slack and updates Salesforce. Vanta launched its AI Agent in June 2025, starting with policy onboarding and evidence evaluation against audit requirements.
By March 2026 the whole category had rebranded around agents. Vanta introduced compliance, third-party risk and customer trust agents that it says keep humans in the loop for final decisions. Drata made agentic vendor risk assessments available to all customers and put agentic questionnaire response into beta. Sprinto launched what it calls an Autonomous Trust Platform that refreshes evidence, prepares audit artifacts and runs vendor due diligence. Secureframe and Sprinto both shipped MCP servers so assistants like Claude can read and act on live control data.
Here is what agents reliably do in production today: pull and check evidence, flag control drift, pre-fill questionnaires from approved sources, and assess vendor documents. What they do not do: sign the audit opinion, accept a risk, or vouch for a control they cannot observe. The auditor is still a licensed human firm.
The March 2026 allegations that one AI-first startup shipped templated, near-identical SOC 2 evidence across hundreds of customers showed the failure mode. Automation that produces the artifact without the underlying control is not compliance. It is fiction with a logo on it. And as agents spread, Drata launched AI agent governance in June 2026, because nobody owns agent behavior yet.
Era 5 · The Next Five Years · 2027-2031
What will SOC 2 and compliance automation look like by 2031?
My bet: by 2031 the annual audit stops being an event. Agents will keep evidence current every day, and auditors will consume machine-generated, signed evidence streams instead of sampling screenshots. The SOC 2 report becomes a live attestation with a freshness date, not a PDF that is eleven months stale by the time a buyer reads it.
The early signs exist. Sprinto already syncs evidence directly to the audit firm A-LIGN. Trust centers already let a buyer's agent pull a vendor's artifacts with consent, which Drata's TPRM agent does today. The next step is the buyer's agent and the seller's agent settling a security review between themselves, with humans reviewing only the exceptions.
The scope will keep growing. ISO 42001 is becoming the expected answer to "how do you govern your AI", and the EU AI Act's high-risk obligations are now slated for December 2027 under the provisional omnibus deal. Even companies that only call a model API carry duties, which I cover in the EU AI Act for the downstream provider.
What has to be true: auditors and the AICPA must accept agent-collected evidence with a verifiable chain of custody, and evidence must be cryptographically signed at the source so nobody can template it. That is the same shift cryptographic consent predicts for signatures: proof that is checked by math, not by a person squinting at an image.
My prediction · by 2031 · medium confidence
By 2031, agents will collect and verify most compliance evidence continuously, auditors will rely on signed machine evidence instead of samples, and SOC 2 will become a live attestation rather than an annual PDF.
What has to be true
- The AICPA and audit firms accept agent-collected evidence with a verifiable chain of custody
- Evidence is signed at the source so it cannot be templated or replayed
- Buyers trust live attestations enough to stop sending custom questionnaires
- Agent identities, scopes and audit logs become a standard control in the frameworks themselves
Projected autonomy 4.0 of 5
- EU lawmakers reach provisional deal to delay high-risk AI Act obligations to December 2027source
- EU AI Act obligations for stand-alone high-risk systems scheduled to applybeing verified
Then vs now: who does each step?
The job broken into its steps, and who or what does each one in each era.
| Job step | On-prem | SaaS and cloud | AI-assisted | Agentic | Next 5 years |
|---|---|---|---|---|---|
| Write policies | Consultant writes a policy binder | Platform templates, edited by the GRC lead | AI drafts, human rewrites | Agent drafts and maps policy to controls; human approves | Agent keeps policy in sync with observed controls; human signs off changes |
| Collect evidence | Engineers take screenshots before the audit | Integrations pull evidence through APIs | Integrations plus AI help on manual uploads | Agent collects, evaluates, and chases owners for gaps | Signed evidence streams from the source, verified continuously |
| Monitor control drift | Nobody, until next year's audit | Automated tests raise alerts | Alerts plus AI-suggested fixes | Agent flags drift and drafts remediation; engineer applies it | Agent remediates low-risk drift within approved scopes |
| Map controls across frameworks | Consultant builds a crosswalk spreadsheet | Platform maps one control to many frameworks | AI explains mappings and gaps | Agent maps new frameworks such as ISO 42001 onto existing controls | New regulations land as machine-readable control sets |
| Answer security questionnaires | Security lead copies last quarter's answers | Trust center deflects some requests | AI pre-fills, human reviews every answer | Agent triages, drafts, routes to experts; human approves | Buyer and seller agents settle reviews; humans handle exceptions |
| Pass the audit | Auditor samples binders during fieldwork | Auditor reviews an evidence room in the platform | Same, with AI-summarized evidence | Agent prepares audit artifacts; licensed auditor tests and signs | Auditor tests the evidence pipeline and issues a live attestation |
How does the SOC 2 and compliance automation team change?
The compliance team stops being a document factory. The hours that went into screenshots, crosswalk spreadsheets and copy-pasted questionnaire answers move to agents, and the people who stay spend their time on control design, risk calls and the conversation with the auditor.
Headcount does not vanish, it changes shape. A company that once needed consultants plus a GRC manager plus weeks of engineering time can run SOC 2 and ISO 27001 with one GRC lead supervising agents. The new skill is knowing when an agent's evidence is real and when it is a well-formatted guess. I make the broader version of this argument in AI didn't kill SaaS, it killed the seat.
Roles that shrink
- Readiness consultants who collect evidence and write policy binders
- Engineer hours spent on audit prep
- Manual questionnaire response by sales engineers
- Junior audit staff sampling screenshots
Roles that appear
- Agent supervisor for GRC workflows
- Control engineer who writes controls as code
- AI governance lead for ISO 42001 and EU AI Act scope
- Trust operations owner who sets questionnaire guardrails
Skills to learn
- Judging whether evidence proves a control actually ran
- Writing guardrails and approval rules for agents
- Mapping AI-specific risks to controls
- Reading cloud and identity configuration directly
- Explaining residual risk to buyers and boards
What gets easier for the humans?
| Before | After |
|---|---|
| Weeks of engineer time taking screenshots before each audit | Evidence is collected and checked continuously; engineers fix what is flagged |
| A 300-question security questionnaire written from scratch per deal | An agent drafts from approved answers and routes the unusual questions to an owner |
| Starting over for each new framework | One control set mapped to SOC 2, ISO 27001, HIPAA and ISO 42001 |
| Discovering a disabled control during audit fieldwork | Drift is flagged the day it happens |
| Emailing the same SOC 2 PDF to every prospect | A trust center and agent handle the request under NDA rules |
Decisions that stay human
- Accepting a risk or granting an exception
- Signing the audit opinion, which stays with a licensed auditor
- Deciding which controls the business actually needs
- Approving any answer that becomes a contractual representation to a customer
- Judging whether a control works in practice, not just on paper
Where should agents not act alone?
Risks and failure modes, through a security and identity lens.
- 01
Templated evidence that proves nothing
Automation can generate a perfect evidence package for a control that never ran. The 2026 allegations against one AI-first compliance startup showed how fast trust in a whole report can collapse. Buyers should ask how evidence is produced, not only whether it exists.
- 02
Over-scoped agent access
A compliance agent needs read access to cloud, identity, HR and code systems, which makes it one of the most privileged identities in the company. Give it its own identity, read-only scopes by default, and short-lived credentials, never a shared admin key.
- 03
Prompt injection through questionnaires and vendor documents
Agents that read inbound questionnaires and vendor PDFs ingest untrusted text. A crafted document could try to make the agent disclose internal policies or mark a vendor as low risk. Treat every external document as hostile input.
- 04
Hallucinated answers become contract terms
A wrong security questionnaire answer can end up in a contract or a breach dispute. Keep a human approval step for any answer not drawn verbatim from an approved source, and log which source each answer came from.
- 05
No audit trail for the agent itself
If an agent marks a control as passing, you need to show what it checked, when, and with which credentials. Without identity-bound, per-action logs, the agent becomes the one unaudited actor in the compliance program.
Who is building agentic SOC 2 and compliance automation?
Incumbents adding agents vs agent-native entrants. Capability lines are checked against each vendor's own site.
Incumbents
Calls itself an agentic trust platform; the Vanta Agent drafts policies, evaluates evidence, completes questionnaires and runs third-party risk reviews.
Checked Oct 9, 2026Compare
Agentic TPRM assessments available to all customers; agentic questionnaire response in beta; AI agent governance launched June 2026.
Checked Oct 9, 2026Compare
Comply AI for remediation and questionnaires, plus a hosted MCP server that lets AI assistants query and update live compliance data.
Checked Oct 9, 2026Compare
Autonomous Trust Platform that refreshes evidence, prepares audit artifacts and runs vendor due diligence; MCP access from ChatGPT and Claude.
Checked Oct 9, 2026Compare
- Archer ↗being verified
Archer Evolv AI portfolio for compliance, risk and intelligence; announced governed AI Operators across audit and third-party risk.
Checked Oct 9, 2026
Agent-native
Sue, an AI agent that triages security reviews, drafts questionnaire answers, consults experts in Slack and updates CRM and ticketing systems.
Checked Oct 9, 2026
Side-by-side comparisons: Top 10 Compliance Automation Platforms of 2026 (Plus 3 AI-Native Challengers).
Questions people ask
How is AI changing SOC 2 compliance?
AI agents now collect and evaluate evidence, flag control drift, map controls across frameworks and draft security questionnaire answers. Vanta, Drata, Sprinto and Secureframe all shipped agentic features in 2025 and 2026. A licensed auditor still tests the controls and signs the SOC 2 opinion.
Will AI agents replace compliance managers?
No, but the job changes. Agents take over evidence collection, questionnaire drafting and policy upkeep. People keep control design, risk acceptance, exceptions and the auditor relationship, and they now supervise and govern the agents themselves.
Can an AI agent pass a SOC 2 audit for you?
No. An agent can prepare evidence and audit artifacts, but the controls must actually operate and an independent CPA firm issues the report. Evidence generated from templates rather than real systems is a serious failure, not a shortcut.
Can AI answer security questionnaires accurately?
For questions covered by approved answers and trust center documents, mostly yes; vendors report high acceptance rates, though those figures are self-reported. Keep a human approval step for novel questions, because answers can become contractual commitments.
What is continuous compliance monitoring?
It means checking controls through integrations every day instead of once before an audit. The platform tests settings like MFA, encryption and offboarding through APIs and alerts when something drifts, so problems surface months before fieldwork.
Do I need ISO 42001 if I already have SOC 2?
SOC 2 does not cover how you govern AI systems. ISO 42001 is the AI management system standard, published in December 2023. Buyers increasingly ask for it if you build or deploy AI, and most compliance platforms now map it onto existing controls.
What are the risks of using AI agents for compliance?
The main ones are over-privileged agent access to cloud and HR systems, prompt injection through vendor documents, hallucinated questionnaire answers, and evidence that looks complete but does not prove a control ran. Give agents their own scoped identity and log every action.
Sources
- Sarbanes-Oxley Act, accessed Oct 9, 2026
- SSAE 16, accessed Oct 9, 2026
- EMC to Acquire Archer Technologies, accessed Oct 9, 2026
- Clearlake and STG Complete Sale of Archer to Cinven, accessed Oct 9, 2026
- About Vanta, accessed Oct 9, 2026
- Drata to acquire SafeBase, accessed Oct 9, 2026
- Secureframe launches Comply AI for remediation, accessed Oct 9, 2026
- Introducing the all-new Vanta AI Agent, accessed Oct 9, 2026
- Vanta's New Agents and Enterprise Controls Eliminate Audit Chaos, accessed Oct 9, 2026
- Vanta unveils agents, enterprise features and privacy tools (SiliconANGLE), accessed Oct 9, 2026
- Drata Unveils Industry-First Agentic AI Capabilities to Transform Enterprise Trust Workflows, accessed Oct 9, 2026
- Drata Expands Trust Management Platform to Support Governance of Enterprise AI Agents, accessed Oct 9, 2026
- Sprinto Launches Autonomous Trust Platform: Moving Compliance From Automated to Autonomous, accessed Oct 9, 2026
- Sprinto Product Updates July-August 2026: AI Agents, Smarter SecQ, and Deeper Integrations, accessed Oct 9, 2026
- Secureframe launches hosted AI server for compliance (IT Brief), accessed Oct 9, 2026
- Introducing the world's first AI agent for customer trust (Conveyor), accessed Oct 9, 2026
- Comp AI: The open-source way to get compliant with SOC 2, ISO 27001, HIPAA and GDPR (Help Net Security), accessed Oct 9, 2026
- Archer Expands AI Powered Archer Evolv Portfolio with Archer Evolv Risk and Archer Evolv Intelligence, accessed Oct 9, 2026
- Insight Partners scrubs investment post amid fake compliance allegations (TechCrunch), accessed Oct 9, 2026
- Delve Allegations Expose Weak Points in Modern Compliance (IANS Research), accessed Oct 9, 2026
- ISO/IEC 42001:2023 (IEC Webstore), accessed Oct 9, 2026
- AI Act enters into force (European Commission), accessed Oct 9, 2026
- EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (Gibson Dunn), accessed Oct 9, 2026
Published Oct 9, 2026. Last verified Oct 9, 2026. Eras 4 and 5, vendors, and scores are re-checked every six to eight weeks; see the changelog and methodology.
Keep reading
Essays and analysis
- Compliance Automation Platforms Compared (2026): Vanta vs Drata vs Sprinto vs Secureframe vs Scytale vs Thoropass
- SOC 2 Policies: What Founders Actually Need to Write
- ISO 42001: What It Actually Certifies, and Whether You Need It
- The EU AI Act for the Downstream Provider: What You Owe When You Just Call an API
- Demystifying SOC 2 Compliance for Startups: A Simple Guide
- Everyone Bought AI Observability. Nobody Owns Agent Behavior.
- AI Didn't Kill SaaS. It Killed the Seat.