All articles
Compliance

Compliance you can prove

5 min readVictor Pettersson, IT-säkerhetschef, Sokigo

There is a quiet gap in most compliance programmes between "we have a policy for that" and "here is the evidence, someone signed off on it, and it is still true today." A spreadsheet full of green cells hides that gap. An auditor's job is to open it.

Aquil's Requirement Tracker is built around that distinction. Instead of marking a control done, you record what your organization actually does, and back it with evidence a human confirmed. Compliance stops being a claim and becomes something you can hand over.

Answers are objects, not checkboxes

The core building block is a capability: a reusable, evidence-backed statement of something you do, like "we encrypt data at rest with AES-256-GCM, per tenant." You link a capability to the requirements it answers (an ISO 27001 control, a policy clause, a customer's security line) and its status is derived from those confirmed links, never typed in by hand.

That derivation is deliberately strict. A capability with live evidence reads as Proven. Confirmed but without current evidence, it reads as Claimed. Nothing linked at all is a Gap. And where a requirement is contradicted, that conflict is surfaced first, not averaged away. The status is a consequence of your evidence, so it can't quietly drift out of sync with it.

Evidence with provenance

Evidence can be a linked Aquil document, an uploaded file, a recorded certificate with an expiry date, a per-service control status, or a signed original: an immutable, download-only document that holds up as audit-grade proof. Each piece is attached to the capability it supports, so "show me the evidence for this control" is a click, not a scavenger hunt.

Because certificates carry an expiry, the ledger ages honestly. When one lapses, the capability it backed drops from Proven to Claimed on its own. Your posture reflects this quarter's reality, not last year's binder.

AI proposes; a human decides

Aquil can suggest which capability answers which requirement, and it will do the tedious matching across a whole framework for you. But no AI, and no automatic rollup, ever sets an official compliance status. A person confirms every link, and every confirmation is attributed and timestamped.

That boundary is the whole point. An assessment you can defend is one where a named human stood behind each answer; the tooling just removes the busywork of getting there.

Built for the auditor's seat

Auditors get a read-only role that sees the full posture for oversight: a live coverage rollup per framework and a worst-first worklist that puts conflicts and gaps at the top. Every change is recorded: who confirmed a link, who reassigned an owner, when a requirement was added, down to field-level history. Completed process runs remain viewable as evidence too.

The reconstruction-from-memory that usually precedes an audit (who did this, when, and why) simply isn't necessary when the record was accumulating the whole time.

Provable compliance is the documentation, the evidence and the sign-off living in one place, so that at any moment the honest answer to "can you prove it?" is yes. It takes no more paperwork than you already write, just one place where it lives.

See what Aquil can do for your team