Service

Compliance as code

Benchmarks and control mappings implemented in Terraform and policy-as-code, with audit evidence generated by your pipeline instead of assembled by hand the week before the audit.

The problem this solves

The controls are defined in a spreadsheet. The infrastructure is defined in Terraform. Nothing connects them, so twice a year someone spends three weeks taking screenshots to prove that what is deployed matches what was promised - and by the time the evidence is assembled it is already out of date.

What I deliver

  • Benchmarks implemented, not just measured - CIS for Microsoft 365 and Azure, expressed as Terraform and Entra policy rather than a findings report you have to translate.
  • Policy as code in the pipeline: a merge request that would breach a control fails before it merges, which is the only enforcement that actually holds.
  • Control mappings to the frameworks you are assessed against - DORA, NIS2, ISO/IEC 42001, PCI DSS - generated from the code, so the mapping cannot silently drift from the deployment.
  • Evidence generation as a pipeline artefact, timestamped and stored, so the audit question becomes a download rather than a project.

What you have after the engagement

A pipeline that fails on a control breach, a generated mapping document, and an evidence artefact from a real run. Scope it to one framework and one platform to start - trying to do all of them at once is how these efforts die.

Where this fits

This is the same discipline as the AI landing zone, applied to the estate you already have. Either is a reasonable place to start, and which one depends on whether your pressure is coming from an auditor or from your own teams.

Tired of assembling evidence by hand?

Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.