A new category of AI-powered compliance platforms has emerged with a compelling promise. Using AI agents and automation to generate documentation, streamline evidence production, and reduce the manual effort traditionally associated with audit preparation, these platforms offer organizations a faster path to compliance readiness. For organizations under pressure to demonstrate third-party assurance to clients or regulators, the appeal is real and understandable.
When used responsibly, such platforms can be a helpful complement to a well-designed, well-operated compliance program. They should not, however, be used as a substitute for the work of building and running the program itself.
Earlier this year, public allegations surfaced regarding a platform that was reportedly helping clients achieve SOC 2 reports using automated, fabricated evidence that was not based on real, underlying compliance activities.
While almost certainly an outlier, the story raises a question worth examining carefully. What can AI usefully support in a compliance engagement, and what still requires human judgment, operational ownership, and program design?
What AI Can and Cannot Do
AI is genuinely useful in a compliance program. It can assist with evidence collection, policy drafting, control mapping, and documentation management. Used effectively and with human professional oversight, it reduces manual effort, improves consistency, and helps organizations stay organized across complex frameworks. There is real value in that, and it is part of how Resiliam approaches its own work.
What AI cannot do is make the judgment calls that give a compliance program its integrity. It cannot independently determine the right scope for a specific organization based on how that organization actually operates. It cannot assess whether a control is functioning as described or only documented as if it were. It cannot build the ownership and accountability structures that allow a team to explain and defend its program when a client or auditor asks a follow-up question.
The platforms that have marketed AI as a substitute for that work, rather than a tool within it, have been offering something the technology cannot fully deliver on its own. Speed in generating documentation is not the same as readiness in practice. A policy set and program documentation produced by artificial intelligence reflects what the AI was instructed to create. Whether it reflects how the organization actually manages its controls is a different question, and one that only human expertise and program oversight can answer.
What a Document Without a Program Actually Produces
There is a phrase that security practitioners use for a familiar pattern: compliance theater. It describes the gap between the appearance of a security program and the substance of one. The documentation exists. The policies are written. The reports have been filed. But when a real incident occurs, or a sophisticated client asks a specific question about how a control actually works, the performance stops holding up.
The compliance automation market did not invent this problem. It simply made it easier to accomplish.
A well-executed compliance report is a meaningful signal. It tells clients and auditors that an independent party has reviewed the organization’s controls and found them operating as documented. That signal has real value and can build real trust when it reflects a real program.
What it cannot do is substitute for the program itself. It does not tell you whether controls continue to operate after the audit window closes, whether the team understands the program well enough to maintain it through staff changes, or whether the governance structures in place can evolve as the organization grows. Those answers come from the program.
What a Real Program Looks Like
The organizations that hold up through re-audits, client security reviews, and the follow-up questions that come after third-party attestations are submitted share a common characteristic. They built a program first and let the evidence follow from it.
That means controls are owned by specific people who understand what they are responsible for and why. Governance structures, oversight processes, and review cycles are part of how the organization operates rather than constructed for the audit period. When an auditor or a client asks a question, the answer comes from the program, not from a document.
Building that kind of program takes longer than the days or weeks that an AI platform may promise. That said, the timeline is not as long as organizations often fear when the work is properly scoped and sequenced. A well-planned engagement, approached correctly, typically takes several months. What takes far longer is the remediation work that follows if documents are automatically generated without first building the program underneath them.
The Question Worth Asking
If your organization holds a third-party attestation or is in the process of pursuing one, one question is worth pausing on. If an enterprise client asked your team to walk through how a specific control actually works in practice, could you answer from the program or only from the document?
The difference between those two answers is the difference between compliance that actually protects the organization and compliance that looks like it does. When responsibly used, AI can be a valuable tool to complement a well-built program. It cannot replace one.
Resiliam’s experienced consultants use the right tools, including AI-supported workflows, to build programs that are designed to hold up through initial implementation, re-examinations, and the questions clients ask in between. We bring deep expertise to every engagement so that the work we do together reflects how your organization actually operates, not just how it is documented.