Most compliance programmes today live inside a vendor platform. This session argues that they do not have to, and looks at what changes for the auditor when they do not.
- The problem with the platform model. Why compliance SaaS bills you forever, what it costs across three renewals, and what happens to your evidence, your history and your programme on the day you leave.
- The alternative: your programme in your own stack. Policies, risk register, access reviews and vendor reviews living in Notion, Jira, Drive and GitHub, structured for integrity with timestamps and immutable history. What auditors accept there, and what they do not.
- Process evidence and technical evidence are not the same thing. Why the Type II observation window, and not the audit itself, is where most programmes fail, and why conflating the two kinds of evidence weakens both.
- Can an auditor trust evidence collected by an AI agent? Agents pulling timestamped artefacts from source systems across the whole window, where the line sits between collecting and asserting, and what an auditor should check when an agent has access to a client environment: read-only, least privilege, scoped, logged.
- Practical takeaways for auditors and risk professionals who will start seeing AI-assisted evidence in their files.
The tone is practical and vendor-neutral. We will leave room for questions at the end.



