AuditReady 2.0: from evidence collection to an operational compliance system
So far AuditReady has done one thing well: keeping controls, evidence and accountability connected, and making them demonstrable during an audit. Version 2.0 widens the scope. Documenting what is under control is no longer enough — you need the domain objects supervisors expect to find when they ask how you manage risk, incidents, critical suppliers and personal data.
This is a preview. The release lands in the coming weeks.
Risk and critical functions
Two registers that were missing so far.
- A risk register with inherent and residual risk, treatment plan, formal acceptance (who, when, with which risk appetite note) and a next review date.
- A critical or important functions (CIF) register, with MTPD, RTO and RPO, linked to systems, assets and suppliers. You can immediately see which dependencies hold up what cannot stop.
Real incidents, not just exercises
Incident simulations stay. Next to them comes the actual operational incident, with a regulatory profile (DORA, NIS2, GDPR, AI Act), classification, impacted services and users, notification deadlines and a tracked lifecycle: open → classified → notifying → contained → closed. Every stage produces evidence, not an attachment in a folder.
Findings and resilience testing
Findings stop being scattered across audits, supervisory bodies and simulations: they become a single register with owner, severity and remediation. Planned resilience tests join them, with outcome, linked findings and attached evidence.
ICT suppliers and the supply chain
The supplier record becomes a register of ICT arrangements: ICT service yes/no, support to critical functions, audit rights, documented exit plan, subcontractors, country and data location, transfer mechanism, DPA and privacy role. These are the key fields feeding the Register of Information and supplier due diligence.
Operational GDPR
The GDPR framework moves from controls to processes: records of processing activities (RoPA), DPIA, data subject requests (DSAR) with deadlines, and legal hold on evidence, blocking deletion when proceedings require it.
Governance and permissions
- Management body attestations and an entity compliance profile: who the entity is, which obligations apply, who attested what and when.
- A new capability-based authorization model: permissions shaped as
capability.action, tenant-configurable roles, and ready-made roles for CRO, CISO and DPO. Permissions follow the enabled frameworks: if a module is off, the capability does not exist. - An immutable trail for platform administrator actions too.
The compliance graph
Finally, the Compliance Graph Explorer: a single navigable map connecting risks, critical functions, controls, policies, incidents, suppliers, processing activities and evidence. It answers in seconds the question that always comes last in an inspection: "this control — what does it actually affect?"
What changes, in one line
AuditReady stops being just the place where evidence is safe and becomes the place where compliance happens: risks assessed, critical functions mapped, incidents classified and notified, findings closed, suppliers qualified.
Want to see the preview applied to your own scope?
Note: AuditReady provides tools to govern, document and demonstrate compliance. It does not replace legal assessment of the applicable regulatory obligations.