Skip to content

Fig Group · Practical resource

Compliance automation buyer checklist

Choose compliance automation by testing the work your team needs to complete: collecting evidence, assigning gaps, reviewing decisions and exporting an auditable record. Use this checklist to compare demonstrated results, not feature counts.

By Fig Group · Updated

A buying worksheet for UK organisations and MSPs. It is not a vendor ranking or a certification assessment. Complete it against your actual package and proposed deployment.

Start with one outcome

Write down the customer requirement or framework, the systems and organisations in scope, your deadline and who will own the programme. Separate the software purchase from independent assessment, remediation and ongoing staff responsibilities. For MSPs, include a representative client and test permissions between clients.

Choose three records for the demonstration: a control with current evidence, one with missing evidence and one with an approved exception. Ask the vendor to use those records throughout the demonstration.

Use the buyer checklist

Use the buyer checklist
CheckAsk to seeRecord your decision
Framework scopeThe applicable requirements and the mapping version; what is not coveredRequired / demonstrated / gap / owner
Evidence qualitySource, collection time, scope, expiry and the underlying recordCan a reviewer trace the result?
Automation limitsAn unavailable connector, stale data and a failed checkWho is alerted and what needs manual work?
OwnershipAssign a gap, change its owner and escalate overdue workNamed owner and follow-up path
Review and exceptionsApprove an exception with a reason, conditions and review dateWho may accept risk?
IntegrationsYour actual product/version and required permissionsSupported connection and setup responsibility
MSP separationTwo clients with different roles and access rightsClient isolation and portfolio visibility
Audit and exitExport evidence, decisions, attachments and historyUsable export and retention/deletion terms
Commercial scopeWritten licence, setup, support, usage and renewal termsTotal cost and excluded services
Operational fitYour administrator completes a routine taskTime, training and support required

Example: test evidence that has gone stale

Fictional evaluation: a 40-person consultancy needs to answer customer security questionnaires and prepare an ISO 27001 evidence set. Its IT lead supplies a current access-review record and one overdue review. The evaluator checks whether the platform distinguishes the two, assigns the overdue review and preserves the original evidence.

A successful demonstration shows the source record, an accountable owner, the next action and an exportable decision history. A green dashboard without those records does not meet this example’s acceptance criteria. This is a proposed buying test, not a report of a Fig Group customer result.

Run a focused proof of concept

  1. Agree scope and acceptance

    Select one framework and three representative records. Write down the required evidence, permissions, export and owner workflow before the demonstration.

  2. Test the normal and failure paths

    Import or attach evidence, let a record become stale, assign the gap and record a review. Test one unavailable connection without using production credentials in a trial.

  3. Record the buying decision

    Mark each requirement demonstrated, conditional or not met. Assign unresolved gaps and confirm the complete written commercial scope before purchasing.

Copy or download the template

Use the blank worksheet in your own document editor. Replace the prompts with your organisation’s details, obtain the relevant approvals and keep a controlled copy.

COMPLIANCE AUTOMATION BUYER CHECKLIST
Organisation / client:
Evaluator / decision-maker:
Framework and version:
Systems and entities in scope:
Required outcome and deadline:

Requirement | Mandatory? | Demonstrated evidence | Gap | Owner | Due date
Framework coverage | | | | |
Evidence source and freshness | | | | |
Missing-data behaviour | | | | |
Ownership and escalation | | | | |
Exception approval and expiry | | | | |
Connector/version/permissions | | | | |
Client isolation and access | | | | |
Export, retention and exit | | | | |

Licence and usage cost:
Setup, training and support cost:
Assessment/remediation excluded from price:
Contract, renewal and cancellation terms:
Acceptance tests and results:
Decision: proceed / conditional / decline
Unresolved conditions and approver:
Review date:

Explore the workflow in Fig Group

Fig Group connects compliance evidence with policies, risks, assets and owned actions. Bring this checklist to a demonstration of the control-to-evidence workflow. Confirm the supported frameworks, connections and responsibilities for your proposed package; software does not replace the independent assessment.

Common questions

Does compliance automation guarantee certification?

No. Software can organise evidence and support control checks, but your organisation must implement the requirements and complete any applicable independent assessment.

How should we compare prices?

Compare the same scope: licences, entities, users or devices, integrations, setup, support, renewal terms and any separate assessment or remediation costs. Record excluded work before deciding.

Sources and further reading

Use the current source guidance alongside your own requirements when completing the worksheet.