---
title: "Compliance management"
canonical: "https://auditbadger.com/nl/functies/compliance-management/"
last-updated: "2026-09-05"
---

# Compliance management

The control hierarchy, ownership, evidence linkage, and audit trail that sit at the centre of every AuditBadger program. Pre-loaded with SOC 2 and ISO 27001 frameworks; extensible to HIPAA, PCI DSS, GDPR, and custom frameworks.

## What it does

| Capability | Detail |
|---|---|
| **Pre-built frameworks** | SOC 2 (all 5 Trust Services Criteria), ISO 27001:2022 (Clauses 4–10 + 93 Annex A controls) |
| **Hierarchical control structure** | Parent and sub-controls with automatic status rollup; a parent control's status reflects its children |
| **Cross-framework linking** | When the same evidence satisfies controls in multiple frameworks, link it once and reference it everywhere |
| **Custom frameworks** | Build HIPAA, PCI DSS, GDPR, or in-house frameworks using the same control model |
| **Evidence attachments** | Unlimited per control; any file format (PDF, screenshots, configs, exports); document versioning preserves audit-period accuracy |
| **Responsible user assignment** | Owner per control with automated permission assignment |
| **Document acknowledgments** | Employee acknowledgment tracking on policy publish and version updates |
| **Audit trail** | Every status change, evidence upload, and ownership change is timestamped and attributed |
| **Auditor read-only access** | Provision auditor accounts that can review controls and evidence directly without write access |

## Control implementation states

`Not Started → In Progress → Implemented → Exception`

Sub-controls roll up to their parent; when all sub-controls are Implemented, the parent is Implemented automatically.

## Frameworks supported out of the box

- **SOC 2** — Common Criteria CC1–CC9 (Security), plus optional Availability, Processing Integrity, Confidentiality, Privacy
- **ISO 27001:2022** — Clauses 4–10 (mandatory ISMS requirements), Annex A (93 controls in themes A.5–A.8)
- **Custom** — HIPAA, PCI DSS, GDPR, and any internal control framework via the same hierarchical structure

## Common questions

### Which frameworks are supported?
SOC 2 and ISO 27001 are pre-configured. Custom frameworks can be added for HIPAA, PCI DSS, GDPR, or any other standard. Controls can be mapped across multiple frameworks simultaneously.

### How does AuditBadger help during audits?
The platform provides a complete timestamped audit trail of every change. Auditors can be given read-only access to review evidence directly. Hierarchical control structure with status rollup makes it easy to demonstrate progress and identify gaps before the audit window opens.

### Can I track evidence per control?
Yes. Unlimited attachments per control, any file format. Evidence is timestamped and version-controlled so you always know which version was current during a given audit period.

### How long does SOC 2 implementation take?
About one week for the core platform setup. Pre-configured frameworks remove the blank-page problem; the AI assistant generates control descriptions and suggests evidence to accelerate further.

## Useful links

- Sign up: [auth.auditbadger.com/signup](https://auth.auditbadger.com/signup)
- All features: [/features](/features)
- SOC 2 deep dive: [/compliance/soc2](/compliance/soc2)
- ISO 27001 deep dive: [/compliance/iso27001](/compliance/iso27001)
