CA

ComplianceAide Capability Matrix

A comprehensive breakdown of ComplianceAide's capabilities across frameworks, controls, evidence, assessments, and enterprise features.

What's Supported

See exactly what's supported and what's coming. The matrix below details our capabilities across key enterprise GRC domains.

Supported

Production-ready capability

Partial

Partially supported or in development

Not in Scope

Outside intended platform scope

Frameworks & Controls

Multi-Framework Compliance Management

Framework catalogue/resolution, framework selection and framework-mapped assessments are implemented platform patterns.

Custom Framework Creation & Extension

Create or extend bespoke frameworks and run evidence-backed assessments against customer, industry or contractual requirements.

Multi-Language Control & Regulatory Content

Supports multiple languages (Spanish, Italian), and any outputs can be translated into any language by asking the chat.

Control Design & Operating-Effectiveness Testing

Delivered through evidence-backed assessments, control conclusions and reviewer-ready workpapers.

Evidence & Monitoring

Evidence Upload & Ingestion

Portal accepts varied evidence formats, large evidence bundles and structured ingestion workflows.

Automated Evidence Collection

API/workflow integration and selected partner telemetry are supported for automated collection.

Evidence Validation & Control Mapping

Evidence is organized, assessed and mapped to framework requirements with human-reviewed outputs.

Evidence Reuse & Provenance

Evidence is reusable across frameworks and audits with full provenance, lineage, versioning and integrity tracking.

Continuous Controls Monitoring & Drift Detection

Telemetry ingestion and interpretation supported. Computer vision allows dashboards and reports to be used as compliance evidence without dedicated connectors.

Continuous Compliance Posture Dashboard

Assessment status and dashboard workflows exist; mature always-on posture dashboard driven by wide integration estate in development.

Assessments & Audit

Readiness & Gap Assessments

Core production pattern including evidence-backed framework assessments and gap identification.

AI-Assisted Remediation Recommendations

Delivered through assessment narratives, gap analysis and generated implementation guidance, subject to human review.

Audit Planning & Fieldwork Management

Audit-ready workpapers and assessment execution are strong; full internal-audit universe planning outside intended scope.

Auditor Collaboration & Secure Access

Reviewer workflows and downloadable assessment artifacts exist with quality auditor communication via chat.

Board & Regulator-Ready Reporting

Delivered through policy, report and assessment artifact generation plus reviewer-ready workpapers.

Maturity Scoring & Progress Tracking

Delivered through framework assessments, structured conclusions and dashboard/report outputs.

Policy & Workflow

AI-Assisted Policy & Procedure Generation

Dedicated policy/artifact service patterns generate policies, procedures and reports from workspace context.

Policy Template Library

Delivered through policy generation patterns and extensive internal policy/framework content.

Policy Lifecycle & Approval Workflows

Supports policy creation, review, approval and attestation with configurable approval chains.

Human-in-the-Loop Governance

Implemented as a central platform design pattern, including review thresholds, approval gates, overrides and reconstructable decisions.

Risk Management

Enterprise Risk Register & Taxonomy

Risk classification, acceptance and governance records are supported; mature enterprise risk register in development.

Risk Scoring & Heat Maps

Risk tiering and assessment outputs supported with dynamic monitoring capabilities.

Risk Treatment & Acceptance Workflows

Delivered through remediation planning, exception/waiver handling, risk acceptance and approval lineage.

Enterprise Features

Multi-Tenant / Multi-Client Workspaces

MSP administration, workspace-specific frontends, evidence separation and workspace licensing are evidenced.

Role-Based Access Control

Delivered through authenticated workspaces, admin-only routes, workspace sessions and controlled impersonation/admin functions.

Integration Catalogue & APIs

API-first integration across cloud, identity, HR, ticketing and security with public APIs, webhooks and data export.

Custom Dashboards & Configurable Reports

Generated reports and dashboards with search and conversational Q&A across controls, evidence and policies.

AI Governance & Privacy

Inventories, intake, approvals, exceptions, privacy frameworks, evidence and AI data-sensitivity review all supported.

Enterprise Support & Deployment

Founder/implementation-led support and negotiable enterprise terms with flexible deployment options.

Ready to Explore ComplianceAide?

See how our comprehensive platform capabilities can support your compliance and GRC needs.

Schedule a Demo