Fig Group · Practical resource
Compliance automation buyer checklist
Choose compliance automation by testing the work your team needs to complete: collecting evidence, assigning gaps, reviewing decisions and exporting an auditable record. Use this checklist to compare demonstrated results, not feature counts.
By Fig Group · Updated
A buying worksheet for UK organisations and MSPs. It is not a vendor ranking or a certification assessment. Complete it against your actual package and proposed deployment.
Start with one outcome
Write down the customer requirement or framework, the systems and organisations in scope, your deadline and who will own the programme. Separate the software purchase from independent assessment, remediation and ongoing staff responsibilities. For MSPs, include a representative client and test permissions between clients.
Choose three records for the demonstration: a control with current evidence, one with missing evidence and one with an approved exception. Ask the vendor to use those records throughout the demonstration.
Use the buyer checklist
| Check | Ask to see | Record your decision |
|---|---|---|
| Framework scope | The applicable requirements and the mapping version; what is not covered | Required / demonstrated / gap / owner |
| Evidence quality | Source, collection time, scope, expiry and the underlying record | Can a reviewer trace the result? |
| Automation limits | An unavailable connector, stale data and a failed check | Who is alerted and what needs manual work? |
| Ownership | Assign a gap, change its owner and escalate overdue work | Named owner and follow-up path |
| Review and exceptions | Approve an exception with a reason, conditions and review date | Who may accept risk? |
| Integrations | Your actual product/version and required permissions | Supported connection and setup responsibility |
| MSP separation | Two clients with different roles and access rights | Client isolation and portfolio visibility |
| Audit and exit | Export evidence, decisions, attachments and history | Usable export and retention/deletion terms |
| Commercial scope | Written licence, setup, support, usage and renewal terms | Total cost and excluded services |
| Operational fit | Your administrator completes a routine task | Time, training and support required |
Example: test evidence that has gone stale
Fictional evaluation: a 40-person consultancy needs to answer customer security questionnaires and prepare an ISO 27001 evidence set. Its IT lead supplies a current access-review record and one overdue review. The evaluator checks whether the platform distinguishes the two, assigns the overdue review and preserves the original evidence.
A successful demonstration shows the source record, an accountable owner, the next action and an exportable decision history. A green dashboard without those records does not meet this example’s acceptance criteria. This is a proposed buying test, not a report of a Fig Group customer result.
Run a focused proof of concept
Agree scope and acceptance
Select one framework and three representative records. Write down the required evidence, permissions, export and owner workflow before the demonstration.
Test the normal and failure paths
Import or attach evidence, let a record become stale, assign the gap and record a review. Test one unavailable connection without using production credentials in a trial.
Record the buying decision
Mark each requirement demonstrated, conditional or not met. Assign unresolved gaps and confirm the complete written commercial scope before purchasing.
Copy or download the template
Use the blank worksheet in your own document editor. Replace the prompts with your organisation’s details, obtain the relevant approvals and keep a controlled copy.
COMPLIANCE AUTOMATION BUYER CHECKLIST Organisation / client: Evaluator / decision-maker: Framework and version: Systems and entities in scope: Required outcome and deadline: Requirement | Mandatory? | Demonstrated evidence | Gap | Owner | Due date Framework coverage | | | | | Evidence source and freshness | | | | | Missing-data behaviour | | | | | Ownership and escalation | | | | | Exception approval and expiry | | | | | Connector/version/permissions | | | | | Client isolation and access | | | | | Export, retention and exit | | | | | Licence and usage cost: Setup, training and support cost: Assessment/remediation excluded from price: Contract, renewal and cancellation terms: Acceptance tests and results: Decision: proceed / conditional / decline Unresolved conditions and approver: Review date:
Explore the workflow in Fig Group
Fig Group connects compliance evidence with policies, risks, assets and owned actions. Bring this checklist to a demonstration of the control-to-evidence workflow. Confirm the supported frameworks, connections and responsibilities for your proposed package; software does not replace the independent assessment.
Common questions
Does compliance automation guarantee certification?
No. Software can organise evidence and support control checks, but your organisation must implement the requirements and complete any applicable independent assessment.
How should we compare prices?
Compare the same scope: licences, entities, users or devices, integrations, setup, support, renewal terms and any separate assessment or remediation costs. Record excluded work before deciding.
Sources and further reading
Use the current source guidance alongside your own requirements when completing the worksheet.