For auditors & assessment firms

Fieldwork is shorter when the evidence is already true

Much of an assessment is not judgement. It is reconciling a folder of screenshots against a spreadsheet of controls, then working out whether any of it is still current. Keel is built so that part is largely done before you arrive. A client therefore cannot show you less than the whole standard without it being stated on the framework’s own public page.

Ask any client on Keel for a seat. It is free on every plan, it is read-only, and it does not use up one of theirs.

What the seat gives you

  • Your seat costs the client nothing

    An auditor seat is free on every plan, including the free one, and does not count against the workspace seat limit. Nobody has to weigh giving you access against their headcount.

  • Read-only, by construction

    The auditor role cannot edit controls, upload or unlink evidence, change checks, or run AI actions. It is enforced in the application, not in a policy document, so independence does not rest on anyone being careful.

  • Evidence attached where it belongs

    Evidence is linked to the control it satisfies, and a control maps to every framework requirement it covers. You follow one thread from requirement to artifact instead of reconciling a folder against a spreadsheet.

  • A failing check withdraws its own evidence

    Automated checks (HTTPS / TLS reachable, Security response headers, SPF record present and DMARC policy present) re-run on a schedule and file dated evidence against the control they cover when they pass. When one fails, errors, or is paused, that evidence is withdrawn and the check stops backing that control. Uploaded evidence behaves differently and it is worth knowing which you are looking at: Keel flags an upload as expiring or expired against the review date someone set on it, but an expired upload stays attached to the control until a person replaces it.

Why the numbers mean something

A readiness percentage is only as honest as its denominator.

  • Complete, or it says so

    Every framework declares itself complete or partial, and a test fails the build if the authored requirement count drifts from the leaf count Keel declares for that standard. Each framework page states that declared scope and names the authority it was checked against. Where Keel models less than the whole standard, that page states what is missing. Today that is EU AI Act and PCI DSS. What no client can hand you is a subset that is silent about being one.

  • Scope is stated, not implied

    Some regulations contain provisions a company cannot itself implement, such as duties addressed to supervisory authorities. Those are excluded from scoring rather than counted against a client who could never satisfy them. Every framework Keel ships states on its own page the scope its denominator is drawn from and the authority that scope was checked against. Some go further, with a scoping page that sets out what the framework’s rows are measured against and names what sits outside them, item by item, with a reason for each. They are linked below. The denominator is auditable.

  • Starting points across the denominator

    Keel ships starting points across that denominator, and names where it does not. Every framework available today except HIPAA and PIPEDA carries at least one of Keel’s 250+ starter controls against every requirement it scores, 2,500+ mappings in all. Both are complete against the scope Keel declares for them. A small number of their requirements have no starter control mapped, so a client writes their own control there. Read this as a starting point and not as a score: a mapped control moves the readiness percentage only once the client has implemented it, so a workspace that has done nothing still reads zero, and a mapping is not evidence that anything was done. The mappings are the dataset Keel publishes, so you can check this one yourself.

  • Paraphrase, never reproduced text

    Keel cites clause and control numbers and titles with original descriptions. Copyrighted standard text is not reproduced, so nothing in a client workspace becomes a licensing problem in your file.

The questions you are going to ask, already asked

Keel ships an auditor question bank of 950+ questions grouped by the control domains below, each mapped to the control it interrogates. Clients work through them before you arrive, so your first pass is a review rather than a discovery exercise.

  • Governance & Risk

    300+ questions

  • Access Control

    25+ questions

  • Data Protection & Privacy

    150+ questions

  • Infrastructure & Operations

    200+ questions

  • Resilience & Continuity

    25+ questions

  • Third-party Risk

    25+ questions

  • People & Culture

    75+ questions

  • Physical & Environmental

    25+ questions

Partnering with Keel

If your firm assesses against SOC 2, ISO 27001, NIST SP 800-171, HIPAA, PCI DSS or ISO 9001, there is a simple version of this: your clients run their programs in Keel, you take a free seat in each, and the evidence arrives in a shape you can test.

We would rather have a real conversation than run a partner portal. Tell us what you assess and how you like evidence delivered.

Keel is a readiness and evidence platform. It is not an assessor, does not perform audits, and does not issue certifications or attestations. That is your work, and Keel is not a substitute for it.