For auditors & assessment firms
Fieldwork is shorter when the evidence is already true
Much of an assessment is not judgement. It is reconciling a folder of screenshots against a spreadsheet of controls, then working out whether any of it is still current. Keel is built so that part is largely done before you arrive. A client therefore cannot show you less than the whole standard without it being stated on the framework’s own public page.
Ask any client on Keel for a seat. It is free on every plan, it is read-only, and it does not use up one of theirs.
What the seat gives you
-
Your seat costs the client nothing
An auditor seat is free on every plan, including the free one, and does not count against the workspace seat limit. Nobody has to weigh giving you access against their headcount.
-
Read-only, by construction
The auditor role cannot edit controls, upload or unlink evidence, change checks, or run AI actions. It is enforced in the application, not in a policy document, so independence does not rest on anyone being careful.
-
Evidence attached where it belongs
Evidence is linked to the control it satisfies, and a control maps to every framework requirement it covers. You follow one thread from requirement to artifact instead of reconciling a folder against a spreadsheet.
-
A failing check withdraws its own evidence
Automated checks (HTTPS / TLS reachable, Security response headers, SPF record present and DMARC policy present) re-run on a schedule and file dated evidence against the control they cover when they pass. When one fails, errors, or is paused, that evidence is withdrawn and the check stops backing that control. Uploaded evidence behaves differently and it is worth knowing which you are looking at: Keel flags an upload as expiring or expired against the review date someone set on it, but an expired upload stays attached to the control until a person replaces it.
Why the numbers mean something
A readiness percentage is only as honest as its denominator.
-
Complete, or it says so
Every framework declares itself complete or partial, and a test fails the build if the authored requirement count drifts from the leaf count Keel declares for that standard. Each framework page states that declared scope and names the authority it was checked against. Where Keel models less than the whole standard, that page states what is missing. Today that is EU AI Act and PCI DSS. What no client can hand you is a subset that is silent about being one.
-
Scope is stated, not implied
Some regulations contain provisions a company cannot itself implement, such as duties addressed to supervisory authorities. Those are excluded from scoring rather than counted against a client who could never satisfy them. Every framework Keel ships states on its own page the scope its denominator is drawn from and the authority that scope was checked against. Some go further, with a scoping page that sets out what the framework’s rows are measured against and names what sits outside them, item by item, with a reason for each. They are linked below. The denominator is auditable.
Amazon Appstore Child-Directed Apps scoring scope →
Apple App Store Kids Category scoring scope →
ESG Essentials scoring scope →
FedRAMP Consolidated Rules scoring scope →
-
Starting points across the denominator
Keel ships starting points across that denominator, and names where it does not. Every framework available today except HIPAA and PIPEDA carries at least one of Keel’s 250+ starter controls against every requirement it scores, 2,500+ mappings in all. Both are complete against the scope Keel declares for them. A small number of their requirements have no starter control mapped, so a client writes their own control there. Read this as a starting point and not as a score: a mapped control moves the readiness percentage only once the client has implemented it, so a workspace that has done nothing still reads zero, and a mapping is not evidence that anything was done. The mappings are the dataset Keel publishes, so you can check this one yourself.
-
Paraphrase, never reproduced text
Keel cites clause and control numbers and titles with original descriptions. Copyrighted standard text is not reproduced, so nothing in a client workspace becomes a licensing problem in your file.
The questions you are going to ask, already asked
Keel ships an auditor question bank of 950+ questions grouped by the control domains below, each mapped to the control it interrogates. Clients work through them before you arrive, so your first pass is a review rather than a discovery exercise.
-
Governance & Risk
300+ questions
-
Access Control
25+ questions
-
Data Protection & Privacy
150+ questions
-
Infrastructure & Operations
200+ questions
-
Resilience & Continuity
25+ questions
-
Third-party Risk
25+ questions
-
People & Culture
75+ questions
-
Physical & Environmental
25+ questions
Partnering with Keel
If your firm assesses against SOC 2, ISO 27001, NIST SP 800-171, HIPAA, PCI DSS or ISO 9001, there is a simple version of this: your clients run their programs in Keel, you take a free seat in each, and the evidence arrives in a shape you can test.
We would rather have a real conversation than run a partner portal. Tell us what you assess and how you like evidence delivered.
Keel is a readiness and evidence platform. It is not an assessor, does not perform audits, and does not issue certifications or attestations. That is your work, and Keel is not a substitute for it.