Keel Research
Original data and cited analysis on governance, risk, and compliance for small and mid-sized businesses. We show our work: every figure is either computed from Keel's own open data or attributed to a named public source.
AI governance is new work — but do it once and you satisfy three regimes
Your SOC 2 program barely touches AI governance — but the three AI regimes overlap heavily with each other. We measured both against our own open control library.
Read the report → Original data (Keel crosswalk)How much do compliance frameworks actually overlap?
If you already do SOC 2, how much of ISO 27001 is free? We measured it against our own open control library. The overlap is larger than most teams expect.
Read the report → Third-party sources, citedWhat SOC 2 really costs an SMB (and why deals wait on it)
For a small company, the expensive part of compliance is rarely the audit invoice. It is the months of preparation and the revenue that sits in security review. Here is what the public data says.
Read the report →