Automated Control Checks
Connect AWS, Microsoft Azure, or Google Cloud so Concord checks your accounts and records the results as evidence on your controls, and use AI Evidence Collection to review a control against connected systems.
Overview
Many controls depend on how your cloud infrastructure is configured: encryption, logging, access, and network settings. Instead of exporting screenshots every cycle, connect your cloud accounts and Concord checks them for you, then records the results as evidence on the controls they map to.
Automated control checks and integrations are available now. If you don't see Integrations in your sidebar, contact us to turn them on for your organization.
Connecting a Cloud Account
- Go to Integrations → Browse Catalog. The Recommended tab shows the most common connections, and All Integrations shows everything.
- Choose AWS, Microsoft Azure, or Google Cloud, and follow the connection steps:
- AWS: connect with an IAM role that Concord assumes, using the external ID Concord provides.
- Microsoft Azure: connect with a service principal.
- Google Cloud: connect with Workload Identity Federation, so there's no key file to download or store.
- Choose which groups of checks to run.
Your connections are listed under Integrations → Your Integrations. Credentials are stored encrypted.
What Gets Checked
Checks are grouped by area, such as identity and access, logging and monitoring, storage and data, networking, and databases, and they're mapped to CIS benchmark criteria for each cloud.
Checks run every night for each connection, and you can also run them on demand. Each check group run uses 50 Actions for each connected account. See Actions and Data Credits.
How Results Become Evidence
Each check that maps to a control records its result as evidence on that control's tests. Not every check maps to a control.
A check can only pass on complete information. When a check can't reach an answer, for example because there's nothing in scope, a credential stops working, or the results are incomplete, it's recorded as Not Checked rather than as a pass or a fail.
If an automated check fails twice in a row on a required test, Concord opens a task for the fix, and the task is resolved when the check passes again.
AI Evidence Collection
For a control that doesn't map neatly to a single check, set up an AI Review on the control:
- Open the control and set up AI Review.
- Choose the Control to Prove and the Connected Systems to check.
- Optionally, add Context for the Agent and a Slack webhook to Post Results to Slack.
- Save, and turn the review on to run it.
An AI agent chooses and runs read-only checks against the systems you picked, then records a pass, a fail, or an inconclusive result on the control, with its reasoning and a summary of the evidence. Each review uses 200 Actions plus up to 100 Data Credits, and the checks it runs use their own Actions.
Next Steps
- Controls and Evidence: the controls these checks prove.
- Adopting Frameworks: see how check results count toward framework coverage.
Adopting Frameworks
Adopt a compliance framework to map your controls to its requirements, see coverage, and prepare for an audit, from SOC 2 and ISO 27001 to CCPA/CPRA and SOX.
Auditor Access
Set up an audit, invite your external auditors with scoped, time-boxed access, and work through their reviews and evidence requests, without adding them as full team members.