Subcapability 03 of 04 · Security Engineering

Compliance as Code

Open Policy Agent with NIST 800-53 controls as code that transform regulatory requirements into continuously verifiable properties and eliminate the pre-audit sprint assembled on the eve of every certification.

What is at stake

The LGPD audit found access controls that were not implemented as described in the policy document. The gap had existed for months. Regulatory exposure grew in silence while the policy document described controls that operations did not actually implement.

What it is, in practice

Document-based compliance has an expiration date. The document describes the policy as it should be. Operations evolve without updating the document. At the next audit, the gap between what is written and what actually runs creates regulatory exposure nobody mapped. Compliance that exists only on paper does not protect. It creates the illusion of protection with real maintenance cost and genuine regulatory risk.

How we work

Measurable gains

What changes in the result when this subcapability matures.

Frequently asked questions

What is Open Policy Agent and how does it connect to regulatory compliance?

Open Policy Agent, a CNCF graduated project, is a general-purpose policy engine that evaluates authorization decisions across any part of the stack: infrastructure as code, Kubernetes admission control, APIs and CI/CD pipelines. The Rego language allows expressing any regulatory control as a verifiable rule. The result is that each control has an associated test that runs continuously, making compliance verifiable, not declared.

Does Compliance as Code apply to data protection regulations?

Data protection regulations require specific controls on personal data processing: documented legal basis, access restricted to what is necessary, incident notification within required timeframes and ability to fulfill data subject rights. Each of these requirements can be expressed as a verifiable policy: access to datasets with personal data controlled by OPA policy, automatic alerts when personal data is accessed outside the expected pattern, and continuous inventory of where personal data is stored and processed.

How to demonstrate to the board that continuous compliance has measurable ROI?

Through avoided cost in three categories. Regulatory fines for violations, which in data protection frameworks can be significant percentages of revenue. Pre-audit sprints, which in organizations with multiple certifications consume weeks of engineering capacity per year. And incident cost associated with controls the document described but operations did not actually implement. All three have real numbers. Continuous compliance reduces the probability and cost of all three.

Does Compliance as Code replace external audits?

Compliance as Code automates continuous control verification and evidence collection. External audits validate that the verification process is adequate and that the chosen controls address regulatory requirements. The two are complementary. Organizations with Compliance as Code arrive at audits with automatically generated evidence, which reduces audit time and cost without eliminating its necessity.

Where to start when the compliance backlog is extensive?

By prioritizing through regulatory risk and operational impact. Controls that cover personal data and payment card data have greater violation consequences. Controls that depend on error-prone manual processes have higher probability of deviation. The intersection of both criteria defines the first controls to automate, with immediate risk return and measurable progress evidence for the board.

Want clarity on where to invest first?

A complete technology capability assessment with an evolution roadmap connected to financial result.