For auditors & assessment firms

Fieldwork is shorter when the evidence is already true

Much of an assessment is not judgement. It is reconciling a folder of screenshots against a spreadsheet of controls, then working out whether any of it is still current. Keel is built so that part is largely done before you arrive — and so a client cannot show you less than the whole standard without it being stated on the framework’s own public page.

Ask any client on Keel for a seat. It is free on every plan, it is read-only, and it does not use up one of theirs.

What the seat gives you

  • Your seat costs the client nothing

    An auditor seat is free on every plan, including the free one, and does not count against the workspace seat limit. Nobody has to weigh giving you access against their headcount.

  • Read-only, by construction

    The auditor role cannot edit controls, upload or unlink evidence, change checks, or run AI actions. It is enforced in the application, not in a policy document, so independence does not rest on anyone being careful.

  • Evidence attached where it belongs

    Evidence is linked to the control it satisfies, and a control maps to every framework requirement it covers. You follow one thread from requirement to artifact instead of reconciling a folder against a spreadsheet.

  • A failing check withdraws its own evidence

    Automated checks — HTTPS / TLS reachable, Security response headers, SPF record present and DMARC policy present — re-run on a schedule and file dated evidence against the control they cover when they pass. When one fails, errors, or is paused, that evidence is withdrawn and the check stops backing that control. Uploaded evidence behaves differently and it is worth knowing which you are looking at: Keel flags an upload as expiring or expired against the review date someone set on it, but an expired upload stays attached to the control until a person replaces it.

Why the numbers mean something

A readiness percentage is only as honest as its denominator. Three things make Keel’s checkable rather than merely assertable.

  • Complete, or it says so

    Every framework declares itself complete or partial, and a test fails the build if the authored requirement count drifts from the leaf count Keel declares for that standard. Each framework page states that declared scope, names the authority it was checked against, and — where Keel models less than the whole standard — states what is missing. Today that is EU AI Act and PCI DSS. What no client can hand you is a subset that is silent about being one.

  • Scope is stated, not implied

    Where a regulation contains provisions a company cannot itself implement — duties addressed to supervisory authorities, for instance — they are excluded from scoring rather than counted against a client who could never satisfy them. Every framework Keel ships states on its own page the scope its denominator is drawn from and the authority that scope was checked against. GDPR goes further: a public scoping page names every excluded provision, grouped where the reason is shared, with a citation and a stated reason for each group. The denominator is auditable.

  • Paraphrase, never reproduced text

    Keel cites clause and control numbers and titles with original descriptions. Copyrighted standard text is not reproduced, so nothing in a client workspace becomes a licensing problem in your file.

The questions you are going to ask, already asked

Keel ships an auditor question bank of 341 questions across 8 control domains, each mapped to the control it interrogates. Clients work through them before you arrive, so your first pass is a review rather than a discovery exercise.

  • Governance & Risk

    133 questions

  • Access Control

    20 questions

  • Data Protection & Privacy

    66 questions

  • Infrastructure & Operations

    35 questions

  • Resilience & Continuity

    22 questions

  • Third-party Risk

    12 questions

  • People & Culture

    36 questions

  • Physical & Environmental

    17 questions

Partnering with Keel

If your firm assesses against SOC 2, ISO 27001, NIST SP 800-171, HIPAA, PCI DSS or ISO 9001, there is a simple version of this: your clients run their programs in Keel, you take a free seat in each, and the evidence arrives in a shape you can test.

We would rather have a real conversation than run a partner portal. Tell us what you assess and how you like evidence delivered.

Keel is a readiness and evidence platform. It is not an assessor, does not perform audits, and does not issue certifications or attestations — that is your work, and Keel is not a substitute for it.