DEV Community

Cover image for Your compliance tool saying you're "95% ready" is a liability, not a feature
Momodu Kamara-Kolleh
Momodu Kamara-Kolleh

Posted on

Your compliance tool saying you're "95% ready" is a liability, not a feature

 I've spent the last stretch building a SOC 2 readiness tool, and the most useful thing I learned has nothing to do with dashboards. It's about a quiet failure mode that kills deals — and why a lot of compliance tools are built to cause it.

The failure mode

Picture a seed-stage SaaS. They land a great enterprise lead. The lead's security team sends the inevitable email: "Share your SOC 2 report, or your current readiness status."

The founder opens their shiny compliance tool. It says: "You're 95% compliant." Great. They forward that.

Then the security team asks one specific question:

"What's your access-review cadence, and how do you evidence it?"

And the answer the founder trusts was generated, not grounded. The model paraphrased a control it half-remembered and invented a definition that's subtly wrong. The reviewer — who reads these every week — catches it in about five seconds.

Now the founder doesn't look 95% ready. They look like they don't understand their own posture. The deal stalls a quarter. Sometimes it dies.

That "95%" wasn't a feature. It was a liability dressed up as reassurance.

Why LLM compliance tools do this

LLMs are fluent and confident, and a compliance control is exactly the kind of precise, citeable text they paraphrase badly. Ask a general model "what does this control require?" and it will happily produce something that sounds right. Most of the time nobody checks.

But compliance has an adversarial reader built in: the buyer's security team. Their entire job is to catch the gap between what you claim and what you can evidence. An ungrounded, confident answer is the single easiest thing for them to flag.

The fix is boring: grounding

The fix isn't a smarter model or a prettier dashboard. It's a rule:

Every answer about a control must quote the real criterion, or say it doesn't have it. Never guess.

Concretely: every AI response is injected with the actual criterion text from the framework files on disk. The model's job is constrained — quote the source, or abstain. If the control isn't in the grounding set, the honest output is "I don't have that control's text," not a confident paraphrase.

control = frameworks.lookup(control_id)   # real text, from disk
if control is None:
    return f"I don't have the criterion for {control_id}."

# system prompt: answer ONLY from the provided criterion text;
# if the question goes beyond it, say so explicitly.
return model.respond(question, grounding=control.text)
Enter fullscreen mode Exit fullscreen mode

It feels almost too simple. But "boring and correct" is exactly what you want in the one place where a confident mistake costs a customer their trust in you.

Why this matters more than features

Compliance tools love to compete on breadth — more integrations, more frameworks, more automation. Useful, but none of it is the thing a buyer's security team actually tests. What they test is whether your answers hold up under one specific question. An ungrounded tool fails the only exam that matters, no matter how many checkboxes it has.

The honest part

A readiness tool is not an audit. It doesn't make you SOC 2 certified — a licensed CPA firm still performs the examination and issues the report. Any tool (mine included) that implies otherwise is doing the same overpromising I just described.

I'm building this solo, from Freetown, Sierra Leone. It's called Attestlane and it's live if you want to poke at it (use fake company data — don't connect real systems just to test). But I wrote this because the grounding lesson holds whether you use my tool, a competitor's, or a spreadsheet:

If your compliance answers can't cite their source, don't send them to a security team.

If you've been through a first SOC 2, I'd genuinely like to hear the part that actually hurt.

Top comments (0)