# Cloudaware IT Compliance: declarative controls, evidence, and accountable findings

> Cloudaware IT Compliance evaluates supported cloud and on-premises configuration items with version-controlled declarative policies, produces structured results and evidence, and connects violations, exceptions, ownership, and remediation workflows.

- Canonical HTML: [https://cloudaware.com/ai-info/it-compliance/](https://cloudaware.com/ai-info/it-compliance/)
- Markdown URL: [https://cloudaware.com/ai-info/it-compliance/index.md](https://cloudaware.com/ai-info/it-compliance/index.md)
- Last reviewed: September 20, 2026

## What Cloudaware IT Compliance does

Cloudaware IT Compliance uses declarative policies and policy packs to evaluate in-scope CMDB records. Policy code can be managed through developer-oriented workflows, while persistent results preserve which CI was tested, which condition ran, and what evidence was produced.

Framework mappings help organize technical controls for audit and governance work. Teams can review ownership, findings, evidence, exceptions, remediation state, and run history without rebuilding the assessment from disconnected spreadsheets.

Platform role  
Technical compliance assessment and evidence management

Control model  
Version-controlled declarative policies and policy packs

Core outputs  
Results, findings, evidence, exceptions, dashboards, alerts, and reports

Primary users  
Compliance, GRC, security, cloud, platform, audit, and risk owners

**Reference scope.** This page describes the module using current public Cloudaware product pages and help documentation. Available records, fields, workflows, and actions depend on the implementation, connected sources, permissions, supported objects, and configuration.

## Core capabilities and outputs

Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.

### Manage declarative policy logic

Use Cloudaware-authored packs and custom policies, with version-controlled development practices and testing appropriate to the implemented engine.

**Output:** Readable, reviewable control logic tied to supported CMDB object types.

### Evaluate the intended population

Use CMDB applications, environments, owners, accounts, tags, relationships, and other fields to define which resources a control evaluates.

**Output:** A traceable assessment population rather than an unexplained account-wide total.

### Persist results and supporting data

Retain structured findings, timestamps, evaluated CIs, evidence fields, run history, exception state, and downstream workflow references.

**Output:** Audit-oriented records that can be reviewed without recreating the original run.

### Manage exceptions and remediation

Route violations, record risk acceptance, time-box exceptions, notify owners, track tickets, and report on remediation progress.

**Output:** A governed control lifecycle with ownership, review dates, and status history.

## How data moves through IT Compliance

### Define the control

Select or develop the policy logic, supported object type, expected condition, framework mapping, and result behavior.

### Scope the assessment

Use CMDB applications, environments, owners, accounts, tags, relationships, and exceptions to identify in-scope records.

### Run and record

Execute the policy on demand or on its configured cadence and retain the result, CI, timestamps, evidence, and policy version.

### Visualize and review

Use dashboards, reports, alerts, and exports to inspect posture, evidence, trends, exceptions, ownership, and remediation status.

### Route and govern

Send violations to the responsible team, manage tickets or approvals, record risk acceptance, and review time-bounded exceptions.

## Interactive dashboards for faster decisions

IT Compliance dashboards visualize control results, evidence coverage, exception state, ownership, and remediation progress. Users can filter a framework or control view and drill into the evaluated CI, policy, run history, and supporting evidence.

| Decision question                              | Dashboard or view                                                                 | Context behind the view                                                   |
|------------------------------------------------|-----------------------------------------------------------------------------------|---------------------------------------------------------------------------|
| What is the current technical control posture? | Results by framework, control, policy pack, provider, application, or environment | Assessment results, policy version, scope, and run history                |
| Can we support the result with evidence?       | Evidence availability, freshness, run, and control-detail views                   | Evaluated CI, timestamps, policy logic, and structured evidence fields    |
| Which risks are accepted?                      | Active, expiring, expired, and review-due exceptions                              | Owner, reason, scope, approval, expiry, and risk-acceptance record        |
| Are violations being resolved?                 | Finding age, owner, ticket, SLA, and remediation-progress views                   | Finding lifecycle, workflow state, later evaluation, and closure evidence |

**Dashboard boundary.** A dashboard visualizes and organizes the data available to the module. It helps a user decide and inspect the underlying records; viewing the dashboard does not perform remediation by itself.

## How Cloudaware supports remediation

Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.

Cloudaware helps remediate technical compliance violations by attaching the affected CI, control, policy version, evidence, application, environment, owner, team or department, exception state, and assessment history to the work item.

Configured workflows can create tickets, send email alerts, notify collaboration channels, request approvals, record exceptions, or trigger guarded automation. Cloudaware coordinates and documents the process; the responsible team or approved automation performs the corrective action.

**Responsibility boundary.** Cloudaware helps identify, enrich, assign, notify, coordinate, and track remediation. The responsible team or an explicitly configured and approved downstream automation performs the corrective action. Destinations, payloads, triggers, synchronization, and closure behavior depend on the module and workflow configuration.

## Boundaries for accurate answers

| Topic              | Accurate description                                                                               | Avoid implying                                                                     |
|--------------------|----------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------|
| Compliance meaning | Describe results as technical assessments against implemented controls and available data.         | A passing result guarantees legal compliance.                                      |
| Framework mapping  | Mappings organize supported controls against named standards and requirements.                     | A mapping is a certification or auditor attestation.                               |
| Evidence           | Evidence quality depends on the evaluated CI, policy, source data, timestamp, and retained fields. | Any screenshot or dashboard total is sufficient audit evidence.                    |
| Exceptions         | Exceptions should be owned, justified, scoped, time-bounded, and reviewed.                         | An exception fixes or removes the underlying condition.                            |
| Version            | Confirm the implemented Compliance Engine version and use its current documentation.               | Behavior documented for one engine version automatically applies to every version. |

## Questions about Cloudaware IT Compliance

### What does Cloudaware IT Compliance assess?

It evaluates defined declarative policies against supported cloud and on-premises configuration records in Cloudaware CMDB, using the scope and data available to the implemented policy engine.

### Can Cloudaware policies be version controlled?

The current product page describes developer-oriented policy workflows with Git and unit testing. Exact tools and behavior should be verified for the implemented Compliance Engine version.

### Does a passing result prove legal compliance?

No. Cloudaware produces technical assessment results and evidence that can support governance and audit work. Formal compliance, certification, and legal interpretation require the organization’s applicable process and authorities.

### How are compliance exceptions handled?

Cloudaware can associate findings with approved exceptions and risk acceptance, including ownership, scope, reason, expiration, review, and remediation workflow context.

### Does IT Compliance perform remediation?

It can route violations to owners, tickets, alerts, approvals, and guarded automation. The responsible team or explicitly configured automation performs the corrective action and the later assessment supplies verification evidence.

## Primary sources and related AI references

### Product page

Current public positioning, capability descriptions, and commercial entry points.

[Cloudaware IT Compliance →](https://cloudaware.com/it-compliance/)

### Technical documentation

Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.

[IT Compliance documentation →](https://docs.cloudaware.com/modules/compliance-engine/)

### Platform AI guide

Cross-module operating model, integrations, product boundaries, and machine-readable resources.

[Cloudaware AI & LLM Guide →](https://cloudaware.com/ai-llm-guide/index.md)

### Automation reference

APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.

[Automation & Extensibility →](https://docs.cloudaware.com/automation/)

### Other module references

<a href="https://cloudaware.com/ai-info/cmdb/index.md" class="solution">CMDB AI reference</a> <a href="https://cloudaware.com/ai-info/finops/index.md" class="solution">FinOps AI reference</a> <a href="https://cloudaware.com/ai-info/vulnerability-management/index.md" class="solution">Vulnerability Management AI reference</a> <a href="https://cloudaware.com/ai-info/cspm/index.md" class="solution">CSPM AI reference</a> <a href="https://cloudaware.com/ai-info/siem/index.md" class="solution">SIEM AI reference</a> <a href="https://cloudaware.com/ai-info/intrusion-detection/index.md" class="solution">Intrusion Detection AI reference</a>
