Automating business information systems for audit compliance in cloud-native organisations
Abstract
Information security compliance audits are increasingly critical yet resource-intensive obligations for modern organisations. This paper examines the intersection of compliance automation and cloud-native business information systems, synthesising peer-reviewed research and industry literature published primarily between 2017 and 2025. The paper traces the evolution of major compliance frameworks (System and Organization Controls 2 [SOC 2], International Organization for Standardization [ISO] 27001, General Data Protection Regulation [GDPR], Health Insurance Portability and Accountability Act [HIPAA]), identifies structural limitations of traditional, manual audit evidence gathering, and evaluates emerging automation technologies —including continuous controls monitoring (CCM), application programming interface (API)-based evidence collection, artificial intelligence and machine learning (AI/ML), and compliance as code — against real-world implementation findings. Key themes show that while automation demonstrably reduces manual compliance effort (by as much as 73 per cent in tested environments) and improves evidence quality and audit cycle times, significant gaps remain in understanding how these technologies perform specifically within cloud-native organisations characterised by dynamic infrastructure, microservices architectures, and continuous deployment pipelines. The paper further highlights limited longitudinal research, insufficient investigation of auditor acceptance of automated evidence, and unresolved tensions between fully automated and human-augmented compliance models. These gaps inform a research agenda aimed at closing the gap between automation’s theoretical potential and its practical adoption in cloud-native contexts. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Dr Sylvester Abanseka is a Principal Information Security GRC Analyst at Cloudflare. He holds a Doctor of Business Administration in management information systems and enterprise resource planning (ERP) from California Intercontinental University, where he completed research on automation in business information systems to enhance audit evidence gathering in cloud-native organisations. He also holds a Master of Science in security management from the University of Portsmouth and a Bachelor of Laws (LLB, Hons) from the University of Buea. Sylvester’s expertise spans ERP change and release management, cloud security, governance, risk and compliance, and strategic peer advisory for global enterprise clients across the North American, Europe, the Middle East and Africa, and Asia Pacific, Japan, and China regions. With over 12 years’ operational and leadership experience across organisations including VMware, Vodafone, GlaxoSmithKline, and British Aerospace Electronic Systems, Sylvester holds certifications including Certified Information Systems Security Professional, Certificate of Cloud Security Knowledge, Amazon Web Service Security Specialty, International Organization for Standardization 27001 Lead Implementer, and a certificate in AI Security & Governance. He was Cloudflare’s representative at the 2025 Gartner Executive Summit, moderating on the topic of ‘Growth and Security — Innovation, Emerging Tech, and Business Agility’, and has published an article on LinkedIn ‘On Triggers for Automation: A Balancing Act of Volume, Effort, and Frequency’.