COMPLIANCEColleague · FAQ

Frequently asked questions

Straight answers about what Compliance Colleague is, what it isn't, and how it works. Can't find what you're looking for? Email support@compliancecolleague.ai.

What does Compliance Colleague do?

Compliance Colleague is a chat-based compliance advisory tool for GRC practitioners, auditors, and security leaders. Every answer is grounded in the actual text of the standard you select -- not general knowledge about it -- across a library of information security and AI governance standards.

Three core things it does today:

  • Answer questions against a specific standard -- pick a framework, ask a question, get an answer grounded in that standard's actual clauses.
  • Crosswalk your standard against any other -- start from a standard in your plan and see where any framework in the library aligns with it and where it diverges, without building your own crosswalk.
  • Review an uploaded document against a standard -- upload a policy, procedure, or control document (PDF or Word) and get a structured review flagging what it satisfies and where the gaps are.
What does Compliance Colleague NOT do?

Compliance Colleague is a research and analysis tool built for the people who interpret, apply, audit or assess standards. It supports, and doesn't replace, the professional judgment of a QSA, auditor, attorney or CISO: every finding cites its clause so you can verify it, and the sign-off stays with you. It isn't legal advice, and using it does not create a professional relationship with us.

Specifically, it does not:

  • Perform an audit, assessment, or certification, or issue any finding that satisfies a regulatory or contractual requirement to engage a real assessor.
  • Guarantee compliance with any standard or regulation.
  • Replace your own judgment -- AI-generated output can be incomplete or wrong, and every answer should be independently verified before you rely on it.
  • Act on your behalf with a regulator, client, or auditor, or let you represent that Compliance Colleague performed part of a professional engagement.

If you use Compliance Colleague as part of a real audit or client engagement, you -- the credentialed professional -- remain solely responsible for that engagement. See our Terms of Service, Section 3, for the full language.

Which standards and frameworks does it cover?

Compliance Colleague covers 30 standards spanning information security, privacy, and AI governance -- including PCI DSS, ISO/IEC 27001, SOC 2, HIPAA, GDPR, FedRAMP, CMMC 2.0, NIST 800-53, NIST CSF, the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework, among others. Your plan determines how many of these you have access to at once -- see Pricing below.

How does document review work?

Upload a policy, procedure, or control document (PDF or Word) against a standard you've selected. Compliance Colleague reviews it and returns a structured verdict -- a written summary of where the document stands, plus a itemized list of what it satisfies and where the gaps are, each tied back to the relevant part of the standard. It's a first pass to speed up your own review, not a finished audit workpaper.

Is my data used to train AI models?

No. Compliance Colleague uses Anthropic's commercial API, which by default does not use inputs or outputs to train models. We don't use any feedback mechanism or program that would create an exception to that. See our Terms of Service, Section 11, for the sourced detail.

How securely is my uploaded document handled?

Documents are sent directly to Anthropic's API for review and are not retained by us beyond what's needed to generate your result. Accounts require multi-factor authentication, and we monitor for patterns consistent with credential sharing across devices. We don't currently hold SOC 2 or ISO 27001 certification ourselves -- we won't claim security credentials we don't have.

How is pricing structured?

Three self-serve plans, based on how many standards you need at once:

  • Solo -- $30/mo, 1 standard
  • Practitioner -- $50/mo, 2 standards
  • Virtual CISO -- $100/mo, 5 standards

You choose which standards fill your plan's slots when you subscribe, and you can swap them a limited number of times per year -- see “Can I change which standards my plan covers?” below for exactly how that works. Every plan can also compare its standards against any standard in the library -- see “How does comparing standards work on my plan?”

Each plan includes a monthly usage allowance. Every payment, first or renewal, comes with a 14-day money-back guarantee -- see our Refund Policy.

How does comparing standards work on my plan?

The standards in your plan are your anchors. You can compare any of them against any standard in the library, not just the others in your plan:

  • Solo -- your one standard, against any other
  • Practitioner -- either of your two, against any other (or against each other)
  • Virtual CISO -- any of your five, against any other (or against each other)

When the other standard isn't in your plan, the answer is a crosswalk from yours: organised around your standard's requirements, with each one mapped to the other framework and a note of where the two differ. Asking a question about a standard on its own, or reviewing a document against it, needs that standard in your plan.

Comparisons draw on your monthly usage allowance like any other question -- they read two standards at once, so each one uses roughly three times as much as a single-standard question. Comparison isn't part of the free trial.

Can I change which standards my plan covers?

Yes, within limits. Your plan covers a set number of standards, and you can swap them a fixed number of times per year:

  • Solo -- 1 change per year
  • Practitioner -- 2 changes per year
  • Virtual CISO -- 5 changes per year

Two things worth knowing before you use one. Changes take effect immediately and can't be undone -- you lose access to the standard you drop right away, and switching back later would spend another change rather than reversing the first one. And the allowance resets on your subscription anniversary, not on January 1st.

To make sure a wrong pick at signup doesn't cost you your whole year, any change made in the first 14 days of a new plan is free and doesn't count against your allowance. Upgrading to a larger plan also resets your allowance to the new plan's number.

Why there's a limit at all: plans are priced by how many standards they cover, so unlimited swapping would effectively turn the smallest plan into access to the entire library. If you genuinely need to move between standards more often than your plan allows, a larger plan is usually the cheaper answer -- get in touch if neither fits.

What happens if I go over my monthly allowance?

Nothing automatic. Usage beyond your plan's included allowance requires opting in to pay-as-you-go billed near our actual cost -- it's never charged silently. Without opting in, you'll simply need to wait for your allowance to reset or upgrade your plan.

Is there a free trial?

Yes -- start a free trial with no card required, and no authenticator app to set up. Each trial includes either one full document review against a single standard, or up to two questions against any standard(s) you choose (for example, one on PCI DSS and one on the EU AI Act) -- not both, since your first request locks in which of the two you're using. You have 30 days from the day you start, and you don't have to use it all in one sitting: ask one question today and the other next week if you like. Anything unused when the 30 days are up simply expires. Side-by-side comparison isn't included in the trial: it's the most computation-intensive thing Compliance Colleague does, so it's reserved for subscribers. One trial per device.

Can I share my account with my team?

No -- each subscription is a single-user license, and we actively monitor for the pattern of one login being used across several distinct devices. Each person who uses Compliance Colleague needs their own subscription. Multi-seat team plans aren't available yet.

This FAQ is a plain-English summary. Where it and the Terms of Service differ, the Terms of Service control.