Auditen

Audit, risk & compliance, made legible.

Regulatory news written from the day's enforcement actions, plain-English guides to the frameworks you actually get audited against, and a working glossary of the terms — kept current, automatically.

From the newsdesk

All news →

Framework hub

All frameworks →
AICPA Tier 1

SOC 2

An attestation report on a service organization's controls over security, availability, processing integrity, confidentiality and privacy — the Trust Services Criteria.

11 guides
ISO/IEC Tier 1

ISO 27001

The international standard for an information security management system (ISMS): a risk-based framework for selecting, operating and improving security controls.

10 guides
PCI Security Standards Council Tier 1

PCI DSS

The security standard every organization that stores, processes or transmits cardholder data must meet, built around twelve core requirements.

12 guides
European Union Tier 1

GDPR

The EU regulation governing how personal data of people in the EU and UK must be collected, processed, secured and accounted for.

10 guides
European Union Tier 1

NIS2

The EU's network and information security directive: cybersecurity risk-management duties, management accountability and strict incident-reporting deadlines for essential and important entities.

10 guides
European Union Tier 1

EU AI Act

The first comprehensive AI law: a risk-based regime that bans some AI practices outright, puts heavy obligations on high-risk systems, and adds transparency duties for chatbots, deepfakes and general-purpose models.

14 guides
European Union Tier 1

Cyber Resilience Act

Cybersecurity requirements for manufacturers of hardware and software sold in the EU: secure-by-design products, vulnerability handling through the product's life, CE marking and rapid reporting of exploited flaws.

10 guides
US HHS Tier 1

HIPAA

The US law protecting health information, enforced through its Privacy, Security and Breach Notification Rules.

9 guides
European Union Tier 1

DORA

Operational resilience rules for the EU financial sector: ICT risk management, incident reporting, resilience testing and hard obligations around ICT third parties, applying since January 2025.

10 guides
US Congress / SEC / PCAOB Tier 1

SOX

The US financial-reporting integrity law: officer certifications and audited internal control over financial reporting — with IT general controls at the heart of every modern SOX programme.

10 guides
NIST Tier 1

NIST CSF 2.0

The most widely used voluntary cybersecurity framework: six functions organizations use to describe, assess and improve their security posture — and the map other standards are measured against.

10 guides
US SEC Tier 1

SEC Cyber Disclosure

The SEC's rules requiring public companies to disclose material cyber incidents within four business days and to describe their cyber risk management and governance annually.

8 guides
UK Government / OPSS Tier 1

UK PSTI

The UK's consumer connectable-product security law, enforceable since April 2024: no default passwords, a vulnerability disclosure route, and honesty about how long products get security updates.

8 guides
ISO/IEC Tier 1

ISO 42001

The international standard for an AI management system (AIMS): the certifiable governance wrapper organizations use to run AI responsibly — and increasingly to evidence EU AI Act readiness.

9 guides

Auditen glossary

Full glossary →

Featured glossary guide

From the glossary

Residual risk

Residual risk is the level of risk that remains after security controls and mitigation strategies have been implemented. It represents the actual exposure an organization faces once its defenses are in place. If this remaining risk exceeds a company's defined risk appetite, further controls must be added or the risk must be formally accepted by management.

Read the full entry →

Recent wire updates

The Wire →
Eisner Advisory Group agrees to settle data breach class action for $1.05 million: Who can claim and how to file - Claim Depot

Eisner Advisory Group has agreed to settle a class action lawsuit for $1.05 million following a data breach.

KT Faces 54 Billion Won Penalty for Data Breach and Unauthorized Payments - 조선일보

KT faces a penalty of 54 billion won due to data breaches and unauthorized payments.

Coupang found liable for compensation in South Korean data-breach mediation - MLex

Coupang was found liable for compensation in a South Korean data breach mediation process.

Amazon.com, Inc. Q2 2026 Financial Results – Earnings, Cash Flow & SEC Filings Overview - Minichart

Amazon announced its Q2 2026 financial results and SEC filings.

EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes - JD Supra

The EU AI Act has been updated with eight finalized compliance changes via the Digital Omnibus.

RTG eyes US$100m revenue after a strong half-year outturn - Herald.co.zw

RTG is projecting US$100 million in revenue following a strong half-year financial performance.