LeadDev Berlin

Painless Compliance, and a Thousand Audits a Day

November 2025 · Berlin, Germany

The core idea: an audit is a test plan. Not metaphorically, literally. It defines expected behaviour, checks it against evidence, and reports pass or fail. Engineering teams have spent two decades building infrastructure to run test plans continuously, in CI/CD, at every change. Compliance mostly still runs that same test plan once a year, by hand, with dozens of people copying screenshots into spreadsheets.

The talk walked through what changes when compliance checks move into the pipeline instead of staying a separate, periodic process: security requirements that can be codified and run automatically, and the parts of compliance that still need human judgement clearly separated from the parts that don’t.

Read the related insights post

Back to Talks