Governance
AWS Audit Manager
Automates compliance evidence collection and maps evidence to audit framework controls for audit-ready reporting.
Key points
- Continuously collects evidence from AWS services such as CloudTrail, AWS Config, and Security Hub.
- Maps collected evidence to controls in frameworks such as SOC 2, HIPAA, GDPR, and PCI DSS.
- Produces assessment evidence and reports for auditors and governance teams.
- Automates evidence collection and reporting but does not enforce or remediate controls.
When to use it
- Prepare audit evidence for regulated AI/ML workloads.
- Track compliance evidence against common frameworks during governance reviews.
- Reduce manual effort when collecting evidence from AWS services for audits.
Exam tips
- Audit Manager is for evidence collection and audit reporting, not control enforcement.
- CloudTrail logs API calls and Config records resource configuration; Audit Manager maps evidence to framework controls.
- Use it when the scenario asks for SOC 2, HIPAA, GDPR, or PCI DSS audit evidence.