Spreadsheets describing controls drift from reality. Compliance as code keeps the source of truth next to the infrastructure that implements it.
Use Terraform modules for approved patterns, OPA/Conftest or cloud-native policy for merge-time checks, and continuous config assessment in the accounts themselves.
Map each control to module outputs, policy packs, and log queries. Auditors follow evidence faster when the trail is technical and current.
This is readiness engineering—not a promise that a framework certificate will appear automatically.
Version policy packs and announce breaking changes like API changes.
Include exception workflow with expiry—silent bypasses destroy the control system.
Generate evidence bundles from pipelines so humans are not copying console screenshots by hand.
Key takeaways
- Encode approved patterns in modules; block known-bad configs at merge time.
- Map controls to module outputs, policy packs, and live config queries.
- Keep auditor-friendly narratives tied to technical evidence paths.
FAQ
OPA vs native cloud policy?
Use both where useful: OPA/Conftest for PR-time checks on Terraform plans; cloud-native policy for continuous runtime posture.
Does compliance as code replace audits?
No. It makes audits faster and more accurate by reducing drift between documents and reality.