Compliance Cost Calculator
Total the annual cost of a compliance programme across audit fees, consultancy, internal effort, tooling and evidence, per employee and per framework.
Inputs
Total Annual Compliance Cost
$560,900
Cost per Employee
$467
Cost per Framework
$186,967
Cost per In-Scope System
$6,599
Three-Year Total Cost
$1,598,565
Evidence Collection Cost
$48,400
Evidence as a Share of Total Cost
8.6%
Plausible Saving from Automation
$38,640
Plausible Saving from Control Mapping
$89,744
Where the Money Is
Cost mix is reasonable — hold audit scope steady and keep driving evidence effort down
Step by step
Values used
Frameworks in scope = 3 frameworks; Employees in the organisation = 1,200 people; Systems in audit scope = 85 systems; External audit and certification fees = 95,000 $/year; Consultancy days used = 40 days; Consultancy day rate = 1,200 $/day; Full-time equivalents on compliance = 2.50 FTE; Fully loaded cost per FTE = 95,000 $/year; GRC tooling and licences = 60,000 $/year; Hours spent collecting evidence each quarter = 220 hours; Blended internal hourly cost = 55 $/hour; Penetration tests per year = 4 tests; Cost per penetration test = 18,000 $
Compliance Cost
Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each.
Overlap and automation savings
Control mapping saving = 8% of total cost per additional framework, capped at 30%, on the basis that overlapping frameworks share most of their control tests.
Total Annual Compliance Cost
= 560,900
Cost per Employee
= 467
Cost per Framework
= 186,967
Cost per In-Scope System
= 6,599
Three-Year Total Cost
= 1,598,565
Evidence Collection Cost
= 48,400
How it works
The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words. Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.
Formulas
Compliance Cost
Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each.
- evidenceCost
- Quarterly evidence hours annualised at the blended internal rate
- internalCost
- Fully loaded, so including employer costs rather than salary alone
- × 3 × 0.95
- Three-year cost with a modest efficiency assumption after year one
Overlap and automation savings
Control mapping saving = 8% of total cost per additional framework, capped at 30%, on the basis that overlapping frameworks share most of their control tests.
- automationSaving
- 60% of evidence effort plus 20% of consultancy, the range typically achievable with continuous evidence collection
- overlapSaving
- Available only if controls are mapped across frameworks rather than tested per framework
Frequently Asked Questions
How is Compliance Cost calculated?
Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each. The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words.
Why does Compliance Cost matter?
Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.
What values do I need to enter?
This calculator takes 13 inputs: Frameworks in scope, Employees in the organisation, Systems in audit scope, External audit and certification fees, Consultancy days used, Consultancy day rate, Full-time equivalents on compliance, Fully loaded cost per FTE, GRC tooling and licences, Hours spent collecting evidence each quarter, Blended internal hourly cost, Penetration tests per year, Cost per penetration test. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why is the cost per framework not simply the total divided by frameworks?
It is here, deliberately, as a blunt unit cost — but the marginal cost of a second framework is much lower than the first because the control set overlaps heavily. Use the overlap saving line for the marginal question and the per-framework figure only for comparing your programme with a peer's.
Is automation really worth 60% of the evidence effort?
That is the upper end of what continuous control monitoring typically delivers, and only for controls whose evidence is machine-generated: access reviews, configuration baselines, patch levels, backup success. Controls that depend on human judgement, like risk assessment or supplier due diligence, barely improve.
You might also need
- Security Investment ROI CalculatorCommonly used together
- PCI DSS Compliance CalculatorCommonly used together
- GDPR Compliance CalculatorCommonly used together
- Control Gap CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- ISO 27001 Compliance CalculatorAlso in Compliance & GRC