Skip to content
Calcrivo

Compliance Cost Calculator

Total the annual cost of a compliance programme across audit fees, consultancy, internal effort, tooling and evidence, per employee and per framework.

Inputs

frameworks
people
systems
$/year
days
$/day
FTE
$/year
$/year
hours
$/hour
tests
$

Total Annual Compliance Cost

$560,900

Cost per Employee

$467

Cost per Framework

$186,967

Cost per In-Scope System

$6,599

Three-Year Total Cost

$1,598,565

Evidence Collection Cost

$48,400

Evidence as a Share of Total Cost

8.6%

Plausible Saving from Automation

$38,640

Plausible Saving from Control Mapping

$89,744

Where the Money Is

Cost mix is reasonable — hold audit scope steady and keep driving evidence effort down

Step by step

  1. Values used

    Frameworks in scope = 3 frameworks; Employees in the organisation = 1,200 people; Systems in audit scope = 85 systems; External audit and certification fees = 95,000 $/year; Consultancy days used = 40 days; Consultancy day rate = 1,200 $/day; Full-time equivalents on compliance = 2.50 FTE; Fully loaded cost per FTE = 95,000 $/year; GRC tooling and licences = 60,000 $/year; Hours spent collecting evidence each quarter = 220 hours; Blended internal hourly cost = 55 $/hour; Penetration tests per year = 4 tests; Cost per penetration test = 18,000 $

  2. Compliance Cost

    Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each.

  3. Overlap and automation savings

    Control mapping saving = 8% of total cost per additional framework, capped at 30%, on the basis that overlapping frameworks share most of their control tests.

  4. Total Annual Compliance Cost

    = 560,900

  5. Cost per Employee

    = 467

  6. Cost per Framework

    = 186,967

  7. Cost per In-Scope System

    = 6,599

  8. Three-Year Total Cost

    = 1,598,565

  9. Evidence Collection Cost

    = 48,400

How it works

The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words. Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.

Formulas

Compliance Cost

Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each.

evidenceCost
Quarterly evidence hours annualised at the blended internal rate
internalCost
Fully loaded, so including employer costs rather than salary alone
× 3 × 0.95
Three-year cost with a modest efficiency assumption after year one

Overlap and automation savings

Control mapping saving = 8% of total cost per additional framework, capped at 30%, on the basis that overlapping frameworks share most of their control tests.

automationSaving
60% of evidence effort plus 20% of consultancy, the range typically achievable with continuous evidence collection
overlapSaving
Available only if controls are mapped across frameworks rather than tested per framework

Frequently Asked Questions

How is Compliance Cost calculated?

Annual cost = audit fees + consultancy days × rate + FTE × loaded cost + tooling + evidence hours × 4 × hourly rate + penetration tests × cost each. The single biggest hidden line in most programmes is evidence collection, because it is spread across dozens of people in hours nobody books to compliance, and annualising the quarterly figure at a blended rate usually produces the largest surprise. The overlap saving reflects a real property of the frameworks: ISO 27001, SOC 2 and PCI DSS ask for the same access reviews and change records in different words.

Why does Compliance Cost matter?

Compliance budgets are argued over audit fees, which are usually the smallest controllable line, while the internal effort that dwarfs them never appears in a business case. These are cost estimates from your own inputs, not quotes.

What values do I need to enter?

This calculator takes 13 inputs: Frameworks in scope, Employees in the organisation, Systems in audit scope, External audit and certification fees, Consultancy days used, Consultancy day rate, Full-time equivalents on compliance, Fully loaded cost per FTE, GRC tooling and licences, Hours spent collecting evidence each quarter, Blended internal hourly cost, Penetration tests per year, Cost per penetration test. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why is the cost per framework not simply the total divided by frameworks?

It is here, deliberately, as a blunt unit cost — but the marginal cost of a second framework is much lower than the first because the control set overlaps heavily. Use the overlap saving line for the marginal question and the per-framework figure only for comparing your programme with a peer's.

Is automation really worth 60% of the evidence effort?

That is the upper end of what continuous control monitoring typically delivers, and only for controls whose evidence is machine-generated: access reviews, configuration baselines, patch levels, backup success. Controls that depend on human judgement, like risk assessment or supplier due diligence, barely improve.

You might also need