Research
Keel Research
Original data and cited analysis on governance, risk, and compliance for small and mid-sized businesses. We show our work: every figure is either computed from Keel’s own open data or attributed to a named public source.
-
Original data (Keel crosswalk)
AI governance is mostly new work, and the three AI regimes only partly overlap
Your SOC 2 program barely touches AI governance, and the three AI regimes cover less of each other than the do-it-once story suggests. We measured both against our own open control library.
Read the report -
Original data (Keel crosswalk)
How much do compliance frameworks actually overlap?
If you already do SOC 2, how much of ISO 27001 is free? We measured it against our own open control library. The overlap is larger than most teams expect.
Read the report -
Third-party sources, cited
What SOC 2 really costs an SMB (and why deals wait on it)
For a small company, the expensive part of compliance is rarely the audit invoice. It is the months of preparation and the revenue that sits in security review. Here is what the public data says.
Read the report