One compliance record across models and frameworks
Different versions of the same control, risk or policy do not have to be maintained in several places. A change is easier to assess when the related information belongs to one program.
One connected record
General meaning: A shared, consistently structured representation of information used across different interfaces and workflows.
Why it matters
Different versions of the same control, risk or policy do not have to be maintained in several places. A change is easier to assess when the related information belongs to one program.
With Kanonik
Controls, policies, risks, evidence references and claims sit in a shared structure. Your AI and the review interface work with that record, and framework views draw on it. Changing a model or looking at another framework need not mean recreating the underlying program.
What to consider
A shared structure still needs clear ownership and good information. It does not automatically resolve conflicting source documents or make every framework requirement equivalent.
Related scenarios: One connected record | Glossary definition
Event history
General meaning: A record kept as a sequence of changes, from which the current state is calculated.
Why it matters
A team can see how the program reached its current state. Overwriting the previous version can make a later review depend on recollection and scattered backups.
With Kanonik
Recorded changes stay available so the program can be examined beyond its latest state. That helps a team investigate how a record developed.
What to consider
Rebuilding an earlier recorded state is not the same as rerunning the AI model that produced it, and intermediate drafts are not all kept.
Decision history
General meaning: The traceable relationship between a decision, its predecessors, supporting information and revisions.
Why it matters
A later question about why work was changed, sent back or accepted can be answered from the record. A final approval alone may not explain the path that led to it.
With Kanonik
Kanonik keeps the recorded feedback, verification results and named approval behind a change, with its before-and-after state. Reviewers can see why work was sent back or accepted without reconstructing the exchange from email. The retained history does not include every intermediate draft or all AI reasoning.
What to consider
The retained path does not include every intermediate draft or all AI reasoning. Use the recorded feedback and decisions for the questions they can answer.
Two-date history
General meaning: A history that keeps two dates for each fact: when it applied and when it was recorded.
Why it matters
The date something happened stays separate from the date it was recorded. For example, a control might take effect in March but only be entered in April; those dates answer different audit questions.
With Kanonik
Historical questions about when a fact applied are distinguished from when it was recorded. Those dates can matter when explaining a past decision.
What to consider
You can read the record as of an earlier date, but not every record type accepts backdated corrections.
Framework-independent record
General meaning: The underlying information model is not tied to one standard or assessment framework.
Why it matters
The underlying program can be reused where requirements overlap, instead of maintaining a separate copy for every assessment.
With Kanonik
Kanonik keeps program information separate from the framework used to view it, and every supported framework (SOC 2, ISO/IEC 27001, HIPAA, GDPR and 12 more) reads from the same record. When you add a second framework, Kanonik suggests how your existing controls map to it, and a person confirms each mapping.
What to consider
Requirements are not interchangeable because they look similar, and meeting one framework does not by itself satisfy another.
Related scenarios: Framework-independent record | Glossary definition
Continue reading
Run your own record on Solo.
Solo is $99 a month and starts with a 14-day trial.