Compliance evidence triage

Use case Β· Compliance

← All use cases
⛉

Compliance evidence triage

Compliance

Classify each uploaded document/screenshot against the right control (SOC 2 / ISO 27001) and flag whether it's sufficient evidence β€” at scale.

The routing recipe
Job typeClassification / routingPolicyCheapest that passesConstraintsgroq
routes to
GPT-OSS 20B groq
groq:openai/gpt-oss-20b
94.4
match score
84.6
task fit
100
cost
96.4
speed
Why this model from benchmarks & capabilities
  • "Classification / routing" leans hardest on instruction; GPT-OSS 20B scores 78/100 there β€” #23 of 40.
  • Strength on this class of work shows up on IFEval, MMLU (zero-shot), where OpenAI (open-weight) models are competitive.
  • Cost: free tier. Speed: ~1000 tok/s on Groq LPU.
  • Chosen over Llama 3.1 8B Instant for higher task-fit (84.6 vs 75.6) & cheaper.
Capability the job needsWeightGPT-OSS 20BCatalog rank
instruction0.9078#23 of 40
speed0.9096#1 of 40
knowledge0.3070#26 of 40
Relevant benchmarksIFEval MMLU (zero-shot) EconomicsCost: free tier.
Speed: ~1000 tok/s on Groq LPU.
vs runner-upChosen over Llama 3.1 8B Instant for higher task-fit (84.6 vs 75.6) & cheaper. (Llama 3.1 8B Instant, score 79.9)
Example result
Sample input β–Ύ
Artifact: 'AWS IAM policy export showing MFA enforced on all root and admin accounts, dated this month.'
control: SOC 2 CC6.1 (Logical access β€” authentication) evidence_type: configuration export sufficient: yes reason: Demonstrates MFA enforcement on privileged accounts with a current date; maps cleanly to access-control criteria. (Also supports ISO A.5.17 / A.8.5.)
Test it on your own data
Sign in to continue

LLM Switchboard is private β€” sign in with Authlee to access the control room.

Sign in with Authlee
← Back to home