Yoetz.ai Team May 14, 2026 9 min read

Enterprise HRIS Compliance: SOX, GDPR, ISO 27001, PCI-DSS

Compliance teams talk in framework language: SOX §404, GDPR Art. 5, ISO 27001 Annex A.9, PCI-DSS 8.2. HRIS teams talk in tenant language: security groups, business processes, ISUs, calculated fields. The translation between the two is where every audit finding lives. This guide is the translation.

Abstract visualisation of layered audit evidence and control checks
CompliancePillar

SOX §404 — Internal Controls over Financial Reporting

Workday processes payroll and controls compensation data, which is material to financial reporting. SOX §404 requires management to assess the effectiveness of the controls around that data. Auditors test 12 ITGCs in every Workday review: user provisioning and deprovisioning, privileged access review, ISU access scope, ISU UI session restriction (the 'Do Not Allow UI Sessions' flag), integration monitoring, change management, segregation of duties, password policy and credential rotation, business process approval definitions, calculated field validation, and review of Workday's SOC 1 Type II report.

GDPR — the four articles that always hit Workday

  • Art. 5 (data minimisation): an unconstrained security group on a compensation domain returns data for every worker, not just the team. Violation by default.
  • Art. 17 (right to erasure): if your termination workflow leaves the worker record active in supervisory orgs, you are still processing their data.
  • Art. 25 (privacy by design): security must be the default state of new configuration, not an opt-in.
  • Art. 32 (security of processing): integration credentials in personal accounts, no MFA on ISUs, missing 'Do Not Allow UI Sessions' — all in scope.

ISO 27001 — the Annex A controls auditors map to HRIS

A.9 Access Control maps directly to Workday security groups, ISSGs, and the ISU model. A.12 Operations Security maps to integration monitoring, alert subscribers, and change management. A.14 System Acquisition, Development and Maintenance maps to Preview promotion controls and calculated field validation. The same controls in SuccessFactors translate to Permission Roles, Permission Groups, RBP rules, and integration monitoring in CPI.

PCI-DSS — when payroll becomes a card data problem

Most teams assume Workday is out of PCI-DSS scope because it does not store card numbers. That changes the moment an expense integration pushes card data through Workday Studio, or a benefits enrolment workflow stores bank account and routing numbers in custom object fields. Once that data flows through the tenant, the security around it is in scope — meaning the same security groups, ISUs, and integrations are now PCI-DSS controls too.

Abstract visualisation of sequential release readiness gates
Abstract visualisation of sequential release readiness gates

How to use one scan for four frameworks

Every Yoetz.ai finding is tagged with the SOX control number, GDPR article, ISO 27001 Annex A control, and PCI-DSS requirement it impacts. Fixing the same security group misconfiguration once moves you forward against four frameworks simultaneously. That is the structural reason a single 2-hour scan replaces three to four separate consulting engagements.

Why compliance frameworks overlap more than they conflict

HRIS and compliance teams often treat SOX, GDPR, ISO 27001 and PCI-DSS as four separate audit exercises requiring four separate evidence-gathering efforts, largely because they are typically owned by four different internal stakeholders (Finance/Internal Audit for SOX, Legal/Privacy for GDPR, IT Security for ISO 27001, and Finance/PCI Scope owners for PCI-DSS). In reality, the underlying Workday, SAP or Oracle controls these frameworks test are substantially the same controls, described in different regulatory language.

An unconstrained security group granting broad access to compensation data is simultaneously a SOX ITGC deficiency (inadequate access control over financially material data), a GDPR Article 5 violation (failure of data minimisation), an ISO 27001 Annex A.9 gap (inadequate access control), and potentially a PCI-DSS issue if compensation data includes payment card details for expense reimbursement. Organisations that recognise this overlap and build a single, framework-agnostic control library mapped to all four frameworks simultaneously dramatically reduce the total audit effort compared to running four independent compliance programs against the same underlying tenant.

Building a unified control library mapped across frameworks

  • Access provisioning and deprovisioning — maps to SOX ITGC, GDPR Art. 32, ISO 27001 A.9.2, and PCI-DSS 7.1/8.1.
  • Segregation of duties — maps to SOX §404, ISO 27001 A.5.3, and (where payment processes are involved) PCI-DSS operational segregation requirements.
  • Change management for configuration changes — maps to SOX ITGC change management controls and ISO 27001 A.12.1.2.
  • Data retention and erasure — maps to GDPR Art. 17 specifically, with a secondary mapping to ISO 27001 A.18 (compliance with legal requirements).
  • Encryption and data protection in transit and at rest — maps to GDPR Art. 32, ISO 27001 A.10, and PCI-DSS 3.x/4.x wherever card data flows through the tenant.
  • Vendor and sub-processor risk management (relevant if third-party integrations process personal or card data) — maps to GDPR Art. 28 and ISO 27001 A.15, and PCI-DSS 12.8 for service providers.

The audit evidence auditors actually accept versus what teams often produce

A recurring friction point in compliance audits is the gap between the evidence auditors formally require and the evidence HRIS teams instinctively produce. Auditors testing SOX controls need to see evidence that a control operated consistently over the full testing period — typically requiring multiple dated snapshots across the year, not a single point-in-time export gathered the week before the audit. Teams that only run a security review once a year, right before the audit, frequently fail testing not because the control itself was deficient but because they cannot demonstrate the control operated throughout the period, only that it existed at the moment of the snapshot.

This is the single strongest practical argument for continuous or at least quarterly automated scanning over annual manual review: it's the difference between being able to produce twelve months of dated evidence versus a single snapshot that an experienced auditor will immediately recognise as insufficient for operating-effectiveness testing (as opposed to design-effectiveness testing, which a single snapshot can satisfy).

Regional and sector-specific compliance layers beyond the big four

Organisations operating in specific geographies or sectors carry compliance obligations beyond SOX, GDPR, ISO 27001 and PCI-DSS that also touch HRIS configuration. California's CCPA/CPRA imposes data subject rights obligations similar in spirit to GDPR but with distinct technical requirements around opt-out mechanisms and data sale definitions. Financial services organisations subject to SOC 2 Type II reporting need HRIS evidence mapped to the Trust Services Criteria, particularly CC6 (logical access controls). Healthcare organisations with HIPAA obligations need to consider whether any HR data (particularly disability accommodation or leave-of-absence medical documentation stored in the HRIS) falls under HIPAA's business associate provisions.

Each of these additional frameworks can generally be layered onto the same unified control library described above rather than requiring an entirely separate compliance program, provided the underlying tenant configuration audit is comprehensive enough to produce framework-agnostic findings that map cleanly to whichever regulatory language a given framework uses.

The auditor relationship: what makes external audits faster and cheaper

External auditors (whether Big 4 firms conducting SOX testing or specialised ISO 27001 certification bodies) bill by the hour, and the single biggest driver of audit cost is how much time the auditor spends gathering and validating evidence versus how much time the organisation spends producing it themselves in advance. Organisations that arrive at an audit with a pre-organised, dated evidence package mapped to the specific controls being tested consistently see shorter audit durations and lower fees than organisations that require the auditor to request evidence piecemeal over the course of the engagement.

This is a direct, quantifiable benefit of running continuous automated scanning with framework-mapped output: the evidence package essentially assembles itself as a byproduct of ongoing operational monitoring, rather than requiring a dedicated, disruptive evidence-gathering sprint in the weeks before each audit — a sprint that inevitably pulls HRIS team members away from their regular work at the exact time year-end or audit-season demands are also peaking.

Common compliance program mistakes that create false confidence

  • Treating a clean prior-year audit result as evidence the tenant is still clean today, when configuration has continued to change in the intervening months.
  • Scoping the compliance review to Production only, ignoring that Sandbox and Implementation tenants sometimes contain copies of real production data used for testing, which brings them into scope for GDPR and other data protection frameworks.
  • Assuming a SOC 1 or SOC 2 report from the software vendor (Workday, SAP, Oracle) covers the customer's own configuration — vendor SOC reports cover the vendor's infrastructure and platform controls, not how the customer configured security groups, business processes or integrations within that platform.
  • Relying on manual attestations ('I confirm access is appropriate') from business owners who lack visibility into the full technical access model, rather than technical evidence of what access actually exists.
  • Running compliance reviews in silos across frameworks, duplicating effort and producing inconsistent findings when two different teams review the same underlying control independently and reach different conclusions.

Frequently asked questions

Do we need separate audits for SOX, GDPR, ISO 27001 and PCI-DSS, or can one process cover all four?

One comprehensive tenant configuration audit, with findings tagged against each applicable framework's specific control language, can satisfy the underlying technical requirements of all four simultaneously. You'll still need framework-specific narrative reporting and sign-off processes, but the underlying evidence-gathering doesn't need to be duplicated four times.

Does the vendor's own SOC 1/SOC 2 report reduce our compliance obligations?

It reduces the scope of what you need to test regarding the vendor's own infrastructure and platform security, but it does not cover how you've configured security groups, business processes, ISUs and integrations within your tenant — that configuration layer remains entirely your responsibility to test and evidence.

How does GDPR apply to a company with no employees or customers in the EU?

GDPR can still apply if you process personal data of EU-based individuals for any reason — EU contractors, EU job applicants, or EU-based employees of a subsidiary, for example. Many organisations without obvious EU operations are still in scope because of these edge cases and should confirm applicability with legal counsel rather than assuming it doesn't apply.

What's the single highest-leverage first step for an organisation that has never run a formal HRIS compliance audit?

Run a comprehensive configuration scan across security, business processes and integrations first, before engaging external auditors or consultants. Understanding your actual current-state findings gives you a far more productive and cost-effective starting point for any subsequent compliance engagement, rather than paying consultants to discover the same baseline issues from scratch.

Continue reading

Get the next HR tenant health briefing

Monthly. No spam. Unsubscribe with one click.

Find out what's broken in your tenant

Free first scan. Read-only access. Results in under 2 hours.

Start Your Free Scan

Related posts