Resources
NOVA Compliance blog
Practical writing on compliance frameworks, evidence, control mapping and responsible assurance, published by Eredox Pty Ltd.
Every article here is written to stand on its own: what a requirement asks for, how evidence is expected to look, and where a human decision is still required. Articles are published only once reviewed and approved — nothing appears here as a placeholder.
Choosing your first compliance framework
SOC 2, ISO/IEC 27001 or Essential Eight — how the choice usually gets made, and the questions worth answering before committing.
Read articlePlanned topics
Subjects in the editorial backlog. These are planning topics only and are not published articles.
Frameworks
What is ISO/IEC 27001 and who needs it?
Frameworks
SOC 2 compared with ISO/IEC 27001
Evidence
What is compliance evidence?
Frameworks
Preparing for a SOC 2 Type II period
Frameworks
Understanding Essential Eight maturity
Responsible AI
ISO/IEC 42001 and AI management systems
Programme management
How control mapping reduces duplicate compliance work
Evidence
What makes evidence audit-ready?
Risk
What is risk acceptance?
Responsible AI
Human oversight in AI-assisted compliance
Programme management
Managing multiple compliance frameworks
Programme management
Compliance readiness compared with certification
Articles are published by Eredox Pty Ltd. NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.