# Generate an audit bundle

Use `kix compliance audit` when a review or compliance process needs the
cluster's policy findings and build evidence together. The command evaluates
the cluster locally and writes five files.

## Write the bundle

Choose an output directory and, in CI, supply the workflow URL as the builder
ID:

<Command {...audit} />

The directory contains five files:

<Command {...auditFiles} />

`audit-report.md` is the human-readable summary. The other files provide OSCAL
Assessment Results, SLSA provenance, a CycloneDX SBOM, and SARIF scorecard
findings.

## Select a framework

SOC 2 is the default control mapping. Select another supported framework with
`--framework`:

<Command
  commands={[
    "kix compliance audit 19-scorecards --out ./compliance-iso27001 --framework iso27001",
  ]}
  cwd="kix-examples/"
/>

The accepted values are `soc2`, `iso27001`, `dora`, and `nis2`.

## Replace an existing bundle

Kix refuses to write over an existing output directory. Pass `--force` when
the job intentionally refreshes that directory:

<Command
  commands={["kix compliance audit 19-scorecards --out ./compliance --force"]}
  cwd="kix-examples/"
/>

Archive or upload the directory as one CI artifact so the files from a single
evaluation remain together.

:::note[Reference]
See [Compliance commands](/docs/reference/cli/compliance-commands/) for each
file's format and the framework options.
:::