CI/CD Modernisation with Compliance Evidence for a Regulated Software Vendor
Challenge
Satisfying auditors that automated evidence was equivalent to (or better than) the previous manual records. We worked with the QA/RA team to map each control to a pipeline artifact and ran parallel releases for two cycles.
Approach
We consolidated legacy Jenkins jobs into GitLab CI pipelines with reusable templates. Each pipeline links commits to requirements and tickets, runs automated test suites, and stores test reports, approvals, SBOMs and deployment records in an immutable evidence store. Release approvals are captured as electronic sign-offs. Blue-green deployments with automated smoke tests and one-click rollback reduced release risk.
Outcome
Illustratively ~60–80% less effort to assemble release evidence Smaller, more frequent releases with lower change-failure rates Full traceability from requirement to deployed build Faster, repeatable rollback Audit preparation shifted from weeks to days