Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
6 to work through
-
intermediate Multiple choice
An annual audit tests a control by sampling 25 changes from the 10,000 made that year. Suppose 5% of changes actually violate the control. Roughly what is the probability that the sample contains at least one violation?
2 min answer -
advanced
An organisation is audited annually against controls that are tested by sampling. How should continuous controls monitoring be architected, and what changes about the assurance itself?
2 min answer -
advanced
An organisation's controls are assessed annually and it wants continuous assurance. What changes architecturally?
2 min answer -
advanced
Design continuous controls monitoring for a large cloud estate. What does it monitor and how does it avoid becoming noise?
1 min answer -
advanced
Quarterly access reviews take two weeks of manager time and everyone approves everything. How do you make this a real control?
2 min answer -
advanced
You implement continuous controls monitoring. It immediately reports 1,800 exceptions. Is this an improvement?
2 min answer
5 terms in this topic
Continuous Controls Monitoring
Automatically testing control effectiveness continuously across the whole population, rather than through periodic manual sampling.
conceptControl Coverage
The proportion of the actual estate a control operates on - the metric that determines whether monitoring provides assurance or false confidence.
practiceControl Test Automation
Executing a control's test continuously against the whole population rather than sampling it annually, which changes both the detection latency and t…
conceptCoverage Drift
A control operating perfectly on a diminishing share of the estate - passing every assessment of the systems it covers while providing progressively …
metricSampling Risk
The probability that a sample-based control test misses a violation that exists in the population - which for small samples and rare violations is mo…
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.