Continuous Auditing and Monitoring: Why Internal Audit Should Stop Waiting for the Next Audit
- John C. Blackshire, Jr.

- 1 hour ago
- 8 min read
Continuous Auditing and Monitoring — August 28 and October 30, 2026
Traditional Internal Auditing is largely periodic.
An audit is scheduled. The auditor selects a sample. Transactions are tested. Exceptions are identified. A report is issued.
Then the auditor may not examine that process again for another year—or perhaps three years.
Meanwhile, the business keeps operating.
Transactions continue.
Controls fail.
Employees change.
System access changes.
Vendors are added.
Payments are processed.
Fraud can occur.
Technology gives Internal Audit another option:
Instead of periodically asking what happened, continuously analyze what is happening.
That is the central concept behind Corporate Compliance Seminars' Continuous Auditing and Monitoring, a four-hour, 4-CPE Auditing webinar focused on designing and implementing continuous auditing programs, automated audit tools, fraud detection, SOX/ICFR monitoring and IT controls.
Upcoming sessions are:
Friday, August 28, 2026
Friday, October 30, 2026
What Is Continuous Auditing?
Continuous Auditing (CA) uses technology, data analytics and automated audit procedures to evaluate transactions, controls and risks on a much more frequent basis than traditional periodic auditing.
Instead of examining 50 transactions six months after they occurred, Internal Audit may be able to analyze an entire population every day, week or month.
CCS's program specifically examines the definitions of Continuous Auditing, Continuous Monitoring and Continuous Assurance, as well as what the course describes as the “Inverse Relationship.”
The difference is substantial.
Traditional Audit
Transaction Occurs
→ Months Pass
→ Audit Begins
→ Sample Selected
→ Exception Identified
→ Finding Reported
Continuous Auditing
Transaction Occurs
→ Automated Test
→ Exception Identified
→ Auditor Investigates
→ Corrective Action
The objective isn't necessarily to audit everything every second.
It is to reduce the time between the occurrence of a significant control exception and its identification.
Continuous Auditing and Continuous Monitoring Are Not the Same Thing
This distinction matters.
Continuous Monitoring is fundamentally a management responsibility. Management monitors operations and controls to determine whether processes are functioning properly.
Continuous Auditing is an assurance activity performed by Internal Audit to independently evaluate risks, controls and transactions.
They can use similar technologies.
They can analyze the same data.
But their responsibilities are different.
Management owns the controls.
Internal Audit independently evaluates them.
An organization should therefore avoid turning Internal Audit's continuous auditing system into a substitute for management's monitoring responsibilities.
Sampling Has a Fundamental Limitation
Suppose an organization processes 500,000 vendor payments each year.
Internal Audit selects 60.
All 60 are properly authorized.
That's useful audit evidence.
But what about the other 499,940 transactions?
Traditional sampling accepts this limitation because examining every transaction manually would be economically impossible.
Technology changes that equation.
Continuous auditing can potentially analyze the entire population for specific characteristics.
Instead of asking:
“Were the 60 transactions we selected properly approved?”
Internal Audit can ask:
“Identify every transaction in the population that appears to have bypassed the required approval.”
That is a fundamentally different audit capability.
CCS describes continuous auditing as enabling analysis of large transaction populations and reducing reliance on traditional sample-based periodic reviews.
Start With Risk—Not With the Software
A common mistake is purchasing an audit analytics platform and then asking:
“What should we do with it?”
Reverse the process.
Start with the business objective.
Then identify the risk.
Then determine the control.
Then determine what evidence exists.
Only then decide whether continuous auditing can improve assurance.
The methodology becomes:
Business Objective
→ Risk
→ Control
→ Data
→ Audit Test
→ Exception
→ Investigation
→ Conclusion
→ Corrective Action
CCS's implementation methodology follows a similar progression: define objectives, identify risks, controls and audit tests, establish data requirements, pilot the system, refine it, and manage and report the results.
What Could Internal Audit Continuously Test?
The possibilities are extensive.
Consider procure-to-pay.
Internal Audit could identify:
Duplicate invoices
Duplicate payments
Payments without purchase orders
Transactions immediately below approval thresholds
New vendors receiving unusually large payments
Vendor bank-account changes
Dormant vendors suddenly reactivated
Weekend transactions
Unusual payment patterns
Now consider user access:
Terminated employees with active accounts
Dormant accounts
Privileged users
Segregation-of-duties conflicts
Unexpected administrator access
Or financial reporting:
Unusual journal entries
Late-period adjustments
Round-dollar entries
Manual entries to sensitive accounts
Entries posted by unusual users
Continuous auditing turns these from occasional audit procedures into repeatable tests.
Fraud Detection Is a Natural Application
Fraud frequently hides in large transaction populations.
A fraudulent payment may look perfectly ordinary when viewed individually.
Its significance may become visible only when compared with other transactions.
For example:
Why does this employee share an address with a vendor?
Why are 27 invoices immediately below the approval threshold?
Why did this dormant vendor suddenly receive $300,000?
Why are payments repeatedly occurring on weekends?
Why does one bank account belong to multiple vendors?
CCS specifically includes occupational fraud, financial transactions, excluded-party listings and disbursement fraud in its continuous auditing curriculum.
The system doesn't necessarily conclude that fraud occurred.
It tells Internal Audit:
“This deserves investigation.”
Continuous Auditing Can Strengthen SOX and ICFR
Continuous auditing can be particularly valuable for organizations subject to Sarbanes-Oxley and ICFR requirements.
CCS devotes a section of the program specifically to applying continuous auditing to SOX compliance and the SEC's focus on ICFR.
Consider a key control that operates thousands of times during the year.
Traditional testing might examine a relatively small sample.
Continuous techniques may enable management or Internal Audit to identify exceptions across a much larger population.
That can help answer:
Is the control continuing to operate as designed between formal testing periods?
This is particularly valuable for high-volume automated processes.
IT Controls Are Another Strong Candidate
CCS also addresses continuous auditing for information technology, including:
Access Security
Development and Change
Implementation
IT Operations
Backup
Restoration and Recovery
IT Vendor Management.
Think about user access.
A conventional audit might review user access annually.
But employees don't leave the organization annually.
They leave every day.
Employees transfer departments.
Contractors finish assignments.
Administrators receive elevated privileges.
New accounts are created.
That raises an obvious question:
Why wait until the annual audit to identify inappropriate access?
Some risks are inherently better suited to continuous monitoring.
Continuous Auditing Does Not Mean Continuous Investigation
There is a practical problem.
Suppose Internal Audit builds an automated test and it generates:
8,427 exceptions.
Congratulations.
You have just created another problem.
A continuous auditing system needs thresholds, prioritization and exception-management procedures.
Otherwise, auditors drown in false positives.
The goal should be:
Data
→ Automated Test
→ Exception
→ Risk Scoring
→ Prioritization
→ Investigation
→ Disposition
→ Trend Analysis
The best continuous audit test isn't necessarily the one that identifies the most exceptions.
It is the one that identifies the most meaningful exceptions with an acceptable false-positive rate.
AI Makes Continuous Auditing Even More Interesting
Artificial intelligence adds another dimension.
Traditional continuous auditing often depends upon predefined rules:
Flag every invoice over $50,000.
Flag every duplicate invoice number.
Flag every weekend journal entry.
Those remain useful.
AI and more advanced analytics potentially allow auditors to ask a different question:
“Which transactions don't behave like the rest of the population?”
That can help identify patterns the auditor didn't explicitly program beforehand.
AI could assist auditors in:
Anomaly detection
Pattern recognition
Transaction classification
Exception prioritization
Text analysis
Trend identification
Fraud-risk scoring
But the same rule applies here as elsewhere in auditing:
AI identifies something unusual. The auditor determines what it means.
Dashboards Can Improve Audit Committee Reporting
Continuous auditing can also improve governance reporting.
Instead of telling the Audit Committee:
“We completed 14 audits this quarter.”
Internal Audit can potentially report:
12.4 million transactions monitored
2,187 exceptions generated
146 high-risk exceptions investigated
17 control failures confirmed
4 systemic issues identified
3 corrective actions overdue
Fraud indicators increased 18%
That changes the discussion.
The Audit Committee begins seeing the organization's control environment dynamically, rather than receiving only individual audit reports.
Continuous Auditing Can Improve Audit Efficiency
CCS specifically identifies improving the cost-effectiveness of the Internal Audit function as a learning objective.
That doesn't necessarily mean doing fewer audits.
It can mean deploying audit resources more intelligently.
Instead of spending hundreds of hours manually searching for exceptions, technology identifies the transactions most deserving of professional attention.
Think of the progression:
Old Model
Auditor searches for exceptions.
Better Model
Technology searches for exceptions.
Auditor investigates and evaluates the exceptions.
That places human judgment where it adds the most value.
Build or Buy?
Organizations interested in continuous auditing eventually face a technology decision.
CCS devotes an entire section to evaluating the build-versus-buy decision and discusses general audit software and automated tools including IDEA, ACL and Approva.
The right answer depends upon:
Data availability
IT capabilities
Audit department size
Transaction volume
Complexity
Budget
Integration requirements
Maintenance capabilities
Required analytics
Technology should support the audit methodology.
The methodology should not be built around whatever software happened to be purchased.
Culture May Be Harder Than Technology
CCS appropriately includes culture and politics among the challenges involved in designing a continuous auditing program.
That issue should not be underestimated.
Management may hear:
“Internal Audit wants continuous access to our data.”
and interpret it as:
“Internal Audit wants to watch everything we do.”
Process owners may worry that every exception will become an audit finding.
IT may worry about data access and system performance.
Internal Audit itself may resist changing familiar methodologies.
Successful implementation therefore requires explaining what continuous auditing is intended to accomplish:
Earlier identification of meaningful risk and control problems.
It should not become organizational surveillance or a gigantic exception-generation machine.
Start Small
An Internal Audit department does not need to begin by continuously auditing the entire enterprise.
Choose one high-volume, data-rich, risk-significant process.
For example:
Accounts Payable
Select perhaps five automated tests:
Duplicate payments
Payments above defined thresholds
Vendor bank changes
Transactions below approval thresholds
Dormant vendor activity
Run them.
Evaluate the exceptions.
Improve the algorithms.
Reduce false positives.
Measure the results.
Then expand.
That is much more practical than trying to build an enterprise-wide continuous auditing environment on day one.
The Continuous Auditing Maturity Model
A useful way to think about development is:
Level 1 — Periodic Auditing
Traditional sampling and point-in-time audits.
Level 2 — Data Analytics
Auditors analyze larger populations during individual engagements.
Level 3 — Repeatable Analytics
Standardized tests are rerun periodically.
Level 4 — Continuous Auditing
Automated testing regularly identifies exceptions.
Level 5 — Continuous Assurance
Audit analytics, management monitoring, risk information and governance reporting operate within an integrated assurance environment.
Organizations do not need to jump immediately from Level 1 to Level 5.
The objective should be progressive maturity.
Two Opportunities to Attend in 2026
CCS's Continuous Auditing and Monitoring program is a four-hour Group Internet-Based seminar providing 4 CPE credits in Auditing. The course is Basic level, requires no prerequisites or advance preparation, and runs from 10:00 a.m. to 2:30 p.m. Central Time.
Friday, August 28, 2026
The August session provides an opportunity to begin considering continuous auditing before Internal Audit departments finalize their 2027 risk assessments and audit plans.
Friday, October 30, 2026
The October session is particularly well positioned for organizations developing 2027 Internal Audit plans, SOX testing strategies and technology investments.
The Bottom Line: Audit the Risk When It Matters
Finding a control failure nine months after it occurred has value.
Finding it nine minutes after it occurred can have considerably more.
That is the strategic promise of continuous auditing.
The progression is:
Periodic Sampling
→ Data Analytics
→ Automated Testing
→ Continuous Auditing
→ Exception Management
→ Earlier Corrective Action
→ Continuous Assurance
The objective isn't to eliminate professional judgment.
It is the opposite.
Use technology to perform the repetitive searching so auditors can spend more time exercising professional judgment.
CCS's Continuous Auditing and Monitoring webinar on August 28 and October 30, 2026 provides four CPE hours focused on helping auditors understand how to make that transition.
Comments