top of page
Search

Continuous Auditing and Monitoring: Why Internal Audit Should Stop Waiting for the Next Audit

Continuous Auditing and Monitoring — August 28 and October 30, 2026


Traditional Internal Auditing is largely periodic.


An audit is scheduled. The auditor selects a sample. Transactions are tested. Exceptions are identified. A report is issued.


Then the auditor may not examine that process again for another year—or perhaps three years.


Meanwhile, the business keeps operating.


Transactions continue.


Controls fail.


Employees change.


System access changes.


Vendors are added.


Payments are processed.


Fraud can occur.


Technology gives Internal Audit another option:

Instead of periodically asking what happened, continuously analyze what is happening.

That is the central concept behind Corporate Compliance Seminars' Continuous Auditing and Monitoring, a four-hour, 4-CPE Auditing webinar focused on designing and implementing continuous auditing programs, automated audit tools, fraud detection, SOX/ICFR monitoring and IT controls.


Upcoming sessions are:

  • Friday, August 28, 2026

  • Friday, October 30, 2026



What Is Continuous Auditing?

Continuous Auditing (CA) uses technology, data analytics and automated audit procedures to evaluate transactions, controls and risks on a much more frequent basis than traditional periodic auditing.


Instead of examining 50 transactions six months after they occurred, Internal Audit may be able to analyze an entire population every day, week or month.


CCS's program specifically examines the definitions of Continuous Auditing, Continuous Monitoring and Continuous Assurance, as well as what the course describes as the “Inverse Relationship.” 


The difference is substantial.


Traditional Audit

Transaction Occurs

→ Months Pass

→ Audit Begins

→ Sample Selected

→ Exception Identified

→ Finding Reported


Continuous Auditing

Transaction Occurs

→ Automated Test

→ Exception Identified

→ Auditor Investigates

→ Corrective Action


The objective isn't necessarily to audit everything every second.


It is to reduce the time between the occurrence of a significant control exception and its identification.


Continuous Auditing and Continuous Monitoring Are Not the Same Thing

This distinction matters.


Continuous Monitoring is fundamentally a management responsibility. Management monitors operations and controls to determine whether processes are functioning properly.

Continuous Auditing is an assurance activity performed by Internal Audit to independently evaluate risks, controls and transactions.


They can use similar technologies.


They can analyze the same data.


But their responsibilities are different.


Management owns the controls.

Internal Audit independently evaluates them.

An organization should therefore avoid turning Internal Audit's continuous auditing system into a substitute for management's monitoring responsibilities.


Sampling Has a Fundamental Limitation

Suppose an organization processes 500,000 vendor payments each year.


Internal Audit selects 60.


All 60 are properly authorized.


That's useful audit evidence.


But what about the other 499,940 transactions?


Traditional sampling accepts this limitation because examining every transaction manually would be economically impossible.


Technology changes that equation.


Continuous auditing can potentially analyze the entire population for specific characteristics.


Instead of asking:

“Were the 60 transactions we selected properly approved?”

Internal Audit can ask:

“Identify every transaction in the population that appears to have bypassed the required approval.”

That is a fundamentally different audit capability.


CCS describes continuous auditing as enabling analysis of large transaction populations and reducing reliance on traditional sample-based periodic reviews.


Start With Risk—Not With the Software

A common mistake is purchasing an audit analytics platform and then asking:

“What should we do with it?”

Reverse the process.


Start with the business objective.


Then identify the risk.


Then determine the control.


Then determine what evidence exists.


Only then decide whether continuous auditing can improve assurance.


The methodology becomes:


Business Objective

Risk

Control

Data

Audit Test

Exception

Investigation

Conclusion

Corrective Action


CCS's implementation methodology follows a similar progression: define objectives, identify risks, controls and audit tests, establish data requirements, pilot the system, refine it, and manage and report the results.


What Could Internal Audit Continuously Test?

The possibilities are extensive.


Consider procure-to-pay.


Internal Audit could identify:

  • Duplicate invoices

  • Duplicate payments

  • Payments without purchase orders

  • Transactions immediately below approval thresholds

  • New vendors receiving unusually large payments

  • Vendor bank-account changes

  • Dormant vendors suddenly reactivated

  • Weekend transactions

  • Unusual payment patterns


Now consider user access:

  • Terminated employees with active accounts

  • Dormant accounts

  • Privileged users

  • Segregation-of-duties conflicts

  • Unexpected administrator access

  • Or financial reporting:

  • Unusual journal entries

  • Late-period adjustments

  • Round-dollar entries

  • Manual entries to sensitive accounts

  • Entries posted by unusual users


Continuous auditing turns these from occasional audit procedures into repeatable tests.


Fraud Detection Is a Natural Application

Fraud frequently hides in large transaction populations.


A fraudulent payment may look perfectly ordinary when viewed individually.


Its significance may become visible only when compared with other transactions.


For example:

Why does this employee share an address with a vendor?
Why are 27 invoices immediately below the approval threshold?
Why did this dormant vendor suddenly receive $300,000?
Why are payments repeatedly occurring on weekends?
Why does one bank account belong to multiple vendors?

CCS specifically includes occupational fraud, financial transactions, excluded-party listings and disbursement fraud in its continuous auditing curriculum.


The system doesn't necessarily conclude that fraud occurred.


It tells Internal Audit:

“This deserves investigation.”

Continuous Auditing Can Strengthen SOX and ICFR

Continuous auditing can be particularly valuable for organizations subject to Sarbanes-Oxley and ICFR requirements.


CCS devotes a section of the program specifically to applying continuous auditing to SOX compliance and the SEC's focus on ICFR.


Consider a key control that operates thousands of times during the year.


Traditional testing might examine a relatively small sample.


Continuous techniques may enable management or Internal Audit to identify exceptions across a much larger population.


That can help answer:

Is the control continuing to operate as designed between formal testing periods?

This is particularly valuable for high-volume automated processes.


IT Controls Are Another Strong Candidate

CCS also addresses continuous auditing for information technology, including:

  • Access Security

  • Development and Change

  • Implementation

  • IT Operations

  • Backup

  • Restoration and Recovery

  • IT Vendor Management.


Think about user access.


A conventional audit might review user access annually.


But employees don't leave the organization annually.


They leave every day.


Employees transfer departments.


Contractors finish assignments.


Administrators receive elevated privileges.


New accounts are created.


That raises an obvious question:

Why wait until the annual audit to identify inappropriate access?

Some risks are inherently better suited to continuous monitoring.


Continuous Auditing Does Not Mean Continuous Investigation

There is a practical problem.


Suppose Internal Audit builds an automated test and it generates:

  • 8,427 exceptions.


Congratulations.


You have just created another problem.


A continuous auditing system needs thresholds, prioritization and exception-management procedures.


Otherwise, auditors drown in false positives.


The goal should be:


Data

Automated Test

Exception

Risk Scoring

Prioritization

Investigation

Disposition

Trend Analysis


The best continuous audit test isn't necessarily the one that identifies the most exceptions.


It is the one that identifies the most meaningful exceptions with an acceptable false-positive rate.


AI Makes Continuous Auditing Even More Interesting

Artificial intelligence adds another dimension.


Traditional continuous auditing often depends upon predefined rules:

Flag every invoice over $50,000.
Flag every duplicate invoice number.
Flag every weekend journal entry.

Those remain useful.


AI and more advanced analytics potentially allow auditors to ask a different question:

“Which transactions don't behave like the rest of the population?”

That can help identify patterns the auditor didn't explicitly program beforehand.


AI could assist auditors in:

  • Anomaly detection

  • Pattern recognition

  • Transaction classification

  • Exception prioritization

  • Text analysis

  • Trend identification

  • Fraud-risk scoring


But the same rule applies here as elsewhere in auditing:

AI identifies something unusual. The auditor determines what it means.

Dashboards Can Improve Audit Committee Reporting

Continuous auditing can also improve governance reporting.


Instead of telling the Audit Committee:

“We completed 14 audits this quarter.”

Internal Audit can potentially report:

  • 12.4 million transactions monitored

  • 2,187 exceptions generated

  • 146 high-risk exceptions investigated

  • 17 control failures confirmed

  • 4 systemic issues identified

  • 3 corrective actions overdue

  • Fraud indicators increased 18%


That changes the discussion.


The Audit Committee begins seeing the organization's control environment dynamically, rather than receiving only individual audit reports.


Continuous Auditing Can Improve Audit Efficiency

CCS specifically identifies improving the cost-effectiveness of the Internal Audit function as a learning objective.


That doesn't necessarily mean doing fewer audits.


It can mean deploying audit resources more intelligently.


Instead of spending hundreds of hours manually searching for exceptions, technology identifies the transactions most deserving of professional attention.


Think of the progression:

  • Old Model


Auditor searches for exceptions.

  • Better Model


Technology searches for exceptions.


Auditor investigates and evaluates the exceptions.


That places human judgment where it adds the most value.


Build or Buy?

Organizations interested in continuous auditing eventually face a technology decision.


CCS devotes an entire section to evaluating the build-versus-buy decision and discusses general audit software and automated tools including IDEA, ACL and Approva.


The right answer depends upon:

  • Data availability

  • IT capabilities

  • Audit department size

  • Transaction volume

  • Complexity

  • Budget

  • Integration requirements

  • Maintenance capabilities

  • Required analytics


Technology should support the audit methodology.


The methodology should not be built around whatever software happened to be purchased.


Culture May Be Harder Than Technology

CCS appropriately includes culture and politics among the challenges involved in designing a continuous auditing program.


That issue should not be underestimated.


Management may hear:

“Internal Audit wants continuous access to our data.”

and interpret it as:

“Internal Audit wants to watch everything we do.”

Process owners may worry that every exception will become an audit finding.


IT may worry about data access and system performance.


Internal Audit itself may resist changing familiar methodologies.


Successful implementation therefore requires explaining what continuous auditing is intended to accomplish:

Earlier identification of meaningful risk and control problems.

It should not become organizational surveillance or a gigantic exception-generation machine.


Start Small

An Internal Audit department does not need to begin by continuously auditing the entire enterprise.


Choose one high-volume, data-rich, risk-significant process.


For example:


Accounts Payable

Select perhaps five automated tests:

  • Duplicate payments

  • Payments above defined thresholds

  • Vendor bank changes

  • Transactions below approval thresholds

  • Dormant vendor activity

Run them.


Evaluate the exceptions.


Improve the algorithms.


Reduce false positives.


Measure the results.


Then expand.


That is much more practical than trying to build an enterprise-wide continuous auditing environment on day one.


The Continuous Auditing Maturity Model

A useful way to think about development is:


Level 1 — Periodic Auditing

Traditional sampling and point-in-time audits.

Level 2 — Data Analytics

Auditors analyze larger populations during individual engagements.

Level 3 — Repeatable Analytics

Standardized tests are rerun periodically.

Level 4 — Continuous Auditing

Automated testing regularly identifies exceptions.

Level 5 — Continuous Assurance

Audit analytics, management monitoring, risk information and governance reporting operate within an integrated assurance environment.


Organizations do not need to jump immediately from Level 1 to Level 5.


The objective should be progressive maturity.


Two Opportunities to Attend in 2026

CCS's Continuous Auditing and Monitoring program is a four-hour Group Internet-Based seminar providing 4 CPE credits in Auditing. The course is Basic level, requires no prerequisites or advance preparation, and runs from 10:00 a.m. to 2:30 p.m. Central Time.


Friday, August 28, 2026

The August session provides an opportunity to begin considering continuous auditing before Internal Audit departments finalize their 2027 risk assessments and audit plans.


Friday, October 30, 2026

The October session is particularly well positioned for organizations developing 2027 Internal Audit plans, SOX testing strategies and technology investments.


The Bottom Line: Audit the Risk When It Matters

Finding a control failure nine months after it occurred has value.


Finding it nine minutes after it occurred can have considerably more.


That is the strategic promise of continuous auditing.


The progression is:


Periodic Sampling

Data Analytics

Automated Testing

Continuous Auditing

Exception Management

Earlier Corrective Action

Continuous Assurance


The objective isn't to eliminate professional judgment.


It is the opposite.

Use technology to perform the repetitive searching so auditors can spend more time exercising professional judgment.

CCS's Continuous Auditing and Monitoring webinar on August 28 and October 30, 2026 provides four CPE hours focused on helping auditors understand how to make that transition.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page