Skip to content

Continuous Assurance

Where to find it: Controls & Assurance, then Continuous Assurance (/assurance).

Continuous Assurance is the layer that sits between raw evidence and compliance conclusions. It turns observations into assessments, deterministically, at whatever cadence the underlying evidence supports.


The problem it solves

In a conventional compliance programme, control effectiveness is established once or twice a year by a testing cycle. Between cycles, the organisation reports the position established at the last test.

That is a reasonable approach for a control tested by sampling a process. It is a poor one for a control that is a configuration setting across a thousand systems, where the state can change on any Tuesday.

Continuous Assurance evaluates those controls at the cadence their evidence supports, and reports honestly when the evidence itself has lapsed.


The four doctrine rules

These are enforced by the evaluation engine, not left to configuration.

Rule A — fresh evidence is not a conclusion

A fresh evidence assertion existing does not by itself cause evidence coverage to be 100%, control effectiveness to be effective, requirement satisfaction to be satisfied, or compliance to be compliant.

Rule B — coverage is not effectiveness

Evidence coverage of 100% does not cause control effectiveness to be effective, because the observed telemetry may contain failing checks. It does not cause requirement satisfaction either.

Rule C — effectiveness is not satisfaction

Control effectiveness of effective does not cause requirement satisfaction to be satisfied, and does not cause compliance to be compliant. Requirement satisfaction is determined at the requirement level.

Rule D — mandatory failure gating

One critical or mandatory failing indicator cannot be hidden by averaging many passing non-critical indicators. If a mandatory indicator fails, control effectiveness is ineffective regardless of everything else.


The five dimensions

Continuous Assurance keeps five things separate that are usually collapsed into one:

DimensionQuestionOwned by
1. Evidence statusIs the telemetry present and current?Continuous Assurance
2. Evidence coverageWhat proportion of the population is covered?Continuous Assurance
3. Control effectivenessIs the control operating?Continuous Assurance
4. Requirement satisfactionIs the obligation met?Requirement Assurance
5. Review stateHas a person signed it?Governance

Continuous Assurance deliberately leaves dimension 4 untouched. A control-level layer has no business concluding things about obligations.


Deterministic, never AI

No AI model determines a pass, a fail or an effectiveness value

Every evaluation in this layer is arithmetic against a stated rule and a stated denominator. Given the same assertions and the same rule, the result is identical every time it is computed, including retrospectively.

That reproducibility is the point. An assessor can recompute it.


Population and qualitative scopes

Qualitative mode exists so that governance obligations — an annual board review, a policy approval — can be assessed without inventing a population that does not exist.


Explainability

Every evaluation carries a deterministic explanation naming the indicator, the timestamps, the expected denominator against observed and fresh counts, the rule applied, the pass, fail and stale breakdown, and any safely captured error.

This is written for a reader who has never used the platform.


Historical reproducibility

Every evaluation can be reproduced as of any past instant, resolving the scope membership effective then and the assertions observed by then.

Combined with immutable indicator results, this means a compliance position from any past date can be recomputed and shown to have followed from the facts available at that time.


What works without Continuous Assurance

The Continuous Assurance entitlement is separately licensed. With it off, the following continue to work in full:

What Continuous Assurance adds is external connections, automated collectors, indicators and automated recalculation.

Assurance without automation is still assurance

A tenant with the entitlement off runs a complete governed compliance programme on manual evidence and periodic assessment. Continuous Assurance raises the cadence and the coverage; it is not a prerequisite for truthfulness.


Permissions

ActionPermissionEntitlement
View control and requirement assurance postureassurance.readcompliance_core
Record a governed requirement assurance reviewassurance.reviewcompliance_core
Trigger automated recalculation across controlsassurance.evaluatecontinuous_assurance
View or manage indicatorsindicator.read / indicator.managecontinuous_assurance
Trigger indicator evaluationindicator.evaluatecontinuous_assurance

Example

A bank enables Continuous Assurance and instruments 62 of its 287 organisational controls.

What gets instrumented: configuration controls with an authoritative system of record — MFA enforcement, disk encryption, backup completion, logging coverage, cloud configuration baselines, patch state, certificate expiry.

What does not: process controls where the evidence is a human judgement — supplier due diligence, conflict-of-interest declarations, board oversight, incident escalation decisions. These stay on periodic manual assessment, which is the right instrument for them.

Six months later:

MetricValue
Instrumented controls62
Active indicators148
Assertions produced monthly~2.1 million
Controls whose effectiveness changed between quarterly cycles19

That last number is the return. Nineteen controls degraded and recovered inside a quarter — invisible to a quarterly testing cycle, and eleven of them were remediated within a week of the indicator failing.

The remaining 225 controls are no worse governed than before. They are assessed periodically, by people, which is what they need.


Troubleshooting

"Everything shows not_assessed." No indicators are defined, or none have been evaluated. Effectiveness requires an evaluated rule.

"Continuous Assurance is not in the menu." Requires the continuous_assurance entitlement and indicator.read.

"Turning Continuous Assurance off broke my compliance position." It should not. Core compliance, manual evidence and requirement assurance are unaffected. Automated indicator results stop refreshing and become stale, which correctly moves affected effectiveness to not_assessed rather than leaving a stale green.

"Results look wrong after a scope change." Scope membership is effective-dated. Check membership as of the evaluation instant.


OrviQ Enterprise Governance, Risk & Compliance Platform