Appearance
Continuous Assurance
Where to find it: Controls & Assurance, then Continuous Assurance (/assurance).
Continuous Assurance is the layer that sits between raw evidence and compliance conclusions. It turns observations into assessments, deterministically, at whatever cadence the underlying evidence supports.
The problem it solves
In a conventional compliance programme, control effectiveness is established once or twice a year by a testing cycle. Between cycles, the organisation reports the position established at the last test.
That is a reasonable approach for a control tested by sampling a process. It is a poor one for a control that is a configuration setting across a thousand systems, where the state can change on any Tuesday.
Continuous Assurance evaluates those controls at the cadence their evidence supports, and reports honestly when the evidence itself has lapsed.
The four doctrine rules
These are enforced by the evaluation engine, not left to configuration.
Rule A — fresh evidence is not a conclusion
A fresh evidence assertion existing does not by itself cause evidence coverage to be 100%, control effectiveness to be effective, requirement satisfaction to be satisfied, or compliance to be compliant.
Rule B — coverage is not effectiveness
Evidence coverage of 100% does not cause control effectiveness to be effective, because the observed telemetry may contain failing checks. It does not cause requirement satisfaction either.
Rule C — effectiveness is not satisfaction
Control effectiveness of effective does not cause requirement satisfaction to be satisfied, and does not cause compliance to be compliant. Requirement satisfaction is determined at the requirement level.
Rule D — mandatory failure gating
One critical or mandatory failing indicator cannot be hidden by averaging many passing non-critical indicators. If a mandatory indicator fails, control effectiveness is ineffective regardless of everything else.
The five dimensions
Continuous Assurance keeps five things separate that are usually collapsed into one:
| Dimension | Question | Owned by |
|---|---|---|
| 1. Evidence status | Is the telemetry present and current? | Continuous Assurance |
| 2. Evidence coverage | What proportion of the population is covered? | Continuous Assurance |
| 3. Control effectiveness | Is the control operating? | Continuous Assurance |
| 4. Requirement satisfaction | Is the obligation met? | Requirement Assurance |
| 5. Review state | Has a person signed it? | Governance |
Continuous Assurance deliberately leaves dimension 4 untouched. A control-level layer has no business concluding things about obligations.
Deterministic, never AI
No AI model determines a pass, a fail or an effectiveness value
Every evaluation in this layer is arithmetic against a stated rule and a stated denominator. Given the same assertions and the same rule, the result is identical every time it is computed, including retrospectively.
That reproducibility is the point. An assessor can recompute it.
Population and qualitative scopes
Qualitative mode exists so that governance obligations — an annual board review, a policy approval — can be assessed without inventing a population that does not exist.
Explainability
Every evaluation carries a deterministic explanation naming the indicator, the timestamps, the expected denominator against observed and fresh counts, the rule applied, the pass, fail and stale breakdown, and any safely captured error.
This is written for a reader who has never used the platform.
Historical reproducibility
Every evaluation can be reproduced as of any past instant, resolving the scope membership effective then and the assertions observed by then.
Combined with immutable indicator results, this means a compliance position from any past date can be recomputed and shown to have followed from the facts available at that time.
What works without Continuous Assurance
The Continuous Assurance entitlement is separately licensed. With it off, the following continue to work in full:
- The Control Register
- The Control Crosswalk
- Manual evidence and evidence links
- Evidence assertions recorded manually or as attestations
- Manual control assessments
- Requirement Assurance — part of core compliance
- Expected evidence and freshness — deterministic and AI-independent
What Continuous Assurance adds is external connections, automated collectors, indicators and automated recalculation.
Assurance without automation is still assurance
A tenant with the entitlement off runs a complete governed compliance programme on manual evidence and periodic assessment. Continuous Assurance raises the cadence and the coverage; it is not a prerequisite for truthfulness.
Permissions
| Action | Permission | Entitlement |
|---|---|---|
| View control and requirement assurance posture | assurance.read | compliance_core |
| Record a governed requirement assurance review | assurance.review | compliance_core |
| Trigger automated recalculation across controls | assurance.evaluate | continuous_assurance |
| View or manage indicators | indicator.read / indicator.manage | continuous_assurance |
| Trigger indicator evaluation | indicator.evaluate | continuous_assurance |
Example
A bank enables Continuous Assurance and instruments 62 of its 287 organisational controls.
What gets instrumented: configuration controls with an authoritative system of record — MFA enforcement, disk encryption, backup completion, logging coverage, cloud configuration baselines, patch state, certificate expiry.
What does not: process controls where the evidence is a human judgement — supplier due diligence, conflict-of-interest declarations, board oversight, incident escalation decisions. These stay on periodic manual assessment, which is the right instrument for them.
Six months later:
| Metric | Value |
|---|---|
| Instrumented controls | 62 |
| Active indicators | 148 |
| Assertions produced monthly | ~2.1 million |
| Controls whose effectiveness changed between quarterly cycles | 19 |
That last number is the return. Nineteen controls degraded and recovered inside a quarter — invisible to a quarterly testing cycle, and eleven of them were remediated within a week of the indicator failing.
The remaining 225 controls are no worse governed than before. They are assessed periodically, by people, which is what they need.
Troubleshooting
"Everything shows not_assessed." No indicators are defined, or none have been evaluated. Effectiveness requires an evaluated rule.
"Continuous Assurance is not in the menu." Requires the continuous_assurance entitlement and indicator.read.
"Turning Continuous Assurance off broke my compliance position." It should not. Core compliance, manual evidence and requirement assurance are unaffected. Automated indicator results stop refreshing and become stale, which correctly moves affected effectiveness to not_assessed rather than leaving a stale green.
"Results look wrong after a scope change." Scope membership is effective-dated. Check membership as of the evaluation instant.