← Back to Blog

From Annual Sampling to Continuous Control Monitoring

Testing a sample once a year tells the audit committee what a control looked like months ago. Continuous monitoring on the full population tells them what it looks like now — and flags the exception days after it happens.

The annual internal audit cycle was built around a constraint that no longer applies: the cost of testing. When every test meant an auditor pulling documents by hand, sampling a few dozen items per control was the only feasible approach. Once the data pipeline exists, running a rule against every transaction is cheap and repeatable — which is what makes continuous monitoring possible.

The limits of the annual sample

A sample of 40 items per control, tested once, produces a point estimate of the exception rate as of the moment the sample was drawn. It says little about the eleven months between engagements, and a deliberate or rare issue is likely to fall outside it. The findings also land late: by the time the report is written, the exception is often months old and the money is gone.

Step one: a repeatable data pipeline

Continuous monitoring depends on getting clean data on a schedule. The model is the same every time:

  • Identify the systems of record for the process — ERP, HRMS, banking, procurement, ITSM.
  • Define the exact extract: the fields, the period, the format, and the user IDs, timestamps, and change logs — not just current values.
  • Issue a standard data request so process owners know precisely what to provide.
  • Validate completeness by reconciling the extract to a control total — a general-ledger balance, a headcount, a payment-run total. An unreconciled extract is not usable.
  • Set a refresh cadence for each feed.

Step two: choose the checks and the cadence

Not every control needs to run daily. A practical starting set, with a sensible cadence:

  • Access and segregation of duties — daily. Users with conflicting roles, terminated users retaining access, privileged accounts not reviewed.
  • Procure-to-pay — weekly. Duplicate payments, split purchase orders, vendor bank details matching employees, invoices booked before the purchase order.
  • Payroll — each run. Payments after a termination date, one bank account paying several employees, overtime outliers by approver.
  • Master data — on change. Vendor and customer bank-detail changes, especially values that later revert.
  • Journal entries — monthly. Manual and top-side entries near period end, round numbers, rare account pairings (the SA 240 management-override criteria).

A monitoring programme lives or dies on follow-up. Every exception needs an owner, a due date, and a recorded resolution. Alerts that no one dispositions erode the whole programme within a quarter.

Step three: reporting and quality

Findings are still rated by risk, tied to a root cause, and turned into agreed management actions tracked to closure — the monitoring feed just makes the evidence current and complete. Every exception links to its source record, and every analysis is reproducible from the source data and the exact rule that produced it, which is what an external quality assessment under a QAIP will look for.

Where AI fits

AI runs the rules across the full population on the cadence you set, alerts on new exceptions and on trend, and drafts the working papers into your templates for reviewer sign-off. The auditor still dispositions every exception and forms the opinion.

Get the Internal Audit Readiness Guide

Risk-based planning, a five-step data-acquisition model, full-population test design by process, continuous control monitoring, and quality-assessment (QAIP) readiness.

Get the guide →