Assurance Without Limits: Rethinking QAIP - 7 October

Register Now →
Risk, Audit & Compliance

Continuous Controls Monitoring

Test the whole population. Show what was not tested, and why.

SustainGRC provides full-population control testing across finance and operations with itemised exclusion sets — making every coverage claim checkable.

Evidenced coverage94.4%
Tested
Excluded, with a reason

Declared coverage is not evidenced coverage

Every vendor claims the full population. Almost none publishes what it missed.

Declared

100%

What the rule set asserts. Unfalsifiable.

Evidenced

94.4%

What the run tested. The 5.6% is itemised by cause.

Connector timeout. Period not closed. Company code unreadable. Every gap has a reason on the record.

Finance and operations, one evidence record

Most of this market monitors cloud configuration. We test the controls your business runs on.

Financial

Duplicate invoices, vendor bank changes, order splitting, manual journals.

Environmental

Tonnage reconciled to billing. Emissions monitor availability.

Health & safety

Permits closed without an isolation certificate.

Asset integrity

Overdue critical maintenance. Expired calibration behind a reported figure.

Workforce

Driving hours against telematics and rostered shifts.

Access & IT

Segregation of duties across vendor creation and payment.

Runs on the system you already have

Your audit system keeps its control library, workflow and remediation. We read it, write findings back as drafts, and take closure as an event.

Diligent OneTeamMate+AuditBoardEnterprise ITSMSustainGRC

Rules execute inside the source. Only the exception crosses the boundary — we never hold a copy of your ledger.

The agent writes the tests

Authoring several hundred control tests by hand is the work that sinks monitoring programmes.

Writes the rule

Control text becomes an executable test against your own schema.

Finds the data

Proposes which source fields hold what the rule needs.

Groups the noise

Four thousand exceptions become a handful of root causes.

Drafts the finding

In the structure your audit function already writes to.

Every proposal arrives with its evidence and a person confirms it — which is what puts the output in an audit file rather than only in a demo.

One rule, every framework it satisfies

Segregation of duties evidences ISO 27001, SOX ITGC, DORA and the IIA Standards from a single run.

Common Questions

What is continuous controls monitoring?

Continuous controls monitoring (CCM) is the automated, ongoing testing of whether internal controls are operating effectively, rather than sample-based testing once or twice a year. Rules run against the whole population of transactions or records on a defined cycle and raise an exception where a control has failed.

What is the difference between declared and evidenced coverage?

Declared coverage is what a rule set asserts it reaches. Evidenced coverage is what a run actually tested. The difference is the exclusion set: records missed because a connector timed out, a period was not closed, a company code was unreadable, or the rule's own filter removed them. A coverage claim without an exclusion set cannot be checked.

What does the AI do?

It writes the tests. Authoring several hundred control tests by hand is the work that sinks monitoring programmes, so the agent turns a written control description into an executable specification against your own schema, and proposes which source fields hold the data it needs. It then collapses thousands of exceptions into a handful of root causes and drafts the finding in the structure your audit function already writes to. Every proposal carries its evidence and a person confirms it, which is what makes the output usable in an audit file rather than only impressive in a demo.

How quickly can we be monitoring?

Bring the rules you already have. A test sheet, an analytics script or an export from an incumbent tool imports into the structured specification, and the agent drafts new rules from your written control descriptions. The first cycle runs on the sources already connected, and each rule states its own coverage from its first run.

Does CCM only apply to IT and security controls?

No. The same evidence record serves financial, environmental, health and safety, asset integrity, workforce and access controls. A weighbridge ticket, a permit to work, a calibration certificate and a journal entry are all populations that can be tested continuously.

Does it replace our audit management system?

No. It runs on top of it. The host keeps its control library, its workflow and its remediation. We read the library, write findings back as drafts, and receive closure as an event.

How does it detect anomalies rather than rule breaks?

A baseline rule derives its limit from the population's own history instead of a fixed threshold. It stays reproducible: same window, same data, same result, and the computed baseline is written into the run record so a re-performance produces identical figures. Outliers are recorded as observations rather than exceptions, because nothing was breached and there is no criterion to cite.


Ask to see the 5.6%

Forty-five minutes, on your control library and your sources.