The difference between a compliance audit and security effectiveness monitoring
A compliance audit and continuous security monitoring answer different questions, and GDPR, NIS2, and DORA now require both. Here is the difference and why it matters.
Compliance audits and continuous security monitoring are often treated as the same thing by organisations that rely on one to satisfy the other. A board receives an annual audit report and concludes that the security question has been answered for the year. A compliance officer points to the audit finding as evidence of control effectiveness. A CISO cites the audit as proof that things are working.
These are different activities. They answer different questions. And the regulatory frameworks now in force — GDPR, NIS2, DORA — require both.
What an audit answers
An audit answers the question: “What was the state of this system at this point in time?”
An audit is a snapshot. It captures what existed when the auditor looked — the configurations in place, the policies on file, the access controls as they were set, the logs as they appeared on the day the auditor reviewed them. It is bounded by time and by the auditor’s scope. Whatever the auditor examines is captured. Whatever falls outside the scope is not.
This is not a weakness of auditing. It is the nature of what an audit is. No auditor claims to capture the complete state of an environment. The value of an audit is that it provides independent, third-party verification of what was true on a specific date. That verification has real regulatory and legal weight.
But the snapshot is precisely that — a snapshot. What it shows you is what was true when the picture was taken.
What audits cannot do
Audits cannot capture ephemeral state data. Modern IT environments — Microsoft 365, Google Workspace, cloud infrastructure broadly — emit information about their current state continuously. Today’s configuration, today’s access patterns, today’s authentication events. That information describes the environment as it exists right now. Without a system pulling and storing that data continuously, the information is gone by tomorrow.
An audit conducted in September cannot tell you what the environment looked like in June. The auditor was not there in June. The data from June was not preserved. Whatever was true in June — whether MFA was enforced, whether a specific mailbox had forwarding rules configured, whether a conditional access policy was active — is knowable only if something was recording it at the time.
This creates a structural gap. The audit tells you what was true on audit day. It cannot tell you what was true on any other day. And it cannot tell you whether the state that existed on audit day was typical or anomalous — whether the auditor saw the system in its normal operating condition or in a state that happened to exist during the audit window.
What continuous monitoring answers
Continuous monitoring answers a fundamentally different question: “What has been true over time, and what changed?”
This is a question about trends, not snapshots. It captures the state of the environment on an ongoing basis — daily, weekly, whatever the cadence — and stores that data so it can be compared across periods. When a control is implemented, a training is conducted, or a policy is changed, the monitoring data shows what the relevant indicators looked like before the intervention and what they looked like after.
That before-and-after comparison is the core of effectiveness evidence. It does not just show that a control exists. It shows what the control did. And because the data is continuous, it can show whether the effect persisted — whether the improvement held over weeks and months, or whether it reverted after the initial period.
This is the kind of evidence that the effectiveness requirements in GDPR Art. 32(1)(d), NIS2 Art. 21(2)(f), and DORA Art. 13(4) are designed to produce. Not proof that a control was in place on audit day. Proof that a control had a measurable, sustained effect on the thing it was designed to address.
Where audits remain essential
This is not an argument against audits. Audits are a regulatory requirement under all three frameworks. They provide independent verification. They carry legal weight. They impose discipline on organisations that might otherwise avoid external scrutiny. No serious compliance programme operates without them.
The argument is that audits alone are insufficient to meet the effectiveness evidence requirements that these frameworks impose. An audit verifies existence at a point in time. The regulation requires evidence of effectiveness over time. These are two different obligations, and one cannot substitute for the other.
An organisation that relies solely on its annual audit to demonstrate effectiveness has a gap between audits — typically eleven months — during which it has no evidence of what its controls were doing. If an incident occurs during that gap, the organisation cannot show what state its environment was in, whether its controls were functioning, or whether the measures it had in place were having the intended effect.
The layer audits cannot provide
Continuous monitoring is the layer that fills the gap between audits. It does not replace the audit. It provides the evidence substrate that the audit alone cannot generate — the time-series data, the before-and-after comparisons, the trend analysis that turns “we have controls” into “here is what our controls did over the past twelve months.”
The question most organisations face is not “do you get audited?” Most do. The question is what happens between audits — and whether you can show it.
For the full regulatory argument and enforcement precedents, read the white paper: Measuring Security Control Effectiveness: From Attestation to Evidence
Ready to see your employees' security behaviors?
Connect your Microsoft 365 and see months of behavioral data in 15 minutes. Free 30-day trial — no credit card, no sales call.
Start Free Trial