Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Writing

The Audit Passed in March. Is It Still True?

Point-in-time certification is the floor, not the goal. The case for continuous assurance over annual audits — and what it takes to run it year-round.

By Michael YorkMarch 30, 2026 1 min read 243 words All postsTable of contents

Most compliance is a photograph. You spend weeks preparing, an auditor shows up, the environment is pristine, the certificate gets issued, and everyone exhales. The photo is real. The problem is that you keep living after it's taken.

By summer, three new services have shipped. A config got loosened for a deadline and never tightened back. Someone left, someone joined, access lists drifted. None of it is malicious. It's entropy — the natural tendency of a living system to wander away from the state it was in on audit day. And the certificate on your wall still says everything is fine.

So I've stopped treating point-in-time certification as the goal and started treating it as the floor. The question worth answering isn't "did we pass?" It's "would we pass right now, without warning, and how would we know?" That changes how you build. You instrument controls so their state is observable on any given Tuesday rather than reconstructable before an audit. You favor evidence generated as a byproduct of how the system actually runs over evidence assembled by hand for the examiner.

Partners and regulators are moving the same direction. "We were compliant in Q1" is starting to sound like "the smoke detector worked when we installed it." The credible claim is the present-tense one. Build for that, and the annual audit stops being a fire drill. It becomes a confirmation of something that was already true yesterday and will be true tomorrow.

ComplianceGRCAuditFintech