For forty years, the international certification system operated on a simple model · initial audit, annual surveillance, recertification every three years. It worked because organisations changed at a human pace · a new process took months to settle in, replacing a critical supplier involved a project, an information system was updated with minutes and a committee. That world has ended. There is just one question the board must be able to answer today · how often is something that changes every week verified.
The diagnosis of the rupture — why systems stopped waiting for the auditor, how fast they mutate, what operates outside what has been declared — has its own article · Criterion 10. This criterion addresses the response. The response has a technical name · continuous auditing. And it has a guiding principle · verification frequency is a technical variable derived from the pace of change of the audited system, just as the sample is derived from risk and the scope from operations. The calendar is an administrative instrument. The system's pace is a fact. When they diverge, the fact prevails.
Three pathologies of the annual model
Pathology 01 · a valid certificate for obsolete operations. The certificate states compliance. Six months later, the models in production, suppliers and supply chain are operationally different. The current certificate attests to an organisation that no longer exists in exactly that form.
Pathology 02 · the audit-as-event that freezes operations. The organisation halts changes from June, passes the audit in September and resumes normal operations from October. The documented system is one thing. The operating system is another. The annual auditor sees the former.
Pathology 03 · unrecorded change between audits. Between visits, the technical team implements changes. Some are recorded. Others are not. Those that are not do not exist for the management system — until an incident makes them visible.
The professional framework has already shifted
The IIA Global Standards have been in effect since January 2025. In September of that year, the Institute published Continuous Auditing and Monitoring as recommended guidance. The distinction matters · it guides a practice; it does not in itself create a conformity requirement. ISO 19011:2026 provides the framework for designing risk-based audit programmes; it does not mandate continuous auditing either. Additional frequency is justified by the system's risk and pace of change.
Continuous auditing is neither automatic maturity nor a universal obligation. It requires reliable data, alert criteria, people responsible and the capacity to investigate exceptions. Without these conditions, a more frequent dashboard merely accelerates signals of unknown quality.
Three operational components
Component one · auditable telemetry. The ability to observe the system in operation, not just its documentation. The records the system produces as it operates — access, versions, configuration changes, automated decisions — remain available for independent verification, with their integrity protected.
Component two · variable-frequency reviews. Independent verifications triggered by relevant change — a new supplier, a new model, a redesigned process, incoming regulation — in addition to the fixed cycle. Risk sets the pace · the calendar sets the minimum.
Component three · trigger-based verification. Assess the system version when it changes, not when the certificate expires. The trigger is the technical event, recorded with an actor, date, criterion, scope and validity period.
The epistemological basis · auditing by distribution
Stochastic systems demand a different reading. An individual case may be evidence of a specific failure, but it does not in itself describe the distribution of outcomes. Assessment combines repeated testing, relevant segments, identified versions and change tracking. Continuity provides time series; statistical design determines whether those series support conclusions.
The economics of continuity
Continuity entails infrastructure and review costs. The organisation must compare these with the risk of detecting a material change late. That decision does not alter the formal certification cycle or turn internal monitoring into third-party auditing.
Monitoring observes · auditing signs
A boundary must be drawn before the test. The continuous monitoring dashboard observes · it accumulates signals, triggers alerts, plots trends. Auditing interprets and signs. Interpretation requires professional judgement — that of Criterion 01 — and signing requires an identifiable person responsible — that of Criterion 06. An organisation with impeccable telemetry and no signatory to interpret it has an instrument, not yet an audit. Continuity adds data to the profession. The profession still consists of deciding what they mean.
The criterion test
Ask the person responsible how many material changes have occurred since the last audit and how many were assessed under the change process. Zero can be a valid answer if there is evidence. The difference between identified changes and assessed changes serves as an internal indicator of continuous audit debt. It is not a normative metric; it helps locate trust travelling without sufficient review.