- Compliance Management
- CCM
- 17th Sep 2026
- 1 min read
Compliance-as-Proof: 4 Shifts GRC Teams Need in 2026
- Written by
In Short..
- Regulators now test how controls actually run day to day: DORA and NIS2 both expect live evidence that controls are working, generated as they run.
- The annual audit cycle leaves blind spots regulators no longer accept: A control that fails in month four of a twelve-month cycle can go undetected until the next audit.
- Continuous controls monitoring turns evidence into a by-product of operating: Automated testing and a centralised evidence repository can cut audit preparation time by up to 75%.
- One control test can satisfy several frameworks at once: A cross-framework control library matters more as regulatory obligations stack up.
Continuous controls monitoring is what closes the gap between having a compliance framework and proving it works. Annual audit readiness used to be enough: policies signed off, evidence packs assembled before the auditor arrived. DORA and NIS2 have moved past that model. Both now expect live evidence that controls are operating effectively today.
This piece assumes you already know DORA and NIS2 in outline; for that grounding, see our Regulatory Compliance Guide. What follows is the operational question that comes after understanding what regulators require: what does a GRC programme actually need to look like once regulators are testing how controls run day to day?
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What our experts say about proving controls work before anyone asks
"I've sat across the table from supervisors asking for twelve months of evidence in a single meeting. The teams that had it were the ones whose controls generated proof automatically. Everyone else promised to send it over by Friday." |
The Regulator Is No Longer Reading Your Policy Documents
The traditional compliance model rested on a simple assumption: demonstrate intent and regulators will infer effectiveness. Publish a policy, appoint an owner, get it signed off annually, file it somewhere accessible. Auditors reviewed the artefacts and issued a finding or a clean report. That assumption has stopped holding.
DORA, which entered full enforcement in January 2025, requires financial entities to maintain and continuously update their ICT risk management frameworks. Article 6 of Regulation (EU) 2022/2554 requires ICT risk management embedded into operational processes, with evidence of ongoing effectiveness available on request rather than assembled after a supervisory request arrives.
NIS2 takes a similar position, with national competent authorities increasingly testing whether controls are operating in practice. The direction across both frameworks is consistent: regulators have shifted from reviewing documentation to testing operations, so evidence needs to exist before the question gets asked. The NIS2 Directive itself, Directive (EU) 2022/2555, sets that expectation at the legislative level, backing up what supervisors are already testing for in practice.
That pressure shows up in board priorities too. PwC's 2026 Global Digital Trust Insights Survey found that 60% of business and technology leaders now rank cyber risk investment among their top three strategic priorities. Regulatory pressure is a real part of that calculation: boards know the bar for demonstrating control effectiveness has risen. For more on the specific DORA obligations driving this, see our Five Pillars of DORA Explained.
Why the Annual Audit Cycle Is Structurally Broken
Annual audit readiness runs on a different assumption than the one DORA and NIS2 now enforce, and that mismatch goes deeper than simple inefficiency. Four things follow from an annual model:
- A point-in-time snapshot only: Controls may have been effective on the day evidence was gathered. What happened in the eleven months before that stays largely invisible.
- Evidence assembled well after the fact: Teams spend weeks pulling together screenshots, logs and sign-offs that approximate what was happening at the time. An approximation isn't the same as evidence.
- A compliance spike that fades once the audit passes: Effort concentrates in the run-up to the audit, then dissipates. The programme is only as strong as its last sprint.
- Coverage gaps nobody sees in real time: If a control fails in month four of a twelve-month cycle, the failure may not surface until the next audit. Under DORA and NIS2, that gap counts as regulatory exposure in its own right.
The Cost of the Scramble
The operational cost of annual audit readiness is real. Teams report spending weeks, sometimes months, assembling evidence packs that should exist as a matter of course. The FCA issued £15.7 million in fines in Q1 2026 alone, and some of those penalties came from controls that couldn't be demonstrated rather than controls that didn't exist.
That's the distinction that matters. Regulators treat an unevidenced control as a control that failed, whether or not it actually worked.
The Spend Signal
Gartner forecasts that assurance leaders across legal, risk and compliance functions will double their department's technology spend by 2027. That acceleration reflects a recognition that manual, retrospective compliance processes can't meet the evidentiary standard regulators now expect, and the investment is landing, in large part, in continuous assurance capability.
What Compliance-as-Proof Actually Requires
Moving from documentation to proof is an operating model change that happens to involve software, rather than a software purchase on its own. Four things need to work together. No exceptions.
1. Controls That Generate Evidence Automatically
Manual evidence collection is always retrospective: someone has to go and find the proof after the fact. In a continuous model, controls are designed so evidence is a by-product of operation. Automated testing, system-generated logs and scheduled control checks create an evidence record as a matter of course, so nothing needs assembling after the fact.
2. Continuous Testing Over Periodic Sampling
Annual or quarterly control testing tells you whether a control was working on the day it was tested. Continuous testing tells you whether it's working today, and whether it was working every day in between. For DORA-regulated entities, that distinction is material: ICT risk management frameworks need to reflect the current risk environment as it stands this week.
3. A Single Source of Truth for Compliance Evidence
Evidence scattered across shared drives, email threads and individual laptops is a liability waiting to be discovered. A GRC programme built for proof needs a centralised, auditable repository where evidence is timestamped, version-controlled and retrievable on demand. When a regulator asks for twelve months of evidence, the answer should take minutes.
4. Real-Time Visibility of Control Status
A control that's failing right now and going unnoticed can't be fixed before it becomes a finding. Under frameworks that require ongoing effectiveness, real-time dashboards and automated alerts earn their keep here: they're the mechanism that shows a programme is actually working, day to day.
Continuous Controls Monitoring: The Practical Operating Model
Continuous controls monitoring (CCM) is the operational mechanism that makes compliance-as-proof possible. It replaces the annual audit cycle with an always-on assurance process: controls are tested on a defined frequency, evidence is captured automatically, failures surface in real time, and the compliance record stays a living document rather than a retrospective reconstruction. Teams using CCM report up to a 75% reduction in audit preparation time, because the evidence already exists before anyone asks for it. See SureCloud's Continuous Controls Monitoring for how the model works in practice.
|
Without CCM |
With CCM |
|
Evidence assembled retrospectively before each audit |
Evidence captured automatically as controls operate |
|
Point-in-time control testing, annual or quarterly |
Continuous testing at defined frequencies |
|
Control failures discovered during audit prep |
Control failures surfaced and remediated in real time |
|
Evidence spread across multiple teams and tools |
One auditable repository, timestamped and version-controlled |
|
Compliance posture unknown between audits |
A live dashboard of control status across every framework |
Cross-Framework Efficiency
One practical advantage of CCM for teams managing multiple regulatory obligations is the ability to test once and satisfy several frameworks simultaneously. A single control test can produce evidence that maps to DORA, NIS2, ISO 27001 and other applicable standards. Running separate evidence programmes for each framework doesn't scale as obligations stack up.
CCM also gives GRC teams a way to show boards the compliance programme is working day to day. Real-time control status data replaces the annual "we passed our audit" update with a continuous view of programme health. For organisations navigating both DORA and NIS2 together, our NIS2 and NCSC CAF v4.0 mapping guide sets out how the two intersect operationally.
Where to Start: Moving Your GRC Programme to Continuous Assurance
The shift to continuous assurance doesn't require rebuilding a GRC programme from scratch. Most teams already have the controls. What they lack is the infrastructure to test them continuously and capture evidence automatically. The transition comes down to sequencing.
- Identify your highest-regulatory-exposure controls first:
DORA and NIS2 both concentrate supervisory scrutiny on ICT risk management, incident detection and response, third-party oversight, and business continuity. Start CCM there first. - Map existing controls to regulatory obligations:
Before you can test continuously, you need to know which controls satisfy which requirements. A cross-framework mapping exercise reveals both coverage gaps and duplication: many teams find they're running more controls than they need and still have gaps where it matters. - Define testing frequencies by risk level:
Not every control needs daily testing. High-criticality controls in DORA-regulated environments may warrant weekly or monthly automated testing; lower-risk controls can run quarterly, scheduled and automatic rather than triggered by an approaching deadline. - Centralise evidence before automating it:
If evidence currently sits spread across multiple systems, consolidating it into a single repository comes before automation. Automating a search across five different stores just makes the search faster, and the evidence itself is still scattered. - Build reporting into the operating rhythm:
Real-time dashboards only help if someone reviews them. A monthly review cadence, at minimum, means control failures get addressed as a matter of course rather than surfacing during audit prep.
The GRC teams making this transition well treat compliance evidence as an operational output rather than an audit deliverable, regardless of budget size. They know the answer to "is it working" before anyone asks the question.
Turn Compliance Evidence Into a By-Product of Operating
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Let Gracie get the work done.
Gracie drafts summaries, evidence requests and audit narratives across your programme — you stay in control.
See Gracie in action or book a full platform demo →See what SureCloud costs
A short form, no sales call. Pricing built around your GRC estate.
Get PricingIDC names SureCloud the industry's first cross-domain agentic GRC platform"
Read the independent analyst view on how SureCloud is redefining risk and compliance.
Download for freeFAQ’s
What is continuous controls monitoring and how does it differ from an annual audit?
Continuous controls monitoring (CCM) is the automated, ongoing assessment of whether security and compliance controls are operating as designed. An annual audit produces a point-in-time snapshot; CCM produces a living record, with controls tested on a defined frequency and failures surfaced in real time rather than discovered during audit preparation. Under DORA and NIS2, regulators expect evidence of ongoing effectiveness covering the full twelve months, generated as it happens.
Does DORA explicitly require continuous controls monitoring?
DORA frames the obligation in its own regulatory language, functionally equivalent to continuous controls monitoring. Regulation (EU) 2022/2554 requires financial entities to maintain and continuously update their ICT risk management frameworks, monitor ICT systems on an ongoing basis, and keep evidence of control effectiveness available to supervisors. The regulation's model is evidence kept current and available on request, generated well before a supervisory request arrives.
How does CCM help with NIS2 compliance?
NIS2 requires essential and important entities to run risk management measures on an ongoing basis and demonstrate those measures are operating effectively in practice. CCM provides the governed evidence cadence that supports that demonstration: defined control owners, measurable KPIs, scheduled testing, and a centralised evidence repository linked to specific NIS2 obligations.
Can one control test satisfy multiple frameworks simultaneously?
Yes, and it's one of the strongest practical arguments for CCM. A single control test can produce evidence that maps to DORA, NIS2, ISO 27001 and other applicable standards at once. A well-structured CCM programme, built on a cross-framework control library, lets a team test once and satisfy several regulators from the same evidence record instead of running a separate evidence exercise per framework.
How quickly can a GRC team move to a continuous assurance model?
The transition doesn't require rebuilding a programme from scratch, since most teams already have the underlying controls. A practical starting point is identifying the highest-regulatory-exposure controls (ICT risk management, incident detection, third-party oversight, business continuity), mapping them to regulatory obligations, defining testing frequencies by risk level, and centralising evidence before automating it. Teams using a purpose-built platform can reach an operational CCM posture within weeks rather than months.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
Esavian House 181A High Holborn, London, WC1V 7QX, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
