Continuous Auditing: Moving Assurance Closer to the Moment of Risk
- Michael G. Bradshaw, CPA

- Aug 11
- 2 min read
Traditional auditing is inherently periodic. An auditor examines a defined period, evaluates evidence and ultimately reports a conclusion about conditions that existed during that period.
But business risk does not operate on an annual reporting cycle. Fraud can occur tomorrow. A critical control can fail next week. A supplier can become distressed next month. An unusual transaction can occur between two audit visits. The gap between when a risk emerges and when assurance identifies it can therefore become strategically important.
This is the space that should be occupied by continuous auditing and continuous assurance. Continuous auditing does not necessarily mean that every transaction is reviewed by an auditor in real time. Rather, it involves the systematic use of technology, data analytics and automated procedures to identify changes, anomalies and control exceptions throughout the year.
The distinction is important because continuous auditing should not become “continuous testing for the sake of testing.” Its value comes from reducing decision latency. Imagine an internal audit function monitoring procurement transactions continuously. Instead of identifying unusual vendor activity months after year-end, the organization could establish indicators that trigger investigation when transaction patterns materially change. The assurance function consequently becomes more closely connected to management's risk response.
The IAASB has previously identified increasingly analytics-based, continuous and real-time assurance as part of the evolving digital assurance environment. Its work demonstrates that standard setters continue to consider how technological change should influence audit and assurance approaches. However, continuous assurance introduces its own risks.
Poorly designed algorithms can produce excessive false positives. Automated rules may become obsolete. Data feeds can fail. Monitoring can create an illusion of coverage without actually addressing the most important risks. Accordingly, the real measure of a continuous audit program is not the number of transactions monitored. It is whether the monitoring architecture identifies meaningful changes in risk early enough to influence decisions.
Comments