Bank operations staff manage transaction alerts while an independent auditor examines the evidence.

Continuous Auditing vs Continuous Monitoring: Who Owns the Control?

Internal audit · Analytics · Control ownership

At 9 a.m., internal audit emails 23 overdraft exceptions. By lunch, the branch has fixed them. Everyone calls it a success. A year later, audit is asked to assess the control. The control is its own script.

That is where continuous auditing vs continuous monitoring stops being a technical distinction and becomes a question of independence.

From
IA Analytics
To
Branch Manager
Subject
23 temporary overdrafts beyond delegated powers. Please investigate and resolve within 48 hours.
“Done. All 23 addressed. Thanks for flagging.”

The email itself is not the problem. The problem starts when operations says: “Audit checks this daily. Why should we?”

This is an illustrative scenario. The figures and timeline are fictional.

Continuous auditing vs continuous monitoring: the difference

Continuous monitoring is management’s ongoing review of risks, transactions and controls so it can act on problems. Continuous auditing is internal audit’s recurring, independent assessment of risks and controls to provide assurance.

The same code can support either. Purpose and accountability decide which one it is.

On mobile, scroll the table sideways.

Who owns the check and the response?
QuestionMonitoringAuditing
Who owns it?Management, with defined operational and oversight roles.Internal audit owns the assurance work.
What happens next?The owner corrects or escalates exceptions.Audit investigates, reports findings and follows up management’s actions.
What is the output?Action and evidence that controls operate.An independent conclusion about risks and controls.
If the script stops?Management has a monitoring gap to address.Audit has an evidence gap to assess.

Audit can test individual transactions and send exception reports. The boundary is who operates the control and makes the business decisions.

How audit quietly becomes the control

  1. Month 1 · A useful test

    Audit starts its nightly checks. Operations still performs its own review.

  2. Month 3 · Growing reliance

    Exceptions fall. Management assumes the process is “covered”.

  3. Month 6 · The review disappears

    Operations drops its check. No replacement management control is established.

  4. Month 9 · Silence looks like success

    A changed status code makes the script return zero rows. Nobody questions it.

  5. Month 12 · Audit reviews itself

    Audit must now assess the detective control the bank relies on: its own script.

Fixing the script would solve the technical fault. It would not restore clear ownership.

Why ownership matters for independence

Ask who approves the rule, decides the response and accepts unresolved risk. Building a test or communicating a finding does not, by itself, mean audit has assumed those responsibilities.

The IIA’s Standard 2.2 requires auditors to refrain from assessing specific activities for which they were previously responsible. Assurance over an activity an auditor was responsible for within the preceding 12 months carries a presumption of impaired objectivity. Prior advisory work needs a separate assessment and appropriate staffing safeguards.

A handover does not automatically resolve every conflict. Plan who can provide independent assurance before assigning the work.

The fix: build, prove, hand over, assure

Keep developing audit analytics. Where management adopts a script as a production monitor, make the transition explicit.

  1. Build

    Document the risk, rule, source data and exclusions. Reconcile the inputs. Make clear whether the output is audit evidence or a management control.

  2. Prove

    Investigate alerts and test what the rule misses. Forty genuine exceptions in 4,000 reviewed alerts means 1% precision. A quiet dashboard can also hide poor coverage.

  3. Hand over

    Name a management owner. Agree the run schedule, response deadline, escalation route, failure alerts and change approvals. Record acceptance and demonstrate that the team can operate without audit.

  4. Assure

    With suitable objectivity safeguards, test coverage, closure quality, suppressed alerts and rule changes. Check whether anyone would notice stale data or an unexpected zero-row result.

A temporary arrangement still needs safeguards. Disclose impairments promptly under Standard 2.3. Where the chief audit executive temporarily assumes nonaudit responsibilities, Standard 7.1 requires independent third-party assurance during the assignment and for the following 12 months, plus a transition plan. Committee approval alone does not remove an impairment.

A one-minute ownership check

Tick what applies to see your next step. Your answers stay on this page.

Does management depend on audit?
Ownership review Discuss each selected statement with the chief audit executive and agree who owns the control.

This is a discussion aid, not an impairment score. One management responsibility can matter more than several weaker signals.

One action this week

List your scripts, their purpose and who depends on them. Audit-only tests can stay with audit. For scripts operating as management controls, identify the person outside audit who owns the outcome. The blank names are where the conversation starts.

Connect the assurance results to your wider plan: see our guide to risk-based internal auditing (RBIA).

If audit’s script stopped tomorrow, who would own the problem?

How does your team draw the line?

Share your approach in the comments, or write to k.casatish@daxified.co.in.

Sources: IIA Global Internal Audit Standards, Standards 2.2, 2.3 and 7.1. Further reading: Continuous Auditing and Monitoring, 3rd Edition (2025). The scenario and handover suggestions are practical commentary.

Leave a Comment

Your email address will not be published. Required fields are marked *