August 21, 2026

Beyond the Compliance Snapshot: Why GRC Needs Continuous Evidence

August 21, 2026
Mark Gillard
Mark Gillard

By Mark Gillard, VP Partner / Alliances & Customer Success, Feroot Security

Passing the audit isn't the finish line.

I recently had the opportunity to speak at the ISACA GRC Conference in San Diego about a challenge I see becoming increasingly important for governance, risk, and compliance teams: How do you prove your controls are actually working in digital environments that never stop changing?

My session, *Beyond Consent Banners: Building Continuous, Evidence-Based Compliance at the Digital Experience Layer*, focused on a fundamental shift taking place in GRC. For decades, compliance has operated around a familiar model: organizations perform an assessment, review controls, gather documentation and evidence, address findings, and close the audit. Those processes remain essential, but there’s an increasingly important problem with relying on them alone: the business keeps moving after the assessment ends.

Today’s digital environments don’t remain static between assessments. Websites and applications change constantly. Marketing teams deploy new technologies. Developers ship new code. Vendors update scripts. SDKs change behavior. AI tools appear. Third-party technologies connect to other third parties. An organization can successfully validate its controls today and have a materially different digital environment tomorrow.

Yet many GRC programs still rely heavily on evidence collected at specific moments in time. The result is an emerging assurance gap: organizations can prove what was true during an assessment, but often struggle to prove what remained true afterward.

The New GRC Question: What Happened Between Assessments?

Point-in-time assessments aren’t going away, nor should they. Privacy assessments, PCI DSS assessments, penetration tests, internal audits, security reviews, and other assurance activities remain critical components of an effective GRC program.

But these activities largely tell us what was true when we looked. Increasingly, organizations also need to answer what happened when no one was actively assessing the environment. What changed two weeks after the assessment? What about three months later? Did the controls that were validated continue to operate as expected?

Consider how much can change during that time. A marketing team adds a new technology through a tag manager. A third-party vendor updates its JavaScript. A developer deploys an approved feature that creates an unexpected data flow. A payment page begins loading a new resource. An SDK update changes where information is transmitted.

None of these events necessarily indicates that someone ignored governance. They’re normal business operations. But every change creates the possibility that the environment an organization documented is no longer the environment its customers are actually interacting with.

One change. Four control domains. No one team saw it all.

Compliance Drift Is an Assurance Problem

This gradual divergence between documented controls and actual production behavior is what I think of as compliance drift, and it can happen surprisingly quickly.

Imagine an organization completes an annual privacy assessment. The consent banner is validated, the cookie inventory is documented, marketing technologies are reviewed, and everything passes. Two weeks later, marketing launches a campaign and introduces a new analytics technology through a tag manager. Nobody is attempting to circumvent a control, but the technology begins collecting an identifier before consent.

If there is no mechanism to detect that change, three months can pass while the organization’s documentation continues to describe the environment that was originally assessed. The documentation may still accurately describe what was true on assessment day, but it no longer accurately describes production.

What’s particularly challenging about compliance drift is that every individual team may have followed its established process. Marketing launched its campaign. Development deployed approved code. Privacy previously validated its controls. Security received no indication that anything significant had changed.

The problem isn’t necessarily a failure of process or governance. It’s often a failure of visibility across those processes. That’s why I believe compliance drift should be viewed as an organizational assurance problem rather than simply a privacy, security, or technology problem.

Digital Risk Doesn’t Respect Organizational Boundaries

Traditional governance structures divide responsibility for good reasons. Privacy manages privacy risk. Security manages security controls. Compliance manages regulatory obligations. Internal audit provides assurance. Marketing manages marketing technology. Engineering builds and maintains applications.

The digital experience, however, doesn’t recognize those organizational boundaries. A single customer interaction can involve a browser, an application, APIs, scripts, SDKs, analytics platforms, advertising technologies, payment systems, and numerous third parties. From the customer’s perspective, all of those technologies are part of the same experience.

A change originating with one team can therefore affect controls owned by another. Marketing may introduce a technology that creates a privacy issue. A vendor update may create a security issue. A development change may affect a PCI DSS control. A new third-party connection may introduce an issue for vendor risk management.

This makes digital risk inherently cross-functional and creates a challenge for governance programs built primarily around periodic reviews and organizational silos. The solution can’t be to stop marketing from launching campaigns, prevent developers from shipping, or stop vendors from updating their products. Governance has to become capable of operating at the speed of that change.

Evidence Needs to Become Continuous, Too

Historically, organizations have often gathered evidence when they needed to prove something. An audit begins, so teams collect screenshots. An assessor requests documentation, so teams assemble records. A regulator asks a question, so the organization attempts to reconstruct what happened.

There’s an important difference, however, between reconstructing the past and having a historical record of it. That’s where continuous evidence can change the assurance model.

Instead of asking teams months later to demonstrate how a control was operating, organizations can continuously observe production and generate evidence as changes occur. If a new third-party technology appears, a control stops behaving as expected, an unexpected network connection emerges, or something changes within a payment environment, the organization has the opportunity to detect that behavior and create a record of it.

That creates a fundamentally different position when an auditor, regulator, legal team, customer, or board member asks whether a control was working. The answer no longer has to depend entirely on documentation describing how the control *should* have operated. The organization can demonstrate how it *actually* operated.

Documentation and Evidence Serve Different Purposes

Documentation remains foundational to governance. Policies establish expectations, procedures define responsibilities, and control descriptions explain how risks should be managed. But documentation and operational evidence answer different questions.

Documentation tells us that controls exist and describes how they are intended to operate. Evidence demonstrates whether those controls actually operated effectively in production. An organization may document controls governing technologies interacting with payment pages, for example, while continuous evidence can demonstrate whether unauthorized JavaScript actually appeared or interacted with those pages over time.

The same principle applies to privacy, third-party risk, security, and other areas of GRC. Strong governance needs both documentation and evidence. The goal isn’t to replace documented controls; it’s to connect those controls to observable production behavior.

Continuous Evidence Creates a Shared View of Risk

One of the most significant benefits of continuous evidence is its potential to create a shared view of risk across the organization. Today, different teams may maintain different perspectives on the same digital environment. Privacy has one inventory. Security has another. Marketing knows which platforms it intentionally deployed. Development understands the application’s architecture. Compliance maintains control documentation. Internal audit collects evidence periodically.

When evidence is generated continuously from the environment itself, these teams gain a common reference point. Privacy gains greater visibility into whether controls remain effective. Security gains insight into third-party activity and unexpected behavior. Internal audit gains historical evidence rather than having to reconstruct the environment during an assessment. GRC gains ongoing control assurance, while compliance teams gain stronger support for regulatory reporting and leadership gains a more defensible view of digital risk.

Instead of six teams maintaining six different interpretations of the environment, continuous evidence can help establish a common source of truth about what’s actually happening.

AI Makes Continuous Assurance Practical

Of course, continuously observing a modern digital environment creates a scale problem. An enterprise may operate numerous websites and applications containing thousands of pages and technologies. Behavior may differ by geography, application state, consent choice, or user journey, and those environments may change every day.

Governance professionals shouldn’t have to spend their time manually checking thousands of combinations to determine whether something changed. Their expertise is better applied to understanding what those changes mean, evaluating risk, establishing governance, prioritizing remediation, and making decisions.

That’s where AI and automation become valuable. Automation can perform the repetitive work of continuously discovering technologies, mapping data flows, identifying behavioral changes, validating controls, monitoring payment environments, and generating evidence. Humans can then apply the judgment and governance expertise required to determine what deserves attention and what action should be taken.

AI doesn’t replace governance professionals. It can give them continuous visibility that would otherwise be extremely difficult to achieve manually.

From Periodic Compliance to Continuous Assurance

Organizations don’t need to transform their entire GRC program overnight. During my ISACA GRC session, I outlined five practical steps organizations can use to begin building a continuous assurance capability.

First, discover your digital assets and understand what’s actually operating across websites and applications. From there, continuously monitor runtime behavior to establish visibility into how those environments behave and change.

Next, validate the controls that matter, whether they’re related to security, privacy, consent, payment security, or other regulatory requirements. Organizations can then generate evidence automatically, building a historical record as monitoring occurs rather than trying to reconstruct one month later.

Finally, put that evidence to work across audits, compliance reporting, risk management, regulatory inquiries, and board-level conversations. At that point, continuous assurance stops being another assessment and becomes an operational capability.

"We Passed the Audit" Isn’t the Finish Line

One of the simplest ways I described this shift at ISACA GRC was as a change in mindset. The traditional mindset is, "We passed the audit." The emerging mindset is, "We can demonstrate our controls are operating effectively every day."

Passing the audit still matters. Point-in-time assessments still matter. Documentation still matters. But in a digital environment that may change hundreds or thousands of times before the next assessment, they can’t be the only measures of assurance.

Digital environments change continuously, and our assurance models need to account for that reality. Point-in-time assessments inherently leave blind spots between reviews, and those gaps are precisely where compliance drift can occur.

Continuous monitoring and evidence give organizations a way to better understand what happens in that space between assessments and demonstrate how their controls actually operated over time.

Ultimately, strong governance isn’t simply about documenting controls or proving that they worked once. It’s about having the visibility and evidence to demonstrate that they’re continuing to work as intended.

Scan your page free with PageScanner

See What’s Really Running on Your Website

Schedule a Demo