No audit committee is a stranger to the following statement: “Based on a sample of transactions, we found no material exceptions.”
It sounds rigorous, has a methodology and gives the impression of confident closure. But it also means that the board doesn’t know what happened to the rest of the transactions that moved through the business last quarter!
Continuous auditing is not new. Groomer and Murthy proposed embedded audit modules in 1989, and Vasarhelyi and Halper formalised continuous audit of online systems in 1991. The CICA and AICPA published a joint framework in 1999. The IIA has issued continuous auditing guidance since 2005. Sarbanes-Oxley gave the concept a legal forcing function in 2002, and researchers at the time expected that broad-based adoption would be only a matter of time.
But that was over two decades ago!
While the idea was correct from the start, two things kept it from wider adoption: infrastructure costs and a strong enough regulatory push to drive change. Now, things are changing, and they are changing fast. That is why the timing looks sudden even though the underlying logic is 35 years old.
What stopped continuous auditing from reaching the mid-market?
Continuous auditing thrived first at companies that could fund a custom build. For example, Siemens’ post-Sarbanes-Oxley implementation of continuous assurance in 2006. It had all the hallmarks of a large-scale implementation — dedicated data engineers, a custom ERP connector, and a standing analytics team to maintain thresholds.
While this sounds realistic for the Big Four and their largest clients, its mostly out of reach for everyone else!
Mid-tier audit firms and mid-market manufacturers spent the next two decades doing the same work by hand instead. They have to rebuild the control logic in legacy GRC tools for every client. This made it hard to standardise a control library across a portfolio or scale a practice without adding headcount and eroding margins.
Frustrating as it may sound, it had to be done, as nobody cared to build a reusable, configurable library that a mid-sized audit firm could own once and redeploy across every engagement, instead of rebuilding it from zero each time. I have seen this up close, having built FUTUROOT’s continuous audit capabilities to solve exactly that problem.
Closing that gap is more a distribution challenge than a technology one, and addressing it unlocked this shift. Fortunately, there couldn’t have been a better time for continuous auditing to take flight.
Geopolitical stress is changing what audit must test
Managing supply chain risks is no longer about configuring the right control. It’s also a governance question. KYU’s 2026 Supply Chain Risk Barometer found that 55% of companies across aerospace, automotive, luxury, distribution, and energy consider geopolitics as the single biggest threat to their supply chains. Essentially, it is a meta-risk, triggering cascading and interconnected disruptions that amplify quickly.
Apparently, none of that is audit’s job to fix! Traditionally, audit has focused on analysing the transaction-level residue those shocks leave behind. For instance, vendor concentration spiking as procurement scrambles to re-source under a tariff shock, master-data records changing hands faster than change control can review them, duplicate or rushed payment approvals as teams route around a broken process.
However, the vendor-master and procure-to-pay anomalies that geopolitical volatility generates are exactly what a population audit should test. With disruption faster than ever and businesses needing to respond rather than react, a model built around a 60-day fieldwork cycle and a 5–10% sample size cannot provide the live picture needed to steer in real time.
Frauds are evolving, and sample testing alone cannot keep up
Fraudulent activities follow a pattern. For instance, segregation-of-duties violations cluster around specific users and approval chains. Vendor fraud clusters around specific master-data records altered to survive scrutiny. Duplicate payments cluster around process exceptions someone learned they could exploit.
Modern audit practices address these to some extent. Monetary-unit sampling and risk-stratified selection under ISA 530 and PCAOB AS 2315 weight samples toward higher-risk accounts and processes rather than drawing purely at random.
However, the stratified sampling approach still requires the auditor to guess in advance which layer the risk sits in. This is easier said than done. For instance, stratify by vendor size, and the fraud may hide in a mid-tier vendor nobody flagged. Stratify by transaction value, and the fraud can lurk in a thousand small transactions built to stay under the threshold.
Here, full population monitoring removes the guesswork entirely. With continuous auditing, every stratum is monitored in real time, leaving no room for anomalies to hide.
Is continuous auditing a silver bullet? View through a realist lens
I have seen audit leaders who have piloted continuous monitoring for their organisation tell the same story: move from a 5% sample to monitoring 100% of the population without disciplined threshold design, and things tend to get worse rather than improve.
In fact, academic literature widely documents continuous audit regimes without the right thresholds that collapse under their own weight. For instance, this research by Rutgers University found that applying simple filters to 100% of the data created an overwhelming volume of exceptions that buried systemic fraud. Further, IIA’s Global Technology Audit Guide (GTAG 3) on Continuous Auditing warns that the biggest operational bottleneck in continuous auditing is managing the outcomes.
When a team get an exception queue that it cannot realistically work through, it will eventually stop reading the alerts. Alert fatigue is real, and I have seen it kill more than a few pilots.
That’s why easily configurable thresholds and controls are as important as coverage. A control library tuned by the vendor once at go-live is likely to eventually drown the team in junk alerts and call into question the idea of continuous auditing itself. An alternative is to let auditors own and continuously retune threshold sensitivity—an idea FUTUOOT’s CCM package supports with configurable controls that make continuous audit accessible and practical for the mid-market.
Alongside volume, materiality matters. Without a materiality filter, a correctly flagged $50 posting error can carry the same visual weight as a $500,000 error and eventually bury the genuine exceptions that demand the auditor’s attention.
Regulators are now demanding continuous evidence
Continuous audit is fast shifting from a best practice to a statutory demand across leading economies globally. This is more than a regional trend, as these economies have different legal traditions, political landscapes, and regulatory climates. Here is a rundown:
United States — PCAOB AS 1105
- Effective for fiscal years beginning on or after December 15, 2025
- Moves away from a binary internal-vs-external test for data reliability
- Requires risk-scalable evaluation of data from cloud platforms, third-party systems, and automated feeds
- Written for evidence that flows continuously, not evidence extracted once for a testing window
United Kingdom — FRC Corporate Governance Code
- From 2026, boards must annually review the effectiveness of risk management and internal controls.
- Reporting follows a comply-or-explain regime.
- Described in the market as a “SOX-lite” reform.
- Assumes ongoing evidence already exists to review, rather than an attestation assembled once a year under deadline pressure.
India — Income Tax Act, Section 43B(h)
- Inserted by the Finance Act 2023.
- Disallows a tax deduction for any purchase from a registered micro or small enterprise unless paid within 15 days (45 with a written agreement).
- Miss the window on a single invoice and the full expense is added back to taxable income.
- Form 3CD now requires disclosure of amounts due, paid on time, and paid late to registered small-enterprise vendors.
- A tax auditor can’t sign that clause based on a sample — it’s a per-invoice, per-vendor test that has to cover the full population.
- Continuous controls monitoring earns its place upstream: tracking vendor registration, invoice dates, and payment timelines all year means the compliance data is already verified before year-end, not reconstructed under pressure during close.
Interestingly, three systems across three continents arrived at the same requirement independently within 3 years of each other. It reiterates my earlier argument that businesses need accessible, practical means of continuous assurance in an uncertain world.
The changing role of the auditor
Automating evidence gathering is only half of the game. The other half is exception adjudication: deciding which thresholds matter, which flagged pattern is a real control failure versus a normal business exception, and which case belongs before the audit committee.
That judgement is exclusively human work. Notably, sample-based approaches never gave auditors enough visibility or bandwidth to do this well in the first place.
Thirty-five years after Vasarhelyi and Halper first described what continuous audit should look like, the infrastructure to run it at mid-market scale and a statute that requires it on a per-transaction basis have both arrived in the same year.
However, design discipline remains the most important part of the puzzle. Implementing the right thresholds turns a correct 35-year-old idea into an operating standard.
Ready to experience continuous assurance with the control?
If your audit function is still building its control population from a sample, the gap between what regulators now expect and what a sample can prove is only widening, regardless of the geographies you operate in.
Reach out to our experts to learn how FUTUROOT CCM can change your approach to assurance!




