Look for policy drift, delayed or missing lineage updates, unexplained access growth, and data quality anomalies that persist longer than they should. Those signals show that the live environment no longer matches the documented control state, even if the last audit looked clean.
What failing controls look like between audits
Between audits, a control usually fails first as drift, not as a loud exception. The clearest warning signs are control evidence that no longer matches reality, exceptions that quietly expand, and monitoring that shows the control is not being exercised at the cadence the policy assumes. In practice, failure is less about one bad event and more about a weakening pattern.
A healthy control leaves a repeatable footprint: approvals happen on time, lineage or ownership is updated when changes occur, and access growth is explainable. When those signals stop lining up, the control may still pass a point-in-time review but it is no longer dependable operationally.
Look especially for the gap between policy intent and daily behaviour. If teams can no longer show timely recertification, accurate inventory, or consistent exception handling, the control state is stale even before the next audit cycle begins.
Why drift, stale lineage, and access growth matter
Control failure is often easiest to spot in the places where governance depends on current truth. Policy drift means documented rules are no longer aligned with how systems are actually run. Delayed or missing lineage updates mean ownership, data flow, or approval paths are no longer trustworthy. Unexplained access growth suggests entitlements are accumulating faster than they are being reviewed.
Data quality anomalies matter for the same reason. If the control relies on accurate records, then persistent anomalies in completeness, consistency, or timeliness are not just data issues, they are evidence that the control environment is losing integrity. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is a useful reference when the problem is really about evidence, governance, and the audit trail behind access and ownership.
These signs matter because they accumulate silently. A control can look compliant at the last checkpoint while the underlying process has already lost discipline, especially when manual exceptions, inherited access, or unmanaged updates become the normal path.
Which signals should trigger investigation first?
The most actionable signals are the ones that show a control has stopped self-correcting. Start with overdue reviews, missing approvals, stale ownership records, and access changes that cannot be tied to a business event. Then check whether anomalies repeat in the same system, team, or control owner, which often indicates a process gap rather than a one-off mistake.
For practitioner triage, the key question is whether the issue is isolated or systemic. One missed update may be clerical. Repeated missed updates, inconsistent evidence, or growth in standing access is a control design problem because it shows the control is no longer keeping pace with change.
When a failure signal persists across more than one review cycle, treat it as evidence of control decay, not an isolated housekeeping issue. At that point the right response is usually to re-baseline the control, not simply to re-run the same checklist.
Risk and Threat Considerations
When controls fail between audits, the main risk is false assurance. The organisation may continue to rely on a control that is only correct in documentation, while the live environment has already diverged. That creates exposure through missed revocations, excessive access, unsupported exceptions, and records that no longer support accountability.
Failure mechanism: Drift accumulates through delayed updates, weak ownership, and inconsistent monitoring, so the control stops enforcing the state the audit expects.
Impact: Undetected exposure can persist for long periods, making it easier for misuse, overreach, or compliance gaps to survive until the next review or an incident forces discovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | GRC — Governance, Risk and Compliance | Covers control monitoring, evidence, and audit consistency in cloud governance. |
| Recommendation — Track control drift and refresh evidence whenever governance state changes. | ||
| NIST CSF 2.0 | GV.OV-01 — Oversight of Governance | Supports oversight of control effectiveness and ongoing governance monitoring. |
| Recommendation — Review control performance continuously, not only at audit time. | ||
| ISO/IEC 27001:2022 | A.5.36 — Compliance with policies, rules and standards for information security | Addresses whether operational controls still align with documented policy. |
| Recommendation — Verify that implemented control behaviour still matches approved policy. | ||
| SOC 2 (AICPA) | CC4.1 — Monitoring Activities | Relevant when assessing whether monitoring catches control failure between reviews. |
| Recommendation — Monitor control activity continuously and investigate unexplained drift. | ||
Practitioner Guidance
What to prioritise: Focus first on controls whose evidence should change whenever the environment changes, such as access recertification, lineage, approvals, and exception tracking. If those are stale, the control is failing regardless of whether the last audit passed.
What to verify: Compare the documented control state to live records, not just to the last signed-off report. Look for mismatches in ownership, entitlement counts, exception age, and the time it takes to reflect a material change.
Common mistake: Treating a clean audit outcome as proof of ongoing control health. Audits validate a point in time, but between-audit signals tell you whether the control is still operational.
Practitioner takeaway: The strongest indicator of a failing control is not a single exception, it is a control that no longer updates as fast as the environment changes.
Related resources from NHI Mgmt Group
- What is the difference between an audit exception and a control deficiency in compliance audits?
- What are the signs that a privacy notice is failing as a compliance control?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?