Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that a compliance control…
Governance, Ownership & Risk

What are the signs that a compliance control is failing between audits?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Look for policy drift, delayed or missing lineage updates, unexplained access growth, and data quality anomalies that persist longer than they should. Those signals show that the live environment no longer matches the documented control state, even if the last audit looked clean.

What failing controls look like between audits

Between audits, a control usually fails first as drift, not as a loud exception. The clearest warning signs are control evidence that no longer matches reality, exceptions that quietly expand, and monitoring that shows the control is not being exercised at the cadence the policy assumes. In practice, failure is less about one bad event and more about a weakening pattern.

A healthy control leaves a repeatable footprint: approvals happen on time, lineage or ownership is updated when changes occur, and access growth is explainable. When those signals stop lining up, the control may still pass a point-in-time review but it is no longer dependable operationally.

Look especially for the gap between policy intent and daily behaviour. If teams can no longer show timely recertification, accurate inventory, or consistent exception handling, the control state is stale even before the next audit cycle begins.

Why drift, stale lineage, and access growth matter

Control failure is often easiest to spot in the places where governance depends on current truth. Policy drift means documented rules are no longer aligned with how systems are actually run. Delayed or missing lineage updates mean ownership, data flow, or approval paths are no longer trustworthy. Unexplained access growth suggests entitlements are accumulating faster than they are being reviewed.

Data quality anomalies matter for the same reason. If the control relies on accurate records, then persistent anomalies in completeness, consistency, or timeliness are not just data issues, they are evidence that the control environment is losing integrity. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is a useful reference when the problem is really about evidence, governance, and the audit trail behind access and ownership.

These signs matter because they accumulate silently. A control can look compliant at the last checkpoint while the underlying process has already lost discipline, especially when manual exceptions, inherited access, or unmanaged updates become the normal path.

Which signals should trigger investigation first?

The most actionable signals are the ones that show a control has stopped self-correcting. Start with overdue reviews, missing approvals, stale ownership records, and access changes that cannot be tied to a business event. Then check whether anomalies repeat in the same system, team, or control owner, which often indicates a process gap rather than a one-off mistake.

For practitioner triage, the key question is whether the issue is isolated or systemic. One missed update may be clerical. Repeated missed updates, inconsistent evidence, or growth in standing access is a control design problem because it shows the control is no longer keeping pace with change.

When a failure signal persists across more than one review cycle, treat it as evidence of control decay, not an isolated housekeeping issue. At that point the right response is usually to re-baseline the control, not simply to re-run the same checklist.

Risk and Threat Considerations

When controls fail between audits, the main risk is false assurance. The organisation may continue to rely on a control that is only correct in documentation, while the live environment has already diverged. That creates exposure through missed revocations, excessive access, unsupported exceptions, and records that no longer support accountability.

Failure mechanism: Drift accumulates through delayed updates, weak ownership, and inconsistent monitoring, so the control stops enforcing the state the audit expects.

Impact: Undetected exposure can persist for long periods, making it easier for misuse, overreach, or compliance gaps to survive until the next review or an incident forces discovery.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixGRC — Governance, Risk and ComplianceCovers control monitoring, evidence, and audit consistency in cloud governance.
Recommendation — Track control drift and refresh evidence whenever governance state changes.
NIST CSF 2.0GV.OV-01 — Oversight of GovernanceSupports oversight of control effectiveness and ongoing governance monitoring.
Recommendation — Review control performance continuously, not only at audit time.
ISO/IEC 27001:2022A.5.36 — Compliance with policies, rules and standards for information securityAddresses whether operational controls still align with documented policy.
Recommendation — Verify that implemented control behaviour still matches approved policy.
SOC 2 (AICPA)CC4.1 — Monitoring ActivitiesRelevant when assessing whether monitoring catches control failure between reviews.
Recommendation — Monitor control activity continuously and investigate unexplained drift.

Practitioner Guidance

What to prioritise: Focus first on controls whose evidence should change whenever the environment changes, such as access recertification, lineage, approvals, and exception tracking. If those are stale, the control is failing regardless of whether the last audit passed.

What to verify: Compare the documented control state to live records, not just to the last signed-off report. Look for mismatches in ownership, entitlement counts, exception age, and the time it takes to reflect a material change.

Common mistake: Treating a clean audit outcome as proof of ongoing control health. Audits validate a point in time, but between-audit signals tell you whether the control is still operational.

Practitioner takeaway: The strongest indicator of a failing control is not a single exception, it is a control that no longer updates as fast as the environment changes.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org