Join our Newsletter — 33% off our NHI Course
Home FAQ Foundations & NHI Taxonomy What are the signs that manual COI tracking…
Foundations & NHI Taxonomy

What are the signs that manual COI tracking is failing compliance teams?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Foundations & NHI Taxonomy

Manual tracking tends to fail when questionnaire progress is hard to monitor, completion rates lag, and follow-up work is left to memory or spreadsheets. Paper-based processes also create human error and weak real-time visibility. If reported conflicts are not reviewed continuously, small issues can linger until they become misconduct, audit findings, or regulatory concerns.

How manual COI tracking starts to break down

Manual conflict-of-interest tracking usually fails at the point where the process stops being actively managed and starts being reconstructed from memory. Once questionnaire status is spread across inboxes, spreadsheets, and paper files, teams lose a reliable view of who has responded, who still needs follow-up, and which disclosures require review before work continues.

The operational sign is not just slowness, but loss of control over the workflow itself. When completion rates lag, reviewers cannot tell whether delays reflect normal backlog, missing responses, or unresolved conflicts. That ambiguity makes it hard to triage cases consistently, especially when the process depends on individuals remembering to chase updates rather than the system surfacing gaps in real time.

Manual methods also make the quality of the underlying record degrade over time. Paper-based routing, rekeying, and spreadsheet edits create avoidable errors, while status fields and timestamps become stale quickly if nobody is continuously reconciling them. Audit and governance expectations become harder to meet when the team cannot produce a clean, current trail of disclosures, reviews, and decisions.

What the warning signs look like in practice

The most useful warning signs are usually visible in the workflow before they become visible in the audit. Watch for questionnaires that sit incomplete without clear ownership, repeated manual follow-ups for the same people, inconsistent treatment of similar disclosures, and a growing gap between reported conflicts and documented review outcomes.

Another common signal is that the process only appears to work when a small number of people are personally overseeing it. If coverage depends on tribal knowledge, saved email threads, or a spreadsheet maintained by one coordinator, the control is fragile. That fragility becomes more obvious during leave, turnover, quarter-end pressure, or any period when volume spikes and informal memory no longer scales.

Real-time visibility is the dividing line. Visibility into identity and access governance is a recurring control theme in compliance work, and the same principle applies here: if a team cannot immediately answer who has completed disclosure, who is overdue, and which items are still open, the process is already slipping from control to exception handling.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-8 — Audit Log ManagementCOI tracking needs a reliable audit trail for disclosure and review activity.
Recommendation — Maintain tamper-resistant logs for disclosure, review, and escalation events.
NIST CSF 2.0GV.RM-05 — Risk Management StrategyManual COI tracking fails when unresolved conflicts are not surfaced and managed as business risk.
Recommendation — Embed COI review into the organisation's risk management process.
ISO/IEC 42001:2023A.5.4 — AI system lifecycle managementLifecycle governance logic applies to controlled review workflows that need traceability and accountability.
Recommendation — Define accountable ownership and review checkpoints for each disclosure workflow stage.

Practitioner Guidance

What to verify: Confirm whether the team can produce a current status view without manual reconstruction. If progress, approvals, and exceptions cannot be shown from one source of truth, the process is already too dependent on memory and cleanup work.

What to prioritise: Focus first on bottlenecks that hide risk, not just the backlog count. A small number of unresolved or unreviewed disclosures can matter more than a large number of low-risk open questionnaires if those unresolved items are the ones most likely to create misconduct, audit, or regulatory exposure.

Common mistake: Treating spreadsheet completion as control completion. A spreadsheet can record that a form was sent or returned, but it does not prove continuous review, timely escalation, or consistent treatment of conflicting disclosures.

Practitioner takeaway: Manual COI tracking fails when the team can no longer distinguish active control from administrative appearance; the key test is whether the process still gives timely visibility into unresolved risk, not whether forms are merely collected.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org