They usually focus on policy documents or point-in-time assessments and miss the ongoing operational work. Regulations in 2025 require continuous classification, lineage tracking, retention enforcement, incident readiness, and evidence generation across changing data environments. If controls are not maintained as systems and regulations evolve, the organisation may look compliant on paper while remaining exposed in practice.
Why one-time compliance projects fail in practice
Compliance becomes fragile the moment teams treat it as a document sprint instead of an operating model. The real work is continuous, because data inventories change, systems are reconfigured, retention periods expire, access paths expand, and evidence has to reflect what is actually running now, not what was true at assessment time.
That gap is where organisations drift into paper compliance. A control can look complete in a review packet while the underlying process has already broken down, especially when classification, lineage, retention, and incident readiness are managed separately rather than as a single living workflow.
Teams also tend to overestimate the durability of the first implementation. Policies age quickly, but operational signals such as audit trails, ownership records, and exception handling need maintenance, or the programme stops describing the environment it is supposed to govern.
- Continuous classification is needed because data does not stay in one risk category.
- Lineage tracking matters because downstream copies and derivatives often outlive the original record.
- Retention enforcement must be monitored, not assumed, because deletions and holds change over time.
- Evidence generation needs to be repeatable so a control can be demonstrated at any point, not only during audits.
What security and privacy teams commonly underestimate
The biggest mistake is confusing control design with control operation. Many teams complete a policy review, assign owners, and pass an assessment, but never verify whether the control still works after product changes, vendor changes, or regulatory updates. Compliance obligations in 2025 are often ongoing precisely because the environment is ongoing.
Another common miss is treating privacy and security as parallel checklists. In practice, data governance, access governance, logging, retention, and incident response are linked. If one area is neglected, the others lose credibility, and the organisation can no longer show that its safeguards reflect current processing.
This is where measurable operational discipline matters more than the existence of a policy. For example, organisations that cannot keep evidence current usually also struggle to prove that data classification, retention rules, and incident response actions are being enforced consistently across all repositories and workflows.
When the question is framed as “are we compliant,” the better practitioner question is “can we prove the control is still working today?” That shift exposes whether the programme has real monitoring, ownership, and escalation, or only a one-time compliance narrative.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV — Oversight | Ongoing compliance requires continual oversight, not one-time sign-off. |
| GV.RM — Risk Management Strategy | Treating compliance as a project creates unmanaged drift in data and control risk. | |
| ID.IM — Improvements | Continuous improvement is needed when regulations, systems, and evidence needs evolve. | |
| Recommendation — Establish recurring oversight checks so compliance evidence and control operation stay current. Embed compliance into recurring risk management so control gaps are reassessed as conditions change. Use lessons from assessments to keep updating controls, evidence, and ownership. | ||
| ISO/IEC 42001:2023 | 9.1 — Monitoring, measurement, analysis and evaluation | A one-time compliance approach fails without ongoing monitoring and evaluation. |
| 10.2 — Nonconformity and corrective action | Operational drift requires corrective action, not just initial certification work. | |
| 8.1 — Operational planning and control | Compliance must be built into operating processes so controls stay active over time. | |
| Recommendation — Measure compliance controls continuously and refresh evidence when the environment changes. Trigger corrective action when controls or evidence no longer match current processing. Run compliance as an operating process with defined ownership and recurring control execution. | ||
| GDPR | Art. 5 — Principles relating to processing of personal data | Continuing compliance depends on ongoing lawful, limited, and accurate processing. |
| Art. 25 — Data protection by design and by default | Compliance must be sustained through design and default settings as systems evolve. | |
| Art. 30 — Records of processing activities | Living records are necessary when classification, lineage, and processing scope change. | |
| Recommendation — Continuously align processing with the core principles of minimisation, limitation, and integrity. Build privacy requirements into the lifecycle so controls persist through change. Keep processing records current so governance evidence matches real-world data flows. | ||
Practitioner Guidance
What to verify: Test whether the compliance control has a living owner, a review cadence, and a current evidence source. If the only proof is a policy, a spreadsheet, or last quarter’s assessment, the control is already stale.
Decision rule: If a requirement affects data location, classification, retention, access, or incident handling, treat it as an operational control with monitoring and revalidation, not a project deliverable that closes after sign-off.
What to measure: Track whether inventories, retention actions, and evidence artifacts are updated after environment changes, not just after audit deadlines. A strong programme can show drift detection and timely correction, not merely historical compliance.
Practitioner takeaway: Compliance fails when it is managed as a snapshot; durable compliance is the ability to keep controls, evidence, and governance aligned as the environment changes.
Related resources from NHI Mgmt Group
- What do teams get wrong when they treat PCI DSS compliance as a one-time project?
- What do organisations get wrong when they treat VCDPA compliance as a one-time privacy project?
- What do teams get wrong when they treat identity verification as a one-time compliance task?
- What do compliance teams get wrong when they treat KYC as a one-time check?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org