Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do quarterly attestations and screenshots fail modern…
Governance, Ownership & Risk

Why do quarterly attestations and screenshots fail modern compliance reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They fail because they show a point in time, not continuous control operation. Regulators and auditors increasingly need evidence that the control worked during the period the business used it. A quarterly artifact cannot explain what happened after the snapshot, when risk and ownership may already have shifted.

Why point-in-time evidence breaks under continuous-control expectations

Quarterly attestations and screenshots are snapshots, not proof of sustained operation. They can show that a control existed on a given date, but they do not prove it stayed effective between reviews, that exceptions were handled, or that ownership remained current when systems, roles, or vendors changed.

modern compliance reviews care about whether the control worked for the period being assessed. If access, configuration, or approvals drift after the screenshot, the artifact becomes historical context rather than defensible evidence of control performance.

What auditors are actually trying to validate

The review question has shifted from “Was there a control?” to “Did the control operate as designed, with evidence of use, exception handling, and timely correction?” That means auditors want operational traces such as logs, workflow records, approval trails, recertification outputs, and dated remediation evidence, not just a captured screen.

When a control is tied to access, configuration, or authorization, a single attestation rarely covers the full lifecycle of the risk. Good evidence shows the control’s operating cadence, the thresholds that trigger escalation, and the record of who reviewed and changed what during the period.

Why screenshots often create false confidence

Screenshots are easy to collect and easy to overtrust. They compress a dynamic process into a static image, which hides whether the underlying system is still configured the same way, whether the reviewer had sufficient context, and whether the control was bypassed outside the review window.

They also invite performative compliance. Teams optimize for the artifact, not the control, which encourages late-stage evidence gathering instead of building evidence that is produced naturally by the process itself. That is why continuous evidence is increasingly preferred over manually assembled proof.

Risk and Threat Considerations

Point-in-time evidence can mask control decay, especially where privileges, system ownership, or third-party access change frequently. The risk is not only audit failure, but also undetected exposure during the gap between review cycles.

Failure mechanism: A control that looks sound in a quarterly packet may have drifted, expired, or been overridden days later, while the evidence still implies compliance.

Impact: Organizations can miss excessive access, stale approvals, or unremediated exceptions until an auditor, incident, or regulator forces a deeper look.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-03 — Results of cybersecurity risk management activities are used to inform decisionsQuarterly evidence must support ongoing assurance decisions, not just a moment-in-time check.
Recommendation — Use ongoing control evidence to inform assurance decisions between review cycles.
NIST SP 800-53 Rev 5AU-2 — Event LoggingContinuous evidence depends on logged activity that shows control operation over time.
Recommendation — Log control-relevant events so operation can be verified across the review period.
ISO/IEC 27001:2022A.5.36 — Compliance with policies, rules and standards for information securityCompliance reviews need evidence that controls were followed continuously, not only at audit time.
Recommendation — Retain evidence that controls were followed throughout the assessment period.
SOC 2 (AICPA)CC2.1 — Commitment to Integrity and Ethical ValuesSOC 2 evidence must show control culture and operation over time, not a quarterly snapshot.
Recommendation — Demonstrate that control operation is sustained across the reporting period.
CIS Controls v8CIS-8 — Audit Log ManagementAudit-grade evidence is stronger when derived from logs and time-stamped records instead of screenshots.
Recommendation — Collect time-stamped records that show control activity over the full period.

Practitioner Guidance

What to verify: Test whether the evidence is generated by the control itself, not assembled after the fact. If a reviewer can only prove compliance by rebuilding the story from screenshots and email chains, the evidence model is too weak for modern assurance.

What good looks like: The control leaves a repeatable trail that shows operation over time, including timestamps, reviewer identity, exception disposition, and remediation closure. For access and approval controls, the strongest evidence usually comes from workflow, logging, and change history rather than a static image.

Decision rule: If the business, system, or permission set can change materially within the review period, treat quarterly attestation as supporting context only and require time-based operational evidence as the primary artifact.

Practitioner takeaway: The goal is not to eliminate attestations, but to demote them from proof of control to one piece of supporting evidence in a broader, continuous assurance model.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org