NovaTerrae NovaTerrae

Continuous Controls Monitoring (CCM)

Internal controls are only as effective as the extent to which they are actually operating as intended. A control that is well-designed but inconsistently applied offers weaker protection than its documentation suggests. Periodic audit testing — testing a sample of transactions once or twice a year — provides a limited window into actual control performance. Between testing cycles, control failures can go undetected for months.

Continuous Controls Monitoring (CCM) addresses this gap directly. By automating the testing of key controls against the full population of transactions in near-real-time, CCM transforms control testing from a periodic sampling exercise into a continuous monitoring capability.

The Limitation of Periodic Control Testing

Traditional control testing has three structural weaknesses:

  • Sample coverage: A typical internal audit samples 25-60 transactions per control test. For a process running 10,000 transactions per month, this represents coverage of 0.08-0.2%. Control failures affecting a small minority of transactions — but potentially high-value ones — may not appear in the sample.
  • Timing lag: By the time a control failure is detected in a quarterly or annual test, it may have been operating for months. The financial, compliance or reputational impact accumulates undetected during that period.
  • Point-in-time snapshot: Control testing confirms that the control operated correctly for the tested transactions. It provides no information about the transactions not tested, and no early warning about deteriorating control performance trends.

How CCM Works

A CCM implementation consists of three layers:

  1. Data connection: CCM reads transaction data from the ERP or source system continuously or at defined intervals — typically daily or in near-real-time for high-risk controls. ERP systems like Business Central store all the transaction data that CCM requires; the challenge is surfacing and analyzing it systematically.
  2. Control rules engine: Each control is expressed as a testable rule. For example: "Every purchase order above €5,000 must have an approval by a user in the Finance Manager role before posting." The rules engine applies this test to every transaction in the population and identifies exceptions — transactions that fail the test.
  3. Exception management: Detected exceptions are categorized by severity, routed to the appropriate control owner with context and tracked through to remediation. Exception trends are reported to internal audit and management, providing a continuously updated view of control performance across the organization.

Which Controls Are Best Suited to CCM

Not all controls are equally suitable for automated monitoring. CCM works best for controls that are:

  • Rule-based: The control logic can be expressed as a clear, testable rule — not requiring human judgment to apply.
  • Data-testable: The evidence of control execution is captured in system data — an approval record, a timestamp, a status field — rather than in a physical document or verbal confirmation.
  • High volume: Controls applied to large numbers of transactions benefit most from automation. The effort of automated testing is essentially constant regardless of transaction volume; the effort of manual testing scales linearly.

Classic CCM candidates in a Business Central environment include:

  • Purchase approval controls (authorization limits by role)
  • Segregation of duties (creator ≠ approver ≠ poster)
  • Three-way matching (PO, goods receipt, invoice within tolerance)
  • Credit limit controls (sales orders against customer credit balances)
  • Vendor master change controls (bank account changes with required approval)
  • Journal entry controls (manual postings with appropriate authorization and supporting reference)

CCM, Continuous Auditing and the Audit Function

CCM changes the role of internal audit from periodic tester to continuous overseer. When controls are monitored automatically, the internal audit function can focus on:

  • Reviewing exception trends and patterns rather than testing individual transactions
  • Assessing the design adequacy of controls rather than their operating effectiveness (which CCM monitors continuously)
  • Investigating significant exceptions in depth
  • Expanding coverage to processes and risk areas that previously received no audit attention due to resource constraints

The result is a higher-value audit function that provides better risk coverage with the same or fewer resources — addressing audit fatigue by shifting effort from routine testing to genuine risk analysis.

CCM and Regulatory Compliance

Regulators and standard-setters increasingly expect organizations to demonstrate continuous, not periodic, compliance. CCM provides the evidence base for this:

  • SOX: CCM enables organizations to provide population-level evidence of control effectiveness rather than sample-based assertions — strengthening the quality of management's assessment under Section 302 and Section 404.
  • NIS2: Continuous monitoring of security-relevant process controls directly addresses NIS2's requirement for ongoing detection and response capabilities.
  • ISO 27001: CCM contributes to the continuous monitoring requirements of the information security management system, particularly for controls governing access to sensitive ERP data.

Related Concepts

Want to apply this in Business Central?

Request a free Quick Scan — we analyse your specific processes and respond within 24 hours.

GDPR compliant · No spam · Privacy statement

From periodic sampling to continuous control coverage

Automated process monitoring and audit trail natively in Business Central — the foundation for CCM without external tooling.

Continuous Auditing →