Answers to the questions practitioners most commonly ask about Monitor.
Is monitoring the same as auditing?
No. Monitoring is generally an ongoing management activity embedded in day-to-day operations, typically performed by the first and second lines to track whether controls are operating and whether risk and compliance conditions remain within expected parameters. Auditing, by contrast, is a periodic assurance activity carried out by an independent, objective function such as internal audit (commonly associated with the third line in the IIA's three lines model). The defining difference is independence and objectivity: monitoring supports management in running processes, whereas auditing provides assurance over those processes and the monitoring itself. Conflating the two can undermine the independence expected of assurance functions.
Does continuous monitoring guarantee that risks and control failures will be detected?
No. Monitoring, including automated or continuous monitoring, may improve the timeliness and coverage of detection, but it does not guarantee that every issue will be identified. Its effectiveness depends on the design and scope of what is being monitored, the quality of the underlying data, the thresholds and indicators selected, and the response to what is observed. Monitoring commonly reduces the likelihood that issues go undetected, but qualified language is appropriate: it mitigates rather than eliminates the possibility of undetected failures.
Who is typically responsible for monitoring activities within an organization?
Responsibility often depends on the type of monitoring and the organization's operating model. In many organizations aligned to the three lines model, first-line operational functions monitor the controls they own as part of executing their processes, while second-line functions such as risk management and compliance may perform independent-of-the-first-line monitoring and oversight of those activities. Assurance over the overall system, including monitoring, is commonly provided separately by internal audit. Roles and terminology vary across frameworks, jurisdictions, and organization size.
What should be monitored, and how are the subjects of monitoring selected?
The scope of monitoring commonly includes the operation and effectiveness of controls, changes in risk conditions, and adherence to applicable laws, regulations, and internal policies. Selection is typically risk-based, focusing effort where the potential impact on objectives is greatest and where control failures would be most consequential. Indicators, metrics, and thresholds are often defined in advance so that observed results can be compared against expected parameters. This entry does not prescribe specific metrics or tooling, as appropriate choices vary by context.
How often should monitoring be performed?
Frequency generally varies with the nature of the process, the level of risk, and the rate at which conditions change. Some monitoring is performed on a continuous or near-continuous basis, particularly where automation supports it, while other monitoring may be periodic. Higher-risk areas commonly warrant more frequent monitoring. There is no single universal cadence; the appropriate frequency depends on the organization, its objectives, and applicable requirements.
How does monitoring connect to reporting and escalation?
Monitoring typically produces information that informs governance oversight, management decision-making, and, where relevant, demonstration of compliance. Results are commonly reported to appropriate levels, and predefined thresholds or triggers may drive escalation when observations fall outside expected parameters. The value of monitoring depends significantly on whether its outputs lead to timely response and corrective action; monitoring without an effective response mechanism provides limited benefit. This entry does not cover specific reporting formats or escalation procedures, which vary by organization.