Skip to main content
Category: Controls Management

Monitor

Simply put

A monitor is a person or device that watches or checks to see that something is going well, usually for a specific purpose. As a verb, to monitor means to watch, keep track of, or check on something over time. The term also refers to a computer output device that displays text, images, and video on a screen.

Formal definition

In general usage, a monitor denotes a person or instrument that observes, tracks, or checks a subject for a defined purpose, or the corresponding verb 'to monitor,' meaning to watch, keep track of, or check something on an ongoing basis. In computing, a monitor is an output device that displays information such as text, pictures, and video on a screen. The evidence provided supports only these general-language and computing senses; it does not establish a GRC-specific definition for this term.

Why it matters

The term "monitor" appears frequently across governance, risk, and compliance discussions, but the evidence supporting this entry establishes only its general-language and computing senses: a person or device that watches or checks that something is proceeding well, the verb meaning to watch or track something over time, and a computer output device that displays information on a screen. Practitioners encountering the word in GRC contexts should be aware that this entry does not supply a GRC-specific technical definition, and any specialized meaning would need to be sourced from the relevant framework, standard, or regulatory text where it is used.

Who it's relevant to

General readers
Readers seeking the plain meaning of "monitor" will find it denotes a person or device that watches or checks that something is going well, or the act of watching and tracking something over time.
Anyone referencing computing terminology
In a computing context, the term refers to an output device that displays text, images, and video on a screen.
GRC practitioners
Compliance officers, risk managers, and auditors should note that the evidence supporting this entry does not establish a GRC-specific definition. Where "monitor" or "monitoring" carries a specialized meaning within a particular framework, standard, or regulation, practitioners should consult that source directly rather than rely on the general-language sense described here.

Inside Monitor

Monitoring activities
Ongoing or periodic evaluations, or a combination of both, used to ascertain whether components of a governance, risk, or compliance framework are present and functioning as intended. In many control frameworks these span routine, embedded checks and separate, more independent evaluations.
Ongoing (continuous) monitoring
Monitoring built into normal operations, often performed by process owners in the first line, that provides near real-time or frequent signals about the operation of controls and the status of risks.
Separate evaluations
Periodic assessments conducted with a degree of independence from the process being examined, which may be performed by second line functions such as compliance or risk, or by third line internal audit, depending on the objectivity required.
Key indicators and thresholds
Metrics such as key risk indicators or key control indicators, together with defined thresholds or tolerances, that help determine when a monitored condition warrants attention or escalation. Thresholds commonly relate back to stated risk appetite and tolerance.
Reporting and escalation
The channels and cadence through which monitoring results are communicated to management, governance bodies, or oversight functions, and the criteria for escalating deficiencies or exceptions for remediation.
Remediation tracking
The follow-up on identified deficiencies, including recording issues, assigning ownership, and confirming whether corrective actions were completed and effective.

Common questions

Answers to the questions practitioners most commonly ask about Monitor.

Is monitoring the same as auditing?
No. Monitoring is generally an ongoing management activity embedded in day-to-day operations, typically performed by the first and second lines to track whether controls are operating and whether risk and compliance conditions remain within expected parameters. Auditing, by contrast, is a periodic assurance activity carried out by an independent, objective function such as internal audit (commonly associated with the third line in the IIA's three lines model). The defining difference is independence and objectivity: monitoring supports management in running processes, whereas auditing provides assurance over those processes and the monitoring itself. Conflating the two can undermine the independence expected of assurance functions.
Does continuous monitoring guarantee that risks and control failures will be detected?
No. Monitoring, including automated or continuous monitoring, may improve the timeliness and coverage of detection, but it does not guarantee that every issue will be identified. Its effectiveness depends on the design and scope of what is being monitored, the quality of the underlying data, the thresholds and indicators selected, and the response to what is observed. Monitoring commonly reduces the likelihood that issues go undetected, but qualified language is appropriate: it mitigates rather than eliminates the possibility of undetected failures.
Who is typically responsible for monitoring activities within an organization?
Responsibility often depends on the type of monitoring and the organization's operating model. In many organizations aligned to the three lines model, first-line operational functions monitor the controls they own as part of executing their processes, while second-line functions such as risk management and compliance may perform independent-of-the-first-line monitoring and oversight of those activities. Assurance over the overall system, including monitoring, is commonly provided separately by internal audit. Roles and terminology vary across frameworks, jurisdictions, and organization size.
What should be monitored, and how are the subjects of monitoring selected?
The scope of monitoring commonly includes the operation and effectiveness of controls, changes in risk conditions, and adherence to applicable laws, regulations, and internal policies. Selection is typically risk-based, focusing effort where the potential impact on objectives is greatest and where control failures would be most consequential. Indicators, metrics, and thresholds are often defined in advance so that observed results can be compared against expected parameters. This entry does not prescribe specific metrics or tooling, as appropriate choices vary by context.
How often should monitoring be performed?
Frequency generally varies with the nature of the process, the level of risk, and the rate at which conditions change. Some monitoring is performed on a continuous or near-continuous basis, particularly where automation supports it, while other monitoring may be periodic. Higher-risk areas commonly warrant more frequent monitoring. There is no single universal cadence; the appropriate frequency depends on the organization, its objectives, and applicable requirements.
How does monitoring connect to reporting and escalation?
Monitoring typically produces information that informs governance oversight, management decision-making, and, where relevant, demonstration of compliance. Results are commonly reported to appropriate levels, and predefined thresholds or triggers may drive escalation when observations fall outside expected parameters. The value of monitoring depends significantly on whether its outputs lead to timely response and corrective action; monitoring without an effective response mechanism provides limited benefit. This entry does not cover specific reporting formats or escalation procedures, which vary by organization.

Common misconceptions

Monitoring and auditing are the same activity.
Monitoring is typically a management activity that may be embedded in operations, whereas auditing is an assurance activity performed with independence and objectivity. Confusing the two can undermine the independence expected of third line internal audit; monitoring by process owners does not substitute for independent assurance.
Continuous monitoring guarantees that risks are controlled and problems will be caught.
Monitoring provides information about whether controls appear to be operating and whether conditions have changed, but it does not guarantee outcomes. Its usefulness depends on the design of indicators, the completeness of data, and the responsiveness of escalation and remediation processes.
Monitoring belongs to a single pillar of GRC.
Monitoring spans governance, risk management, and compliance. Governance bodies rely on monitoring information for oversight, risk functions monitor exposures against appetite and tolerance, and compliance functions monitor adherence to laws, regulations, and internal policies. The specific object of monitoring differs by pillar.

Best practices

Define what is being monitored and align indicators and thresholds explicitly to the organization's stated risk appetite and tolerance rather than to arbitrary levels.
Preserve the independence of assurance functions by distinguishing management monitoring performed in the first and second lines from separate evaluations performed by third line internal audit.
Combine ongoing monitoring embedded in operations with periodic separate evaluations, so that routine signals are complemented by more objective, less frequent assessments.
Establish clear escalation criteria and reporting cadence so that exceptions and deficiencies reach the appropriate management or governance level in a timely manner.
Track identified deficiencies through to remediation, assigning ownership and confirming whether corrective actions were completed and effective.
Tailor monitoring scope and frequency to the applicable jurisdiction, sector, and organization size, recognizing that obligations and expectations may differ across contexts.
Application Security Isn’t Optional Anymore.