CeFPro Connect

Article
Developing continuous monitoring for oversight processes across contact lifecycle
The objective of continuous monitoring & assurance (CMA) as a tool is to understand any emerging themes or trends to the expected behaviors / outcome of the controls. Thisapproach allows better insights to understand - what are the outliers, understand root cause, identify any systemic theme driving those root cause and help formulate remediation
03/05/2024
Developing continuous monitoring for oversight processes across contact lifecycle

Disclaimer: Opinions are of Samikendra Ghosh, as an individual, not attributed to any particular organization.

Why is continuous monitoring a valuable tool to monitor risks?

The objective of continuous monitoring & assurance (CMA) as a tool is to understand any emerging themes or trends to the expected behaviors / outcome of the controls. This approach allows better insights to understand - what are the outliers, understand root cause, identify any systemic theme driving those root cause and help formulate remediation steps required to bring them back to the expected control outcome. CMA can be done using a wide variety of ways such as using a set of defined measures often called Key Control Indicators to Key risk events against a set threshold being reported periodically or reviewing alerts generated from any surveillance based tools for targeted risk monitoring such as cybersecurity events. Key is to evaluate the functionality and continued relevance for the CMAs as a tool and keep them updated for effective results. Also use of CMA also allows one the opportunity to also keep the monitoring dynamic with agile ways to manage changes. CMA also can influence opportunities to streamline upstream and downstream processes used in the organization throughput the lifecycle of Third Party Management. It services the role of road testing the overall operational and design effectiveness of controls developed in the process.

What are the implications and opportunities of moving from a point in time to continuous monitoring process?

A point in time view does not provide insightful data which can be used for informed decision making and if often limited as reference point to an earlier point in time snapshot and states the net change. Continuous Monitoring & Assurance (CMA) on the other hand is ongoing so data is being captured more periodically and consistently which can narrate a storyline/ identify thematic movements and 

Log in to continue or register for free
WHAT'S INCLUDED:
Unlimited access to peer-contribution articles and insights
Global research and market intelligence reports
Discover iNFRont Magazine, an NFR publication
Panel discussion and presentation recordings