Solution · Continuous GRC

The certificate lasts three years. The evidence lasts until tomorrow.

Eleven months sit between the first audit and the first surveillance audit. Whatever does not run in that time is missing later — visibly, because evidence carries a date.

The trouble with snapshots

Compliance is usually set up as a project: kickoff, assessment, controls, audit, certificate, relief. Then the team goes back to its real work and the management system stands still.

The first surveillance audit surfaces it. Not because the auditor is severe, but because the evidence gives it away: the access review is from last year, so is the vendor assessment, the internal audit programme was never carried forward. Three nonconformities nobody wanted, each avoidable in two hours.

Continuous GRC does not mean doing more. It means doing the few things on time, and evidencing them while you do.

What keeps running between audits

None of these tasks is large. They are dangerous because they fail invisibly.

  1. 1
    Review access rightsWho has access to what today, and is it still justified. The classic nonconformity, because leavers and role changes fall between reviews.
  2. 2
    Reassess vendorsCritical providers at least annually, looking at certificates, incidents and contract changes. NIS2 makes this an explicit duty.
  3. 3
    Training and awarenessNew staff within a defined period, everyone else on the set cycle. What has to be evidenced is competence, not attendance.
  4. 4
    Test restoresA backup never restored is an assumption. The test belongs in a record, with date, scope and result.
  5. 5
    Internal audit and management reviewThe two clauses organisations actually fail on. Both need a date in the calendar, not an intention.
  6. 6
    Carry risks forwardAfter every significant change and at least once a year. A risk register unchanged for twelve months describes your effort, not your organisation.

How Sightadel carries that

  1. 1
    Every checkpoint has an ownerNot a department, a person. What belongs to nobody does not get done — not cynicism, but the most common cause of expired evidence.
  2. 2
    Every piece of evidence has an expiry dateThe cycle you set becomes the reminder. When evidence expires it surfaces — before the auditor finds it.
  3. 3
    One change reaches every frameworkEvidence is attached to every requirement it serves. You maintain it once, not three times, and it cannot drift into three versions.
  4. 4
    The dashboard shows direction, not percentagesWhat matters is not the headline number but what expired since last month, and who holds it.
Software reminds, it does not do the work. If nobody inside owns it, a tool only moves the moment when that becomes obvious. That is why every setup here starts with ownership rather than with controls.

Fourteen days of trial access, no payment details. Bring your existing spreadsheet — that is where the difference shows fastest.

Book a demo