,

Continuous Auditing vs Continuous Monitoring: How to Build

The two terms get used as synonyms in vendor decks and audit committee papers, and the confusion has a cost. When internal audit builds a duplicate-payment alert, routes it to accounts payable, and chases the exceptions itself, it has built a control and become part of the first line, which is the one thing the independence standards say it cannot be. When management calls its exception dashboard “continuous auditing,” it has claimed assurance it does not have. The difference is not the technology, which is identical, or the rules, which overlap heavily. It is who owns the output and what happens when an alert fires. Continuous monitoring is management’s control, operated by management, that catches and corrects exceptions as they happen. Continuous auditing is internal audit’s procedure, operated by internal audit, that tests whether the process and its controls, including the monitoring, are working, on a cadence closer to the transactions than an annual engagement allows.

This guide draws the line precisely and then shows how to build each side of it: a twelve-dimension comparison, the independence rules that keep continuous auditing from turning into a control, the architecture both share, a catalog of 22 rules with logic and thresholds across purchase-to-pay, payroll, the general ledger, access, and expenses, a phased implementation roadmap, a worked duplicate-payment implementation at MidState Beverage with real alert volumes and false-positive rates, an alert governance table, and what continuous auditing does to the annual plan and to sampling. It was rewritten in September 2026 to reflect the Global Internal Audit Standards and current tooling. The site’s separate deep dives on continuous auditing and continuous monitoring go further into each; this guide is the one to read first.

In this guide

The distinction, in twelve dimensions

DimensionContinuous monitoring (CM)Continuous auditing (CA)
OwnerManagement: the process owner or a second-line functionInternal audit
PurposeDetect and correct exceptions in the process as they occur; a detective controlObtain evidence, at a higher frequency than an annual engagement, that controls and the process are operating; an audit procedure
Position in the three linesFirst line (process owner) or second line (risk, compliance, finance)Third line
What an alert meansSomething needs fixing now: a duplicate to block, an unapproved change to reverseSomething to test: an exception rate to evaluate, a control to conclude on, a finding to consider
Who acts on an alertThe process owner, with a service levelThe auditor, who evaluates and reports; the auditor does not fix
FrequencyReal-time to daily, tied to the process cycleWeekly to quarterly, tied to the audit’s need for evidence over a period
OutputException queue, corrective actions, management metricsTest results, control conclusions, findings, changes to the audit plan
Evidence useThe monitoring log is evidence that the control operatedThe audit’s results are evidence that management’s controls, including CM, work
ThresholdsTuned by management for operational tolerance and workloadSet by audit for risk; often tighter than management’s, and audit tests management’s threshold as a design question
Scope over timeStable: the same rules run every day on the same processRotating: rules change with the plan and the risk assessment; some run all year, some for a quarter
Independence effectNone; it is management’s activityMust be preserved: audit tests, reports, and does not own the exception queue
What it replacesManual after-the-fact review controls, with far better coverageSome sample-based testing in the annual engagement; never the engagement itself

The row that decides most arguments is “who acts on an alert.” If the answer is the process owner, it is monitoring, whoever wrote the rule. If the answer is the auditor, and the auditor’s action is to evaluate and report rather than to fix, it is auditing. Where the answer is that the auditor chases the process owner to fix it, the function has drifted into the first line and needs to hand the rule over.

Why the distinction matters: independence and the three lines

The Global Internal Audit Standards require internal audit to be independent of the activities it audits and require auditors to avoid assuming management responsibilities; the IIA’s Three Lines Model puts operating controls in the first line and assurance over them in the third. An alert that management relies on to catch duplicate payments is a control, and a function that runs it, tunes it, and works the queue has designed and operated a control it will later be asked to give assurance on. The practical consequences arrive within a year: the function cannot audit the process because it owns part of it, the external auditor cannot rely on the function’s work in that area, and management stops building its own monitoring because audit is doing it.

Four rules keep continuous auditing on the right side of the line. Audit builds rules for audit’s purposes and reports the results; it does not own an exception queue that management is waiting on. When a rule proves so useful that management wants it as a control, audit hands it over, documented, and then tests it as management’s control, which is the best possible outcome and is how most mature monitoring programs began. Audit’s rules and thresholds are its own and may differ from management’s, because audit is asking a risk question, not an operational one. And every alert audit acts on becomes an evaluated exception in a workpaper, with a conclusion, not a ticket for someone to fix. The Domain II guide covers the objectivity standards behind those rules.

Advisory work is the honest exception. A function may help management design its monitoring as an advisory engagement, with the boundaries the Domain III guide describes: management makes the decisions, owns the result, and the function does not audit its own design for a period. The “we built it, so we know it works” argument is the one to refuse.

The shared architecture

Both sides run on the same five components, and a function that understands them can evaluate a vendor’s platform or build its own in a database and a scheduler. What differs between CM and CA is the owner of each component and the retention rules, not the design.

ComponentWhat it doesDesign questionsCM ownerCA owner
Data accessExtracts or reads the transaction, master, and log data the rules needDirect read on the ERP, a replicated reporting database, or scheduled extracts? What latency? Who controls the extract logic, and is the extract complete? (The completeness and accuracy of the feed is an IPE question for every rule built on it)IT, for the process ownerAudit’s own extract, or a read replica audit can query independently
Rules engineApplies the logic: matches, thresholds, comparisons across sources, statistical outliersSQL and a scheduler, a BI tool, a scripting language, or a platform? Who can change a rule, and is the change logged? Are rules versioned so that an alert can be traced to the logic that produced it?Second line or IT, under change controlAudit, under audit’s own change control
Alert workflowRoutes each alert to an owner, records the disposition, tracks the service levelTicketing system, workflow tool, or a shared queue? What are the disposition codes? Can an alert be closed without a reason?Process owner, with second-line oversightAudit’s workpaper, not a queue: each alert is evaluated and concluded on
Evidence retentionKeeps the alert, the data it fired on, the disposition, and who did whatHow long? Immutable? Can the retained alert be reproduced from the retained data and rule version?Management, to the record-retention policy; audit tests itAudit, to the workpaper retention standard
ReportingMetrics: alert volumes, false-positive rates, time to disposition, trends by unitWho sees which cut? Does the report distinguish alerts closed with action from alerts closed as false positive?Management information; second line to the risk committeeAudit to the audit committee, as results and as coverage

The data-access component is where most programs are weaker than they look. A rule is only as good as the feed, and a feed that drops a subsidiary, a document type, or the last day of the month produces confident silence. Every rule in the catalog below carries an implicit first test: reconcile the feed to a control total before trusting a zero-alert day. The ITGC primer covers the change and access controls the rules engine itself needs, because a rule anyone can edit is a control nobody can rely on.

The rule catalog: 22 rules with logic and thresholds

Each rule below states the logic in words a data owner can implement, a starting threshold, and the risk it addresses. The “CM or CA” column says where the rule most naturally lives; several belong in both, with management running it daily as a control and audit running it quarterly to test that management’s version is catching what it should. Thresholds are starting points to be tuned against the first month’s alert volume; the tuning method is in the worked example. The domain guides on accounts payable analytics, payroll analytics, and journal entry analytics carry the full catalogs from which these were drawn.

#DomainRuleLogicStarting thresholdRiskCM or CA
1P2PExact duplicate invoiceSame vendor, same invoice number, same amount, within 365 days, either not cancelledAny matchDuplicate paymentCM daily; CA quarterly
2P2PFuzzy duplicate invoiceSame vendor, same amount, invoice numbers differing only by punctuation, leading zeros, or one character; or same invoice number and amount across two vendor IDs with matching bank account or addressAmount over $500Duplicate payment; duplicate vendorCM daily; CA quarterly
3P2PInvoice paid without PO where PO is requiredInvoice with no PO reference where the vendor category or amount requires one per policyAmount over $2,500Unauthorized purchaseCM weekly
4P2PPrice variance within tolerance but material in aggregateInvoice unit price above PO unit price, summed by vendor per quarterVendor total over $5,000 or over 2 percent of vendor spendOverbilling under the match toleranceCA quarterly
5P2PVendor master change followed by paymentBank account or address changed, then a payment to the vendor within 14 daysAny, for bank changesPayment diversionCM daily
6P2PVendor–employee matchVendor bank account, address, or phone matches an employee master recordAny matchFictitious vendorCA quarterly; CM monthly where tooling allows
7P2PSplit purchasesTwo or more POs to the same vendor by the same requester within 3 days whose sum exceeds the requester’s approval limit while each is below itSum over the limitApproval circumventionCA monthly
8P2PPayment run released outside dual controlPayment file uploaded and released by the same user, or released outside business hoursAnyUnauthorized paymentCM daily
9PayrollGhost employee indicatorsActive employee with no time entries, no badge events, and no benefits deductions for 60 days; or two employees sharing a bank accountAnyFictitious or departed employee paidCA monthly
10PayrollTermination after last payPayment dated after the termination date plus one pay cycleAnyOverpayment after leavingCM per pay run
11PayrollPay rate change without approvalRate changed by a user without HR approval role, or self-changedAnyUnauthorized payCM per pay run
12PayrollOvertime outliersOvertime hours above 2.5 standard deviations from the employee’s own 12-week mean and above the department’s 90th percentileBoth conditionsTime inflation; supervisory failureCA monthly
13GLManual journals by non-finance usersJournal posted by a user whose role is not in the finance role setAnyAccess; unauthorized entriesCM weekly
14GLRound-amount journals near period-endManual journals in the last 3 days of the period with amounts divisible by 1,000 and above a floorAmount over $10,000Management override; estimates without supportCA quarterly
15GLSelf-approved journalsPreparer equals approver, or approver lacks the approval roleAnySegregationCM weekly
16GLSuspense and clearing account agingBalance items older than 60 days in clearing accountsItem over $1,000 or account total over $25,000Unreconciled differences hiddenCM monthly; CA quarterly
17AccessTerminated user with active accountHR termination date passed; account status active in any in-scope systemAny, after 1 business dayUnauthorized accessCM daily
18AccessSegregation conflict createdRole assignment that creates a conflict in the SoD matrixAnySegregationCM at provisioning; CA quarterly full re-run
19AccessPrivileged account activity outside change windowsAdministrative or firefighter account used outside an approved change ticket windowAnyUnauthorized changeCM daily
20T&EDuplicate expense claimsSame employee, same amount, same merchant within 30 days; or same receipt image hash on two claimsAmount over $25Duplicate reimbursementCM per claim
21T&EJust-under-threshold receiptsClaims between 90 and 100 percent of the receipt-required threshold, by employee per quarterEmployee with 4 or moreThreshold gamingCA quarterly
22T&ESelf-approved or manager-approved own claimsClaim approved by the claimant, or approver’s own claim approved by a subordinateAnySegregation; collusionCM per claim

Rules 1, 5, 8, 10, 17, and 22 are the six a function should expect management to run as controls, and where management does not, the absence is the finding, not the rule audit builds to fill it. Rules 4, 7, 9, 12, 14, and 21 are the ones that belong to audit, because they ask risk questions management has little incentive to ask of itself. The ERP SoD analysis guide and the user access review guide cover the access rules in depth, including why a quarterly full re-run by audit is not redundant with a daily provisioning check.

Implementation roadmap

The roadmap below is for internal audit building continuous auditing, with notes on where a management continuous-monitoring program differs. The timescale assumes a function with one person who can write SQL or use a query tool and a data owner who will provide extracts; a platform shortens the build and lengthens the procurement.

PhaseWeeksWorkDeliverablePitfall
1. Select the domain and the rules1–2Pick one process with high transaction volume, a clean data source, and a risk on the annual assessment; choose 5 to 8 rules from the catalogRule specification: logic, threshold, data fields, owner, frequency, what an alert meansStarting with twenty rules across five processes; nothing gets tuned
2. Secure the data2–5Agree the extract or read access with IT; document fields, period, and refresh; reconcile the first extract to control totalsData feed with a completeness check that runs every refreshAccepting a feed without a reconciliation; discovering in month three that credit memos were excluded
3. Build and back-test4–8Implement the rules; run them on 12 months of history; evaluate every alert in the back-test to learn the false-positive rate and tune thresholdsBack-test results: alert volume, confirmed exceptions, false-positive rate, tuned thresholds, per ruleGoing live on untested thresholds and drowning in alerts
4. Define the evaluation procedure6–8For each rule, write what the auditor does with an alert: evidence to inspect, exception definition, conclusion options, workpaper formatEvaluation procedures in the work program; workpaper templateTreating alerts as tickets to chase instead of tests to conclude on
5. Go live on a cadence9–12Run the rules on the agreed cadence; evaluate; report the first quarter’s results to the CAE and then the committeeQuarterly CA results: coverage, exceptions, findings, plan changesRunning daily because the tool can; audit does not need daily
6. Hand over what management should own12–20Rules that are catching operational exceptions management should be catching become a finding and then, if management adopts them, a control audit testsHandover document; management’s monitoring under change control; audit’s test of itKeeping the rule because it is audit’s favorite
7. Expand20+Next domain; retire rules that have produced no exceptions in four quarters or convert them to annual analyticsRule inventory with retirement datesRules accumulating forever

For a management monitoring program, phases 1 to 3 are the same, phase 4 becomes the disposition procedure with service levels (below), phase 5 runs at the process cadence, and phase 6 does not exist because management owns it from the start. Internal audit’s role in a management program is phase 3’s challenge, the design test of the thresholds, and the operating test of the dispositions; the management review controls guide treats a monitoring dashboard as the review control it is.

Worked example: duplicate-payment monitoring at MidState Beverage

MidState Beverage is the site’s running example: a three-state distributor with 12 depots, a 2013 ERP, two acquired distributors on their own systems, a lean finance team, and a six-person audit function. In FY27 the function built rules 1, 2, 4, and 5 from the catalog as continuous auditing over accounts payable, after the ICFR support engagement found that the ERP’s duplicate-invoice check matched on vendor and invoice number only and that nobody reviewed within-tolerance price variances. The numbers below are the first two quarters.

The data: the AP invoice table and the vendor master, extracted weekly from a reporting replica by a query the audit senior owned, with a completeness check that reconciled the extract’s invoice count and value to the ERP’s AP register totals for the week; two weeks in the first quarter failed the check because a depot’s batch posted late, and both were re-extracted before the rules ran. Annual volume: 41,600 invoices, $118 million. The back-test on twelve months of history produced the thresholds.

RuleBack-test alerts (12 months)Confirmed exceptionsFalse-positive rateTuning appliedLive alerts, Q1–Q2Confirmed, Q1–Q2
1. Exact duplicate619 (all already caught by AP before payment)85 percent (recurring monthly invoices with the same number and amount by design)Exclude vendors flagged as recurring-billing; require both invoices posted, not cancelled72 (one paid twice, $4,180, recovered)
2. Fuzzy duplicate4182394 percentRaise floor to $500; require bank account or address match for cross-vendor pairs; add invoice-date within 45 days386 (three paid twice, $11,940 total, all recovered; three blocked before payment by AP after the alert was shared as a finding)
4. Price variance in aggregateNot applicable (quarterly aggregate)Vendor threshold set at $5,000 or 2 percent of vendor spend, whichever is lower14 vendors4 vendors overbilling on contract prices, $27,300 recovered; one vendor’s freight terms renegotiated
5. Vendor bank change then payment520 (all legitimate, all approved)100 percentKept as a CA rule for one more quarter, then handed to AP as a control with a call-back requirement110; rule handed over in Q2

Three things about that table are the lesson. The back-test is where the false-positive rate is learned, and the exact-duplicate rule’s 85 percent false-positive rate was entirely explained by recurring-billing vendors, which one exclusion fixed. The fuzzy rule needed three tuning steps, and its live false-positive rate of 84 percent is still high, which is acceptable for a quarterly audit rule evaluated by an auditor and would be unacceptable for a daily management control worked by a clerk. And rule 5 produced nothing in eighteen months, which is a good result and the right reason to hand it to management: the risk is real, the control belongs in the first line, and audit tests it once a year.

What happened to the results is the independence lesson. The $16,120 of duplicates and the $27,300 of overbilling went into a finding on the AP duplicate-check configuration and the within-tolerance variance review, with the recoveries reported as management’s. AP adopted rules 1 and 2 as a daily control in Q3, with a disposition procedure and a service level; audit retired its weekly run of both and replaced it with a quarterly re-run against the whole population to test that AP’s version was catching what it should. Audit kept rule 4, because a quarterly aggregate is an audit question. The accounts payable audit guide has the full risk catalog that rules 1 to 8 were selected from, and the vendor master audit guide the tests behind rules 5 and 6.

What the auditor does with an alert

The evaluation procedure is what makes a continuous-audit alert an audit result rather than a ticket. For the fuzzy-duplicate rule at MidState it read: for each alert, inspect both invoice images and the purchase orders; establish whether the invoices are for the same goods or services (same PO line, same delivery reference, or same service period); if they are, establish whether both were paid, and if both were paid, whether AP’s own check could have caught it and why it did not; record the disposition as duplicate paid, duplicate blocked, or not a duplicate with the reason; and conclude quarterly on the AP duplicate control by comparing what the rule found with what AP’s check found. The workpaper for the quarter listed all 38 alerts with dispositions, the six confirmed duplicates with amounts and recovery status, and one conclusion: the ERP duplicate check, matching on vendor and invoice number only, did not detect three paid duplicates totaling $11,940 in which the invoice numbers differed by a suffix, and is not designed effectively for that pattern. That sentence became the condition of a finding. The recoveries were AP’s work, initiated from the finding, and were reported as management’s action; audit did not call the vendors.

A false positive is also a result. The 32 alerts that were not duplicates were classified by reason (recurring billing, credit and re-bill pairs, legitimate split deliveries, and data-entry corrections), and the reasons drove the next round of tuning. An evaluation procedure that records only the hits cannot improve the rule; one that records the misses by reason can, and it produces the false-positive analysis the committee will ask about when it hears that 84 percent of alerts were not exceptions.

Alert governance: triage, ownership, service levels

A monitoring program without alert governance is a dashboard, and dashboards do not prevent anything. The table is written for management’s continuous monitoring, because that is where alerts have to be worked; for continuous auditing the equivalent is the evaluation procedure in the work program, and the only service level is the audit’s own reporting cadence.

ElementRuleWhy
Triage ownerA named role receives every alert for a rule; not a shared mailboxShared queues are nobody’s queue
Disposition codesA fixed list: confirmed and corrected; confirmed and accepted with reason; false positive with reason category; referred for investigation; duplicate of another alertFree-text closures cannot be analyzed and hide false-positive patterns
Service level by severityPayment-blocking rules (1, 2, 5, 8, 17): same business day. Others: 5 business daysA duplicate caught after the payment run is a recovery, not a prevention
EscalationAlerts open past the service level escalate to the process owner’s manager; past twice the level, to the controller; the second line sees the aging weeklyAn unworked alert is a control that did not operate
SegregationThe person who caused the transaction cannot close its alert; closures by the same user as the transaction are themselves an alertSelf-closure is the monitoring equivalent of self-approval
False-positive reviewMonthly review of false positives by reason; a rule above 70 percent false positives for two months is re-tuned or retiredAlert fatigue is the most common way monitoring dies
Rule change controlRule logic and thresholds are versioned; changes are approved by the second line and logged; audit is toldA threshold quietly raised to reduce workload is a control quietly weakened
EvidenceAlert, underlying records, disposition, user, and timestamp retained for the record-retention period, immutableThe disposition log is the evidence that the control operated; audit will sample it
MetricsVolume, confirmed rate, false-positive rate, time to disposition, open past service level, by rule and by unit, monthlyWhat the second line and the audit committee should see

What continuous auditing does to the audit plan and to sampling

Continuous auditing changes three things about the annual plan. Coverage becomes partly continuous: the plan states which risks are covered by quarterly rules rather than by an engagement, and the committee’s coverage map shows both, which the annual plan template accommodates in its coverage section. Engagement scoping starts from the rule results: an accounts payable engagement at MidState in FY28 will spend its hours on the vendor master, contract pricing, and the acquired distributors, because duplicates are now covered by a tested management control and a quarterly audit re-run. And the risk assessment gets a data input it never had: exception rates by unit and by quarter, which is a better indicator of control health than a questionnaire.

Sampling changes in a specific way and not in the way vendors claim. A full-population rule replaces a sample for the attribute the rule tests: when every invoice in the year has been screened for exact duplicates, a sample of 25 for duplicates adds nothing. It does not replace samples for attributes the rule cannot see, such as whether the goods were received or whether the approver read what they approved, which still need a sample and a human; the sampling techniques guide draws the line between what a population analytic answers and what it cannot. And a rule’s output is only evidence if the feed it ran on was complete, so every continuous-audit conclusion carries the feed reconciliation as its first workpaper.

Common failures

FailureWhat it looks likeWhy it mattersFix
Audit becomes the controlAudit’s rule is the only duplicate check; AP waits for audit’s emailIndependence lost; management never builds its own monitoringHand the rule over; test it as management’s control
Alert fatigueHundreds of alerts a week, 90 percent false positives, closures without reasonsThe one real exception is closed with the restBack-test before go-live; monthly false-positive review; retire or re-tune rules above 70 percent
Trusting the feedA zero-alert month celebrated; the extract had dropped a company codeConfident silenceCompleteness reconciliation every refresh, filed as IPE evidence
Rules nobody can change, or anybody canThe analyst who wrote the SQL left; or thresholds edited in a spreadsheet with no logUnmaintainable, or unreliableVersioned rules under change control with a named owner
Daily because the tool allows itAudit runs rules daily and evaluates nothingVolume without conclusions; the queue becomes management’s problem by defaultAudit’s cadence follows its evidence need: weekly to quarterly
Metrics that flatter“Alerts closed” reported without distinguishing corrected from false positiveThe committee sees activity, not controlConfirmed rate and time to disposition, by rule
Platform before rulesA twelve-month procurement for a tool with no rule specificationsThe tool is configured by the vendor to its defaults, and nobody owns the logicWrite the rule specifications first; they are the requirements
Never retiring anythingForty rules, half producing nothing for yearsMaintenance cost; real signals buriedAnnual rule inventory with retirement criteria

Adapting: small functions, tools, and when not to build

A small function can run continuous auditing with a database view, a scheduler, and one person who can write a query, and the six rules to start with are 1, 2, 9, 14, 17, and 18, because they cover the most money and the most common findings with the least data. What a small function should not do is build management’s monitoring for it; the finding that management has no duplicate check is the product, and management’s adoption of the rule is the outcome. Tooling ranges from SQL and a scheduler, through the analytics modules in audit-management platforms, to dedicated monitoring platforms; the rule specifications above are tool-independent and are the requirements document for any of them. The journal entry analytics guide shows the scoring approach that turns several rules into one ranked list, which is how a function with limited evaluation hours decides what to look at first.

There are processes where neither should be built yet: where the data source is a spreadsheet, where the transaction volume is low enough that a quarterly sample sees everything, or where the process is about to move to a new system. In those cases the annual engagement with population analytics for the year, run once, gives the same assurance at a fraction of the maintenance. Continuous methods earn their cost where volume is high, the process is stable, the data is in a system, and the risk is on the annual assessment. Every guide on the site is indexed at All Guides and by subject on the Topics page; the free tools, including the sampling tool the sampling guide refers to, are on the Tools page.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading