For a decade, every GRC platform pitch has carried the same headline: automate the control environment. Boards funded it, teams deployed it, and the natural expectation is that control automation rates climbed steadily through the 2020s.
The benchmarks say otherwise. Industry surveys of SOX programmes have recorded the share of automated controls drifting downward, from around a fifth to under that, even as average SOX compliance budgets climbed into the millions per company and kept rising. Protiviti's long-running SOX research has tracked both curves. Hours up, costs up, automation stubbornly flat to falling. More tooling, more spend, less automation: a result strange enough to need an explanation.
Workflow is not automation
The distinction sounds pedantic and is actually the entire story. A control is a check that something is true: access was appropriate, the reconciliation balanced, the change was approved before deploy. Automating the control means the check itself runs mechanically, against the data, without a person performing it.
What the GRC generation deployed automates everything around the check. The platform routes the testing request, chases the evidence, stores the screenshot, tracks the sign-off, escalates the overdue item. Inside that beautifully orchestrated workflow, the control is still a person, quarterly, examining a sample of 25 items out of a million, pasting an image into a form.
The consequences follow mechanically:
- Cost scales with controls, not risk. Every new system and regulation adds manual tests; each test costs analyst hours forever. Budget growth is built in.
- Assurance stays sampled and lagged. A quarterly sample of 25 says little about the other 999,975 transactions, and says it months late. Control failures surface in the period-end scramble or the audit, not when they happen.
- The workforce burns out on evidence theatre. Skilled people spend their year producing screenshots that prove a test occurred, which is not the same as proving a control works.
A workflow around a manual test is a faster way to document that you tested almost nothing.
The version that deserves the word
Continuous control monitoring is the alternative the label always implied: express the control as a logical condition over the actual data, and evaluate it continuously over the whole population. Segregation of duties becomes a standing query against access and transactions, all of them, every day. The reconciliation control becomes an automated match with only genuine breaks surfaced. The approval-before-change control becomes a join between the change log and the approval log that never sleeps.
Three properties separate this from the workflow generation. Coverage is total rather than sampled. The population, not 25 of it. Detection is immediate rather than quarterly. The exception fires when the condition breaks, routed to a named owner with the evidence attached. And the economics invert: an automated control costs its construction once, then near-nothing per period, so cost stops scaling with the control count.
The honest caveat is that not every control reduces to a query. Judgement controls, management review, estimates, tone, remain human, and should. But the bulk of a transactional control population is precisely the mechanical kind that queries handle best, which is why the current automation percentages are not a ceiling imposed by the nature of controls. They are a residue of buying workflow and calling it automation.
Automate the control, not the paperwork around it.
Controls as continuously evaluated conditions on one event backbone, with exceptions routed to owners. That is how the Prophesee Compliance Suite's Risk and Controls module works. Put one of your manual controls on a query. Start here.