Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Method and evidence

Method and evidence

Continuous technical verification

Link a technical drift to the control, the evidence and the client commitments it affects.

Question addressed

Detect when a technical drift undermines a client commitment.

Between two audits, controls drift: an MFA exception granted "temporarily", two forgotten administrator accounts, a backup failing silently. The problem is not the drift — it is inevitable — but finding out about it from the client. Continuous verification links every technical signal to the client commitments it puts at risk.

The chain is always the same: a signal (MFA coverage drops from 98% to 94%) affects a control (staff MFA coverage), which weakens a piece of evidence (the quarter's coverage export), which affects specific commitments (Client A's annex, Client B's question 44). At the end, a human decision: correct it, document an exception, or requalify the response.

Propagation of a drift

A technical signal becomes significant once it touches a promise made to a client.

01

Signal

MFA coverage is declining across a monitored population.

02

Control

Access control is no longer supportable within the same scope.

03

Commitment

Two client responses need to be reviewed again.

04

Decision

Documented exception, correction or new communication.

Decision enabledYou discover the drift before your clients do — and you choose the response instead of enduring it.

Reading a conclusion

Give commercial meaning to the technical signal

A drop in coverage or a failed control does not trigger an abstract alert. The conclusion shows the evidence that has become insufficient, the commitments potentially affected, and the choice expected: verify, correct, accept an exception, or communicate.

The signal remains an invitation to verify until its population, its cause and its effect on the commitment have been confirmed.

REPORTING STRUCTUREContinuous technical verification
Starting questionDetect when a technical drift undermines a client commitment.
  1. 01Sourced technical signal
  2. 02Affected control
  3. 03Evidence that has become insufficient
Decision enabledYou discover the drift before your clients do — and you choose the response instead of enduring it.

Implementation

Turn a technical signal into a client decision.

  • Sourced technical signal
  • Affected control
  • Evidence that has become insufficient
  • Promises to be requalified
01

Choose the signals that matter

Not everything is monitored: what is monitored is what underpins commitments — MFA, privileged accounts, backups, restores, critical dependencies, logging.

02

Link signal → control → evidence

Each signal is wired to the controls and evidence it conditions. An orphan signal is noise; a linked signal is a useful alert.

03

Trace back to the affected engagements

The drift shows the list of clients and commitments concerned, with their criticality. It is this that sets the priority — not the raw technical severity.

04

Decide and record

Remediate, document an exception, requalify a response or notify the client: the decision is dated, assigned and visible in the assurance register.

Terms of use

The thresholds that turn a signal into a decision.

A deviation only affects a commitment once the population, cause and control actually affected have been qualified.

Do we need to install agents on our systems?

The principle works from the exports and signals your systems already produce. The level of integration is decided at scoping — from periodic import to direct connector.

How does this differ from our existing supervision?

Your monitoring protects production; continuous verification protects your commitments. Sometimes the same signal, but a different reading: it answers "which clients are affected?", not just "which system is down?".

What happens when a drift is detected?

Nothing happens automatically on the client side: the alert stays internal. You choose the response — that is precisely the advantage of learning of the drift before the client does.

Continue reading

Observe how a technical drift reaches a client promise.

The MFA drift example shows how a technical signal reaches a piece of evidence and then several client commitments.