Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Compliance

Continuous Controls Monitoring (CCM)

Continuous Controls Monitoring (CCM) is the practice of testing the operation of security and compliance controls on a defined cadence, against evidence collected from the systems that produce it, rather than once a year during an audit. Each control has a test, a source of evidence, a cadence and an owner; a failed test or a missing evidence becomes a finding with a deadline. Where a machine-readable source exists the test is automated; where it does not, the evidence is uploaded, validated and reviewed on the same cadence.

The unit of work is the control

A framework requirement is a sentence; a control is a thing that can be tested: “privileged accounts are reviewed quarterly and the review is signed”. CCM works at that level. For each control it states what evidence proves it, how fresh that evidence must be, who reviews it and what happens when it fails. A hundred well-specified controls monitored this way cover several frameworks at once, because the requirement sentences map onto them.

Automated where possible, honest where not

A CCM program that claims full automation is usually claiming coverage it does not have. Identity, cloud configuration and endpoint controls can be tested from connectors; a training completion, a supplier contract clause or a board approval cannot. The workable model mixes both: automated tests where a source exists, evidence upload with AI-assisted validation and human review elsewhere, and a single status vocabulary so a reader never has to ask which kind of proof sits behind a green.

What it feeds

Control status is the input that makes the rest of the GRC honest. The residual score of a risk inherits from the status of its controls; a KRI can count controls whose evidence has aged; the compliance view of a framework is the sum of its mapped controls’ status on the day it is read. CCM is therefore less a reporting feature than the source of truth the register, the indicators and the audit all read from.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.