IAM

Documented Is Not Proven: The Case for Continuous Compliance Monitoring

15 Sep 2026
Dr. Heiko Klarl
Dr. Heiko Klarl CEO, Nexis

Auditors do not just want to know whether a control exists. They want compliance evidence that it actually worked – for a specific system, at a specific point in time. 

Most regulated organizations can explain their controls in detail. But when an auditor asks for proof that a control was actually effective, the answer is often much harder to provide. 

That difference matters. A documented control describes what should happen. Evidence shows what actually happened, and one thing is clear: The evidence provided should be current, not updated. 

Documentation vs. Compliance Evidence: What Auditors Actually Need 

Regulatory frameworks such as DORA, NIS 2, BAIT, VAIT, and MaRisk place strong emphasis on effective and traceable controls. A policy or control description alone does not demonstrate that those controls are reflected in the systems they govern. 

A policy may require SSO, for example. But it does not prove that SSO is correctly configured in a specific application. An authorization concept may define who should belong to an administrative group. It does not show who actually belongs to that group today. 

Traditionally, this proof is collected when an audit approaches. Application owners gather screenshots, exports, and documents manually, often with varying levels of quality and completeness. By the time everything has been collected, some of the evidence may already be outdated. 

A green status on a compliance dashboard does not solve this either. The underlying evidence is what makes that status defensible. 

Making Compliance Evidence Collection Part of Daily Governance 

Instead of treating evidence collection as an audit exercise, it can become part of everyday governance. 

For every governed item, the governance team defines what evidence is expected, how it should be provided, and which criteria it must meet. Clear working instructions tell application and object owners exactly what they need to submit. 

NEXIS embeds these requirements directly in the IAM governance documentation. Evidence can be provided while the documentation is maintained rather than reconstructed months later. 

This turns evidence collection from a periodic exercise into an ongoing process, with requirements, current status, and evidence history kept together. 

Evidence also has a shelf life. Each requirement can define how long its proof stays valid, and NICO requests fresh evidence when that window expires. Compliance stays current instead of frozen at the last audit. 

Why Automated Compliance Evidence Collection Still Needs Validation 

Continuous collection also creates more evidence to review. If every screenshot, export, or document still needs to be checked manually, much of the efficiency is lost. 

This is where NICO, the NEXIS Intelligent Co-Pilot, comes in. NICO evaluates submitted evidence against criteria defined by the governance team and returns a verdict together with its confidence and reasoning. 

NICO does not decide what “compliant” means. Your governance team does. 

The team defines these criteria centrally, and NICO applies them consistently. Every evaluation remains traceable, including the submitted evidence, the time of evaluation, NICO’s confidence, and its reasoning. The original artifact is preserved unchanged and protected against tampering. 

The result is a consistent and transparent validation process without making every piece of evidence dependent on manual review. 

Capturing Audit-Ready Evidence at the Source 

Evidence collection becomes even more practical when proof can be captured directly at the source. 

With the NEXIS browser plugin, application owners can see their open evidence requests, capture the relevant system state, and submit it directly for evaluation by NICO. Instead of taking a screenshot, saving and naming it, and uploading it separately, evidence becomes part of the workflow itself. 

The same approach works for applications that are not connected to an IGA or PAM platform. Rather than building a dedicated connector for every system, the governance team defines the required proof. The application owner provides the relevant screenshot, export, PDF, or document, and NICO evaluates it against the defined criteria. 

This allows organizations to apply a consistent evidence standard across a much broader application landscape, including systems that would otherwise remain outside centralized governance. It’s not a question anymore, whether the system is a IAM-managed application or whether this is not the case. 

From Audit Preparation to Continuous Compliance Monitoring 

Requirements are defined up front. Evidence is captured as part of ongoing governance. Submissions are validated as they arrive. Audit preparation then changes fundamentally. 

Requirements, evidence, compliance status, and history remain connected for each governed item. Missing accepted evidence stays visible as a gap. When an auditor asks for proof, organizations no longer have to reconstruct it from scratch. 

This also lays the foundation for broader continuous compliance monitoring: moving from isolated compliance checks toward an ongoing view of whether governance requirements are actually supported by evidence. 

The Takeaway: Evidence Starts with Governance, Not Audits 

A documented control tells you what should be true. Evidence shows whether it is true. 

Making evidence part of ongoing governance means defining what proof is required, capturing it close to the source, validating it consistently, and keeping every decision traceable. 

That is the idea behind the NEXIS Evidence Collector: turning audit preparation from reconstruction into retrieval. 

Want to see it in practice? Book a demo and explore how the NEXIS Evidence Collector takes you from a defined requirement to validated, audit-ready evidence.

Request a Demo