Control automation went backwards

A decade of GRC investment promised to automate the control environment. Surveyed automation rates fell while compliance costs climbed. What got deployed was workflow, and workflow is not automation.

2 min read

Ten years of GRC spending were supposed to automate controls. What many organisations actually automated was the paperwork around controls. The workflow improved. The control stayed manual.

The controls in question are the routine checks behind financial reporting, mandated in the US by the Sarbanes-Oxley Act. Through the 2020s, industry surveys recorded the automated share drifting down, from around a fifth to under that, while average compliance budgets climbed into the millions per company. Protiviti's long-running research tracked both curves. More tooling, more spend, less automation. The numbers only make sense once you see that control automation and workflow automation are different things, and the industry bought the second while believing it was buying the first.

Workflow is not automation

The distinction sounds pedantic and is the whole story. A control is a check that something is true. The right people had access, the accounts matched, the change was approved before it went live. Automating the control means the check itself runs against the data.

What got deployed instead automates everything around the check. The platform routes the testing request, chases the evidence, stores the screenshot, tracks the sign-off. Inside that workflow, the control is still a person, quarterly, examining a sample of 25 items out of a million.

A workflow around a manual test is a faster way to document that you tested almost nothing.

What that bought

  • Cost stays manual. Every manual control consumes analyst hours, period after period, so cost scales with the number of controls rather than with risk.
  • Assurance stays sampled. A quarterly sample of 25 transactions says little about the other 999,975, and says it months after the fact.
  • Evidence replaces insight. Control teams spend their year proving tests happened, which is not the same as proving controls worked.

The version that deserves the word

Continuous control monitoring writes the control as a rule the data must obey, then tests it against everything, all the time. The rule that nobody should both request and approve a payment becomes a standing check on every transaction, every day. The approval-before-change control becomes a comparison of the change log against the approval log that never sleeps.

Coverage becomes total rather than sampled. Detection becomes immediate rather than quarterly, with each exception routed to a named owner and the evidence attached. And the economics invert; an automated control costs its construction once, then near-nothing per period.

Not every control reduces to a query. Management review, estimates and judgement stay human, and should. But most transactional controls are exactly the mechanical kind a query handles best. Today's automation percentages are not a ceiling set by the nature of controls. They are what you get for buying workflow and calling it automation.

Controls as continuously evaluated conditions, with exceptions routed to owners, is how the Prophesee Compliance Suite works. Put one of your manual controls on a query. Start here.

New essays land on LinkedIn first. Follow 3RDi to catch them, or get a demo to see Prophesee on your own data.