Skip to content

Continuous Monitoring

Definition

An automated control framework that applies fraud indicator tests to transactions as they are processed or on a frequent scheduled basis, generating alerts when a transaction matches a defined risk rule. Reduces detection lag from months to days.

Applies to
Transactions as processed or on frequent scheduled batches
Output
Alerts when a transaction matches a risk rule
Benefit
Reduces detection lag from months to days
Contrasts with
Periodic post-hoc audit sampling

Common questions

How does continuous monitoring differ from a periodic internal audit?+

A periodic audit samples a subset of transactions after the fact, often months later, while continuous monitoring runs automated rules across the full transaction population as it flows through the system, catching anomalies close to when they occur rather than at the next scheduled review.

What causes false positives in continuous monitoring systems?+

Rules calibrated too broadly flag legitimate but unusual transactions, such as a genuine large year-end adjustment, and teams typically tune thresholds and add context checks over time to reduce alert volume without missing real fraud indicators.

Who typically reviews the alerts continuous monitoring generates?+

Internal audit or a dedicated fraud analytics team triages alerts, closing false positives quickly and escalating credible matches for deeper investigation, since the tool generates leads but does not itself determine whether fraud occurred.

Related terms

ACL / Galvanize HighBond
A purpose-built audit analytics platform (originally Audit Command Language) that imports financial data, executes statistical and rule-based tests, and produces exception reports...
Benford's Law
An empirical regularity in naturally occurring numerical datasets: the leading digit follows a logarithmic distribution, with 1 appearing about 30% of the...
Compliance Dashboard
An automated reporting surface that aggregates metric and control-status data and presents it in a format aligned to one or more regulatory...
Control Effectiveness
The degree to which a security control achieves its intended objective under real operating conditions. Measured through a combination of design review...
Fuzzy Matching
A string-comparison technique that identifies near-identical records by measuring edit distance or phonetic similarity rather than requiring character-exact matches. Used in duplicate...
IDEA
Interactive Data Extraction and Analysis: an audit data analytics tool that supports Benford analysis, duplicate detection, stratification, and custom query filters across...
Key Performance Indicator (KPI)
A metric that measures how well a specific control or process is performing against a defined target. KPIs are often lagging indicators:...
Key Risk Indicator (KRI)
A metric that measures the level or trend of a specific risk exposure. KRIs are often leading indicators: they change before a...
Network Link Analysis
A technique that represents entities (vendors, employees, bank accounts, addresses) as nodes in a graph and shared attributes as edges, enabling investigators...
SIEM (Security Information and Event Management)
A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.