I have been writing about the limitations of audits and compliance systems for several years.
In Accountability and Transparency in Modern Systems, I wrote about systems producing evidence continuously rather than assembling it periodically for an auditor.
In First Principles for Root Store Management, I looked back at the decision to require WebTrust for publicly trusted CAs and argued that, if we were designing the system today, much more of the trust decision should be based on continuously verifiable behavior.
That led to The Limitations of Audits, Rethinking Compliance, and Compliance at the Speed of Code.
The common thread was that the systems we are trying to assure change much faster than the mechanisms we use to understand them.
Over the last year, I have spent considerably more time on this problem, both thinking about it and building systems intended to work differently. That work convinced me that the problem is deeper than periodicity alone.
I have pulled that thinking together into two new long-form pieces.
- The Assurance Model Was Built for a World That No Longer Exists looks at how the modern assurance model developed, what it actually establishes, and five distinct ways the evidence available can fail to justify the conclusion people ultimately rely on.
- Why Continuous Assurance Did Not Happen Until Now asks why decades of automation gave us continuous evidence without continuous reasoning, what AI changes in that equation, and what a different assurance architecture might look like.
They are intended to be read together.
The first explains how we got here.
The second explores what comes next.