Written August 2026. Periodic audit was a rational method for a world with different properties than ours. Its epistemic reach has been shrinking for fifty years, and AI makes the mismatch worse before it makes anything better. Nothing here argues that audits are broken, that auditors are the problem, or that the method should be abandoned. The argument is about the distance between what audit can establish and what we ask it to carry.
Traditional audit is not irrational, obsolete, or valueless. It is a deliberately bounded method for obtaining reasonable rather than absolute assurance about a defined subject, over a defined period, using sufficient appropriate evidence. Audit sampling explicitly applies procedures to less than 100 percent of a population. Materiality, risk assessment, management assertions, professional judgment, and independent challenge are what make that compromise economically useful rather than merely convenient.[1]
The difficulty is not that those bounds appeared recently. They were there from the beginning, and section 2 supplies the existence proof, a computer-generated insurance fraud that survived a decade of audits during the very years the discipline of IT audit was assembling itself. What has changed is the environment that once made those bounds cheap to live inside. The populations under examination are larger, more heterogeneous, more interconnected, more frequently altered, and increasingly adversarial. Evidence can remain perfectly accurate about the moment in which it was collected while becoming unrepresentative of the system that exists when the report is issued, and more unrepresentative still by the time someone relies on it.
The problem is not administrative but epistemic. What can the assurance process actually know, and how much confidence should that knowledge support?
This post runs in four parts. The first describes the bounded world in which periodic examination made sense, and what audit has always promised in it. The second traces how the world stopped being bounded, and what institutions did in response. The third works through why the method's reach shrank rather than merely its coverage, with five cases that failed in different ways. The fourth names the deficit and asks what a different model would have to be.
The Bounded World
1What an Audit Actually Promises
The argument crosses several domains, so it matters what exactly is being criticized. Wirecard, SolarWinds, Storm-0558, and Silicon Valley Bank were not four failures of one identical mechanism. They were four institutions operating under different assurance regimes, and what they share is narrower and more interesting than “audit failed.” Each reveals the same limitation in a different costume, namely that a bounded, periodic, representation-dependent process struggled to establish, or to act upon, the state of a system that was moving. Here is the family of mechanisms, and what each one is and is not for.
| Mechanism | Primary question | Typical evidence | Core limitation |
|---|---|---|---|
| Financial-statement audit | Are the statements free of material misstatement? | Records, confirmations, tests, controls, estimates | Not a guarantee against fraud, collapse, or operational risk generally |
| Internal-control audit | Are controls over financial reporting designed and operating effectively? | Walkthroughs, control tests, selected transactions | Bounded to financial-reporting objectives, as of a specified date |
| IT audit | Can systems and processing be relied upon for defined objectives? | Access, change, operations, data, configuration | Scope and evidence may not represent the live environment |
| Security assessment / SOC | Do defined controls meet specified criteria over a period? | Policies, tickets, logs, samples, interviews | Control presence does not prove absence of exploitable conditions |
| Certification | Does a management system conform to a standard? | Governance processes, documented controls, sampled implementation | Certifying the management system is not validating every outcome |
| Regulatory supervision | Is the institution within prudential or legal expectations? | Filings, examinations, findings, models, supervisory judgment | Known risks may not be escalated faster than conditions change |
| Continuous monitoring | What is changing right now? | Telemetry, transactions, configuration, events | Produces signals without context, independence, or judgment |
Read down the last column and the common pattern is not that any of these mechanisms is defective in principle. Execution certainly fails sometimes, and two of the cases later in this post involve exactly that. Each is designed to answer a narrower question than the one relying parties tend to ask of it. The pattern is that a narrow conclusion gets repeatedly reused as a broad trust signal, while the underlying system may have changed, may hide important variation, or may simply exceed the assessor's practical field of view.
I have spent a good deal of my career on both sides of that table, and the thing that is hardest to convey to people outside the process is how much of it is honest. The scope statement says what it says, the opinion is carefully worded, and the limitation is printed on the page, and then the report goes out into the world and becomes a green checkmark in a procurement portal.
2Containment, Not Simplicity
The institutional origin of modern IT audit is usually placed at the Electronic Data Processing Auditors Association, incorporated in 1969 after practitioners auditing increasingly consequential computer systems concluded they needed shared guidance. ISACA's own record shows the discipline assembling itself over the following decade, with a journal in 1973, an education foundation in 1976, the first Control Objectives publication in 1977, and the CISA credential in 1978.[3][4] That sequence matters because it shows the discipline did not spring fully formed from a single date. The decade from 1969 to 1979 was a period of professional formation, in which techniques developed around financial and operational control were converted into a specialized body of knowledge for electronic data processing.
It is tempting, and wrong, to describe the baseline environment as simple. Mainframe applications were often extremely complex, and organizations maintained them, corrected them, altered data, and introduced new systems continuously. The honest word is not simple but contained. It is equally tempting, and more dangerous, to describe that environment as one in which the method reliably worked. It did not, and the counterexample sits squarely inside the decade the discipline was forming.
Computing was concentrated in governments, universities, banks, airlines, manufacturers, and a handful of other large institutions. Machines, storage, telecommunications, and specialist labor were all expensive. Authority over computing was comparatively centralized even when individual applications were not. Major hardware, operating-system, and application changes were visible organizational events rather than invisible updates delivered continuously by external services. The population of organizations needing specialist computer audit was a fraction of today's near-universal digital dependence. And failures could be severe without there being a globally connected software supply chain capable of distributing one compromised build to thousands of institutions in an afternoon.
The fraud that was running while the discipline was being founded
Equity Funding Corporation of America inflated its reported earnings from roughly 1964 until the scheme collapsed in 1973. At the centre of it was a computer system dedicated to manufacturing fictitious life insurance policies, more than 56,000 of them with a combined face value approaching $2 billion, which were then sold on to reinsurers for real cash.[21]
The operational details are uncomfortably familiar. A custom program filtered the records so that the fabricated policies were concealed from the auditors who came to examine them. When sampling required physical policy files to inspect, employees manufactured the files. The company simulated policyholder deaths at plausible mortality rates so the portfolio would behave the way a real one behaves. Outside auditors and financial analysts examined the statements for a decade, and the fraud was ultimately exposed not by any of them but by a fired vice president who told a state insurance regulator and a securities analyst what he had seen.[22]
Representation dependence, evidence manufactured to satisfy a sample, a system whose behaviour the assessor could not independently observe, and detection arriving from outside the assurance process entirely. None of that arrived with cloud computing. It was in place before the EDPAA had issued its first Control Objectives publication, and the fraud was running throughout the years the profession was assembling itself. So the historical claim this post needs is not that the method used to work and has since stopped, but something narrower and considerably harder to attack.
Periodic assurance was always epistemically bounded. What changed over fifty years is not that the bounds appeared. It is that the cost of living inside them exploded.
Containment is still the right description of the 1970s environment, and it still matters. It is why a bounded method was economically rational despite its bounds, because the gap between what the process could observe and what relying parties needed to know was narrower, and the consequences of being wrong inside that gap were generally less networked and less able to propagate instantly across organizational boundaries. Equity Funding shows what happened when someone deliberately widened the gap. The rest of this post is about what happened when the world widened it by accident, everywhere, at once. Security was not absent from this picture, incidentally. By 1978 the National Bureau of Standards and the U.S. General Accounting Office were convening workshops on computer-security audit whose scope already covered terminals, communications, operating systems, applications, databases, organizational vulnerabilities, and management controls.[5] Security emerged from concerns about the validity of processing, authorization, protection, and reliability, and only became distinctly adversarial as systems connected outward.
State it that way and you do not have to prove what anyone in 1975 believed. You only have to show what happened to the condition.
Everything Outgrew It
3Six Decades of Acceleration
A one-sided technology history is easy to write, so each decade below is described across the same dimensions, which are penetration, change cadence, complexity, volume, consequence, assurance demand, and institutional response. The quantitative indicators are imperfect, because definitions and collection methods changed over the period, but the direction of travel is not in doubt.
| Decade | Penetration | Change cadence | Consequence | Institutional response |
|---|---|---|---|---|
| 1970s | Strategic but concentrated | Deliberate, centralized releases and program changes | Serious, but less networked and slower to propagate | Controls over input, processing, output, access, change, operations |
| 1980s | PCs reach offices and homes; 8% of U.S. households by 1984 | Packaged software and departmental systems multiply the change points | Control escapes central data processing | Security evaluation and professional credentials expand |
| 1990s | Business computing broadens; home internet at 18% in 1997, 42% by 2000 | Client-server, ERP, web, vendor release cycles | Remote attack and external exposure | COBIT, security management, internet-era controls |
| 2000s | Normal infrastructure; 62% of U.S. households by 2003 | Shorter releases, virtualization, outsourcing, SaaS | Failure becomes enterprise-wide and market-relevant | SOX, sector rules, service-organization assurance |
| 2010s | Near-universal dependence; 83.8% household ownership by 2013 | Cloud and DevOps normalize daily or hourly change | Single dependencies can affect thousands of organizations | SOC, ISO, privacy, vendor-risk and cyber regimes accumulate |
| 2020s | 95% of U.S. households with a computer, 90% with broadband, 2021 | Continuous deployment, plus changing models, prompts, data, and tools | Error and compromise propagate at machine speed | Early automation; no accepted replacement for periodic assurance |
Those household figures are landmarks, not measurements of enterprise dependence.[6][7][8] They are useful because they are collected consistently over half a century, and because they mark the transition from scarcity to ubiquity in a way that enterprise data does not. The more important shift is the one they only gesture at. Computing moved from supporting selected administrative processes to mediating identity, communication, payment, logistics, access, health, public services, and now the production and operation of software itself.
4Adoption Is Not Attach Rate
Counting computers understates the transformation, because the decisive variable was never how many machines existed. It is how much human and economic activity is attached to them. A 1970s organization might depend on a computer for payroll, accounting, inventory, reservations, or settlement, and could in principle continue operating, badly, without it. A 2026 organization frequently exists as an orchestration of cloud infrastructure, identity services, payment processors, APIs, open-source libraries, communications platforms, analytics services, and outsourced business processes. There is no underlying manual process to fall back to, because the digital system is not supporting the business; it is the business.
So the risk surface expands along two axes at once. More organizations and people use technology directly, and a larger proportion of every organization's activity is inseparable from it. This is why a stable-looking audit population can be so misleading. An organization may enumerate a few hundred systems while depending on many thousands of external components and services that change independently of anything it controls. A control tested at the organizational boundary may depend entirely on conditions outside that boundary.
And then the reports themselves become inputs to other reports. One supplier's bounded opinion is accepted by a customer; that customer's vendor-management process is accepted by its own auditor; that auditor's report is relied upon by more customers still. At every reuse, the original scope becomes a little less visible while the inferred trust becomes a little broader.
5How Security Attached to Audit
There is a tidy story in which accounting audit handed off to cybersecurity at some identifiable moment. It is not what happened. Early computer audit already addressed authorization, access, program changes, data validity, and operational reliability. What changed is not that security arrived; it is that the object of assurance kept expanding as the threat environment did. The progression runs roughly like this. First, trust the calculation, meaning did the computer process the records accurately. Then, trust the controlled system, meaning were access, changes, operations, and data governed. Then, trust the connected enterprise, meaning could outsiders, suppliers, and network dependencies compromise it. And now, trust the changing ecosystem, meaning do policy, configuration, code, identity, models, data, and observed behavior remain aligned as each of them changes independently of the others?
That last question is different in kind from the first three. The first three can usually be bounded around a defined state or period, even where the thing examined is a process. The fourth asks whether relationships among independently changing components still hold, which no period boundary contains.
6Assurance Debt
Assurance debt is my term and my construct, not a measured quantity; nothing here counts frameworks longitudinally. What it names is a pattern that is easy to observe and hard to quantify. When new risks or new failures appeared, institutions generally added an obligation rather than retiring an older one. A single modern organization may map substantially the same underlying practices into financial controls, SOC criteria, ISO 27001, PCI DSS, privacy requirements, sector-specific rules, supplier questionnaires, cyber-insurance requests, and customer-specific contractual commitments.
These regimes have genuinely different legal and professional purposes and should not be collapsed into one another. Their overlap nevertheless produces a consistent set of operational effects. The same experts repeatedly explain the same system in different vocabularies; evidence is copied into multiple portals, workpapers, spreadsheets, and reports; controls that produce easy artifacts attract more attention than controls that reduce risk but are awkward to demonstrate; descriptions of the system are translated from implementation to policy to evidence to auditor narrative and back; and each new requirement increases the cost of assurance without any guarantee of a proportional increase in knowledge.
That is what I mean by assurance debt, a growing stock of representations, tests, mappings, exceptions, and evidence obligations that must be serviced out of the same finite human capacity needed to understand and improve the underlying system. Every hour spent restating a control in a fourth vocabulary is an hour not spent asking whether the control works.
The SEC's 2026 proposal is a useful illustration of where this pressure ends up, and it is easy to caricature. The Commission did not propose annual-only reporting. It proposed permitting public companies to replace three quarterly Form 10-Q filings with a single semiannual Form 10-S, and framed the proposal explicitly in terms of reducing reporting and compliance burden.[9][10] Whether that is good policy is a separate argument, and the analogy has a limit, since 10-Q cadence is corporate reporting, not audit methodology, so this is an adjacent example of reporting-cost pressure rather than evidence about audit itself. What it illustrates is the reflex. When observation becomes expensive, the available move is to reduce its frequency rather than change how the evidence is produced.
The Epistemic Problem
7The Narrow Claim and the Broad Signal
A costly audit can be enormously valuable. A manual process can involve exceptional judgment. A periodic process can be entirely appropriate for a stable subject. Efficiency is not the interesting question; what matters is whether the method produces knowledge proportional to the confidence placed in it. Under PCAOB standards an audit seeks reasonable, not absolute, assurance. Sampling applies procedures to less than 100 percent of a population. Internal control over financial reporting is designed around the reliability of financial reporting and the prevention or timely detection of matters that could materially affect the statements.[1][2] These are bounded propositions, and they do not ordinarily promise that no fraud exists, that no system has been compromised, that every transaction is correct, that every control operated in every instance, that all relevant risks were identified, that the organization is secure today, or that the conclusion will survive the next material change.
And yet an unqualified opinion, a certification, or an attestation becomes a market signal. It supports procurement, investment, regulation, insurance, board confidence, and access to customers. The formal claim is narrow. The economic interpretation is broad. Which means clean opinions and failed systems are not necessarily in contradiction at all. Sometimes the assurance work was genuinely deficient. Sometimes management concealed the evidence. Sometimes the failure sat outside the scope. Sometimes the system changed after the period ended. And sometimes, most uncomfortably, the report accurately answered a question that was simply narrower than the question the market believed it had answered.
8When a Sample Stops Meaning What We Think
Sampling is not the villain here, and it is not even central to the argument. Modern audit analytics already examine complete populations for some procedures, and the research literature is actively demonstrating population-scale automated testing. If coverage were the binding constraint, it would already be dissolving.[23] The percentage examined is not the decisive variable. A statistically sound sample can support a strong inference about a very large stable population. A much larger sample can support a weak inference about a heterogeneous, changing, adversarial one. The question is never really how much did you look at. It is what is the thing you are generalizing to.
Consider a hypothetical assessment of a service operating at search-engine scale. Whether 3 percent of transactions were sampled is close to the least informative fact available. The questions that actually determine what the sample means are these. Which languages, regions, devices, user states, query classes, experiments, and model versions were represented? Which software, configuration, data, and dependency versions produced the observed outputs? How were rare but severe failures represented at all? Could targeted or adversarial behavior have avoided the sample by construction? Did the population change between collection and reporting? And would the conclusion still hold after the next deployment?
Population coverage does not solve semantic incompleteness.
That is the durable version of the claim, and it survives full-population testing entirely. You can examine every row in a database and still be looking at the wrong database, misunderstand what a field represents, miss an external dependency that never appears in it, test an invariant that was never the one that mattered, accept a management model of the system that was wrong at the outset, or fail to notice that three individually benign facts combine into one serious condition. None of those are fixed by looking at more rows. As evidence ages and the system moves, the same audit procedure reduces less uncertainty than it once did, while the report retains exactly the same authoritative form. Nothing in the document changes to reflect that. This is the quiet part of the problem. The method degrades without any visible signal that it has degraded.
9What the Auditee Does Not Know Either
An external assessor always begins with less information than the organization. Management and operators select the systems, hold the data, control access to personnel, and prepare many of the representations the engagement runs on. Independence, confirmation, professional skepticism, and direct testing exist in large part to compensate for that asymmetry, and they do real work. Modern complexity introduces a harder condition, one the traditional model has no procedure for. The auditee may not possess a complete understanding either. No single person may understand the whole architecture. Documentation lags implementation as a matter of routine. Cloud and SaaS providers deliberately conceal internal behavior. Configurations vary by tenant and by region. And AI-assisted development can widen the distance between the person specifying an outcome and anyone able to explain every implementation detail behind it.
Fewer people understand enough of the whole system to describe it coherently to an assessor. Which turns the information chain into something closer to a game of telephone with a legal opinion at the end of it.
The commercial relationship adds a structural tension on top of the epistemic one, and it is easy to describe cynically. Public-company audit committees formally oversee appointment, compensation, and communication with the external auditor, and the professional independence rules are extensive and taken seriously.[11][12] Nevertheless the audited enterprise funds the engagement, direct verification is expensive, and the large-company audit market is highly concentrated; GAO has described the market for large public-company audits as an oligopoly.[13] None of that establishes that auditors routinely compromise their judgment, and I would resist that reading. What it establishes is that independence, governance, and professional skepticism are being asked to compensate for a widening gap in direct knowledge, with limited supplier choice, using tools designed when the gap was much narrower.
10Five Cases, Different Mechanisms, One Pattern
The cases below are not interchangeable, and the point of putting them in one table is not to claim they were all the same failure. They ran under different mechanisms and failed in different ways. Being precise about how they differ turns out to strengthen the argument rather than weaken it, so name the failure modes before walking the cases.
Four deficits belong to the assurance system itself. An epistemic deficit means the process could not establish the relevant fact at all. A temporal deficit means it established the fact too late to matter. An integrative deficit means it held the pieces and never assembled them into the conclusion that mattered. An institutional deficit means it reached the conclusion and failed to act on it.
A fifth sits with a different party altogether. An interpretive deficit is the relying party inferring more from an assurance result than it establishes, and it is the subject of sections 4 and 7. It is listed here because it compounds the other four, not because the assurance system commits it. Read the table with those in hand and the cases stop looking like five attempts to prove one thing. They are five different ways for the same architecture to fail.
| Case | Deficit | Mechanism | Known or represented | Failure or delay | Structural lesson |
|---|---|---|---|---|---|
| Wirecard | Epistemic, then interpretive | Financial audit, corporate governance, financial supervision | Repeated audited accounts; cash reported as held through third parties | €1.9 billion in purported cash could not be verified; oversight and information exchange criticised | A false model can survive repeated review when assurance depends on management narrative and indirect evidence |
| Enron | Epistemic and institutional | Financial audit, board governance, professional advice | Audited statements and formally governed structures | Economic reality obscured through complex transactions and conflicts; collapse drove SOX | After failure, institutions strengthen accountability without escaping periodic, reasonable-assurance limits |
| SolarWinds | Epistemic and integrative | Supplier assurance, customer risk management, secure development | A trusted vendor shipping signed software updates | Attackers compromised the Orion build and distribution process | Control evidence about a supplier does not prove any given delivered artifact is unmodified |
| Storm-0558 | Integrative and temporal | Enterprise security governance, identity and key management, external oversight | A mature global provider with extensive security and compliance functions | CSRB found a cascade of failures enabling forged tokens and mailbox access | Individually governed controls can combine into an unrecognised high-consequence path |
| Silicon Valley Bank | Institutional and integrative | Prudential supervision, bank risk governance, regulatory reporting | Known growth, concentration, liquidity and rate weaknesses; supervisory findings on record | Vulnerabilities not fully appreciated or remediated in time; 31 warnings open at failure | Information and findings do not equal timely system-level understanding or intervention |
Wirecard
Wirecard shows how devastating representation dependence becomes at scale. The company reported roughly €1.9 billion in cash that ultimately could not be verified, and European parliamentary and supervisory analyses identified weaknesses across audit, enforcement, coordination, and information exchange.[14][15] The lesson is not that one confirmation procedure was skipped. It is that a complex, regulated company sustained a false account of its own reality across multiple independent lines of defence for years.
Enron
Enron had audited statements, a board, professional advisers, and internal-control structures. Its collapse produced Sarbanes-Oxley, which strengthened executive accountability, audit-committee authority, auditor independence, and internal-control assessment. SOX was genuinely consequential. It also exemplifies the reflex this post is about, since the response to a failure of the method was to add formal obligations on top of the method.
SolarWinds
The SolarWinds compromise converted a trusted software distribution mechanism into an attack channel; CISA described it as a supply-chain compromise and ordered emergency federal action.[16][17] The defensible claim is not that some specific clean report certified the compromised build process. It is that ordinary supplier-assurance mechanisms gave customers no timely knowledge that signed, trusted updates had become the delivery path for compromise.
Microsoft Storm-0558
The Cyber Safety Review Board concluded that Storm-0558 succeeded because of a cascade of security failures, spanning key management, identity, logging, detection, and governance.[18] It is the clearest available demonstration that a sophisticated organization can satisfy extensive assurance obligations while retaining an unknown failure path created by the interaction of multiple individually governed controls.
Silicon Valley Bank
The Federal Reserve's review found that SVB's board and management failed to manage risk, that supervisors did not fully appreciate the vulnerabilities as the bank grew, and that identified problems were not corrected with sufficient speed or force. SVB grew from $71 billion to more than $211 billion in assets between 2019 and 2021, and at failure carried 31 unaddressed safety-and-soundness warnings, roughly triple the peer average.[19][20]
This case sharpens the thesis rather than merely illustrating it. The risks were not unknown. The process had findings, reports, and supervisory mechanisms pointed at exactly the right problems. What it did not have was any way to convert them into intervention before the state changed catastrophically. Digital banking and digital communication had also compressed the time available to respond, so the supervisory process and the risk state were running on different clocks.
The state of risk was changing continuously. Governance processed it periodically and procedurally. The process lost the race.
Be careful with that sentence, because it is the one most easily misused. SVB is routinely offered as an argument for observing more often, and the deficit table above says why that is wrong. Its failures were institutional and integrative, not epistemic. The findings existed. Faster observation would have produced them sooner and changed nothing, because nothing in the process converted findings into intervention. A case that is fundamentally about acting on what you already know is the worst possible advertisement for knowing more, more frequently.
11Evidence Has a Half-Life
Security practitioners have said for two decades that satisfying a framework does not prove resistance to real adversaries. Compliance is not security. That observation is correct and no longer sufficient, because there is a newer problem underneath it. Periodic compliance may not establish current compliance either. A control may operate correctly when sampled and be bypassed by a deployment the following morning. A policy may accurately describe one service and not its neighbour. Regional configurations diverge. A supplier changes something. An AI system is connected to new tools or new data without anything resembling a conventional software release, and therefore without triggering any of the change-management controls that would have caught it a decade ago.
None of which is a discovery. The profession has had subsequent-events procedures, dual dating, and roll-forward work for as long as there have been reports, precisely because everyone has always known evidence ages between fieldwork and issuance. The question is not whether that was noticed. It is whether procedures built for a subject that moved between annual cycles still hold for one that moves weekly, and whether the answer is knowable from inside a process that only looks twice a year.
One documented case does more here than the abstraction, and the one to choose is where the evidence problem was already solved, because the usual response to all of this is that better data collection would fix it.
In the public certificate ecosystem, every certificate a browser will accept must first be published to Certificate Transparency logs, which are append-only, cryptographically verifiable and public, and which anyone can watch. That is about as good as continuous evidence gets, being independent, tamper-evident, complete within its scope, and free. In September 2025 Cloudflare disclosed that twelve certificates had been issued for one of its services without authorization, the earliest eighteen months before anyone noticed. Cloudflare operates Certificate Transparency logs. Cloudflare also runs a monitor over them and sells alerting on it to customers. Their post-mortem names three failures. The certificates were of a type their monitor did not cover; where alerts could fire, the volume arriving exceeded what anyone could review; and because the monitoring was noisy, alerting had been switched off for some of their own names. Two reports through their own disclosure programme were mistriaged before an outside mailing list post was picked up.[24]
Continuous evidence existed. A monitor existed, run by the affected party, who was among the most capable operators in that ecosystem. Coverage, throughput, and attention failed in sequence, and no conclusion was ever updated. If the answer to the assurance problem were more evidence, this is what solving it would have looked like.
The consequence side of this has been rising too, and increasingly across jurisdictional boundaries. GDPR applies in specified circumstances to organizations outside the European Union and authorizes penalties tied to worldwide turnover. Newer European cyber, operational-resilience, product-security, and AI regimes extend the same pattern, because maintaining separate systems per region is often more expensive than applying the most demanding rule everywhere. Extraterritorial legal reach and global market influence are different things and should not be conflated, and different regimes regulate genuinely different objects. But the direction is consistent. More systems regulated, more jurisdictions claiming authority, obligations overlapping, penalties scaling with revenue, and the same bounded report relied upon across a larger ecosystem than ever.
The Deficit and What Follows
12The Settlement Is Already Breaking
Everything so far has been diagnosis, and diagnosis invites the reasonable objection that institutions absorb bad news for decades without changing anything. So set the argument aside and look only at what is already on published schedules, with dates, decided by parties who were not persuaded by any of this.
The bottom track is a forcing function, and it is the least arguable item because it is already in force. Maximum lifetimes for public web certificates are on a schedule that takes them from 398 days to 47 between March 2026 and March 2029, agreed unanimously by the body that sets them.[26] The assurance consequence is arithmetic rather than argument. A control that operated a handful of times a year per subscriber will operate roughly eight times as often, while the annual sample of it does not grow. Whatever that sample characterised in 2020, it characterises proportionally less of each year now, on a published timetable.
The top track is institutions changing the method rather than the frequency, and the three items on it are doing different jobs. The first is about the obligations themselves. In June 2025 an executive order directed NIST, CISA and OMB to stand up a pilot for a rules-as-code approach, producing machine-readable versions of the cybersecurity policy and guidance those agencies publish.[27] Read that against section 6. It is the government proposing to make its own obligations machine-readable, which is an admission that the requirements themselves, not just the evidence, are now too numerous and too fast-moving to be handled by people reading documents. The order gave it a year, which elapsed in June 2026, and I have not been able to confirm what was delivered. The other two belong to bodies that decide whom to trust. FedRAMP 20x has the same government committed to machine-readable evidence, automated validation, and ongoing certification rather than static packages. And a major browser root program, which decides what billions of clients trust, has published phases dated to 2027 alongside a stated intent to move third-party oversight toward continuous, externally verifiable monitoring that could replace the function annual audits now serve. Neither is a vendor claim. Both are programme documents from institutions that set requirements rather than sell against them.
The middle track is the one that makes this honest, and it points the other way. The SEC's 2026 proposal would let public companies replace three quarterly filings with one semiannual report, framed explicitly as burden reduction. That is an institution facing the same cost pressure and responding by observing less often rather than by observing differently.
That is the whole of the inevitability claim, and it is deliberately narrow. It does not say continuous reasoning wins, that the technology is ready, or that the institutional and social obstacles will yield; the companion piece argues at length that two of the four constraints have not moved at all. What the timeline establishes is only this. The settlement in which periodic examination is the presumed instrument is dissolving on published schedules, decided by parties with no stake in this argument, and it is dissolving in both directions at once.
Which sets up the stake, and it is not the one usually stated. The alternative to solving this is not the status quo. The assumptions supporting the status quo are already being scheduled away in at least one ecosystem, and under pressure in others. The certificate lifetime schedule is in force, while the replacement of annual audit as the primary oversight instrument remains a proposal in conditional language. If a better way of knowing does not arrive, the SEC track is what remains available, and it is entirely rational. When observation costs more than it yields, reduce the observation. That path is open, it is cheap, it requires no new technology, and it ends in knowing less about larger and more consequential systems.
13Three Rising Curves and One Slower Line
Here is the whole argument in one picture, which is where this post started and where it has been heading since. Treat it as a conceptual model rather than four measured series, since nothing here establishes comparative growth rates, and the argument does not need them.
Three of these quantities rise, and the claim is only directional. Technology scale and velocity contains systems, users, dependencies, changes, transactions, and machine-generated actions. Assurance obligations accumulate in steps, particularly after failures, and few layers ever retire. Consequence rises with attach rate, interconnection, and jurisdictional reach. The fourth line needs no growth rate at all, because the claim about it is simply that it is bounded. Human attention is finite, and the central unit of assurance work has remained remarkably constant, which is to read a policy, interview an operator, select evidence, reconcile a spreadsheet, test a sample, document an exception, and write a report. You do not have to believe any particular slope to accept that three rising quantities are being serviced by a fixed one.
14We Optimized for Auditability, Not Adaptation
Traditional assurance is at its strongest when reconstructing a bounded past. Who approved this activity? Does the evidence support the assertion? Did the selected controls operate? Can a formal report be issued and defended? These are good questions and the profession answers them well. Modern risk mostly asks a different class of question. What changed this morning? Which prior evidence just became stale? Did a deployment invalidate a control? Did observed behavior diverge from policy? Which supplier or dependency changed? Which individually modest findings combine into a serious failure path? Which customers and systems sit inside the blast radius? And how quickly would the assurance system even discover that its last conclusion had stopped being true?
We have become very good at proving that required activities occurred, and much weaker at determining whether the system is becoming unsafe in motion.
Auditability is the right word for what we bought, and the more flattering one should be resisted. Accountability, as people ordinarily use it, means somebody is held to account. What the method actually produces is the capacity to establish afterwards what happened and who was responsible, which is a precondition for accountability and not the same thing as it.
Silicon Valley Bank is the demonstration, and it cuts against the tidy version of this section. If the trade were auditability in exchange for adaptation, the auditable record would at least have bought consequences. It did not. The record was excellent; the Federal Reserve's own review reconstructs in detail what was known, by whom, and when, down to thirty-one open warnings at failure. What was missing was not documentation and not attribution. It was anyone converting either into action while it still mattered. So the honest framing is not that we chose accountability over adaptation. We optimised for the record, and the record on its own delivers neither.
15AI as Accelerant, Then as Possibility
AI should not enter this argument as a solution, because that is not how it enters the world. It enters first as fuel. AI lowers the cost of writing and changing software, creating integrations, responding to customers, producing documents, making decisions, and operating workflows. It expands the population of things requiring assurance and multiplies the number of machine-generated actions inside each one. It also widens the gap between intent and implementation. A person can specify a desired result, accept generated code or a generated workflow, and operate the system successfully without understanding every dependency, authorization path, failure mode, or emergent behavior. A problem that was already badly managed can become substantially worse in a very short period.
Only after saying that plainly is it reasonable to talk about the other direction. Because the same force does change what is economically knowable, and the opportunity is not faster report writing. Automating the inherited audit would improve throughput while preserving every one of its central limitations, and I would treat any product that describes itself that way with suspicion.
A more significant model could evaluate entire transaction populations where data access permits; continuously compare requirements against configuration and observed behavior; track the provenance, scope, and freshness of evidence; identify which changes invalidate which prior conclusions; correlate findings across systems, suppliers, and organizational boundaries; distinguish isolated exceptions from systemic patterns; reason about combinations of individually minor conditions; maintain dependency and blast-radius models; and direct scarce independent human attention toward ambiguity, manipulation, and consequential judgment. This remains unproven, and the failure modes are real. AI can hallucinate, omit context, be manipulated, and generate unjustified confidence with great fluency. A credible assurance system built on it would require traceable evidence, reproducible checks, explicit scope, explicit uncertainty, versioning, separation between observation and judgment, and independent human review. None of it is optional.
Read the right-hand column from the bottom up, because the order is the argument. Continuous operational evidence means authoritative records of configuration, identity, change, transactions, approvals, dependencies, and policy-relevant behavior, carrying provenance and integrity. Deterministic evaluation means objective requirements translated into reproducible tests wherever the rule actually permits it. Continuous reasoning means contextual correlation, contradiction detection, evidence-freshness tracking, dependency analysis, and aggregation of interacting conditions. Independent human assurance means someone whose job is to challenge the sources, the tests, the scope, the omissions, the manipulation risk, and the fairness of the conclusions. And periodic accountability, meaning the formal reports, certifications, submissions, and board attestations, sits on top as an output rather than a reconstruction.
16The Uncomfortable Truth
The traditional audit was not foolishly designed. It was a rational response to practical limits, in a world where the condition set out in section 2 was far easier to satisfy, because material change could usually be identified, scoped, and examined before the resulting assurance went stale. Periodic examination and selective testing produced genuinely useful confidence, not because the method was unbounded, but because the bounds were cheap to live inside. Over five decades, computing moved from concentrated infrastructure to universal dependency. Systems became distributed, connected, cloud-based, continuously changed, supply-chain dependent, and increasingly machine-generated and machine-operated. Transaction populations became vast and heterogeneous. Regulation accumulated in layers. Penalties and reliance both expanded. The method still produces value. The problem is that we ask it to produce more confidence than its evidence can support.
We expect a point-in-time assessment to describe a moving system. We expect a sample to characterize a heterogeneous population. We expect management to explain systems that management may not fully understand. We expect an outsider to know what the inside organization does not. We expect a narrowly scoped opinion to function as a general certificate of trust. And we expect more controls, more frameworks, and more evidence to compensate for an unchanged way of knowing.
For fifty years, the pace, scale, reach, complexity, and consequence of systems grew faster than the assurance model used to govern them, and our response was to add audits, frameworks, evidence, reports, certifications, controls, regulators, and penalties. We expanded the obligations. We did not change the method. AI now makes systems cheaper to create, faster to change, easier to automate, and harder for any one person to understand. It intensifies a problem that was already unmanaged. But it also changes the economics of observation and analysis, which means it may become possible to examine whole populations, correlate heterogeneous evidence continuously, maintain live models of obligations and dependencies, and point human judgment at the questions that genuinely require it.
What this post does not establish
The limits. The decade matrix uses U.S. household adoption as a longitudinal landmark, not as a measure of enterprise dependence, and claims about exact software-release frequency in the 1970s have been deliberately narrowed because comparable data is sparse and varied enormously by institution. The four curves in section 13 are a conceptual model; nothing here establishes their comparative growth rates, and the argument is constructed so that it does not need them. The five cases involve different assurance and governance mechanisms, and the deficit labels in that table are an analytical framing rather than findings of any investigation. And the continuous-assurance stack in section 15 is a proposal, not a description of something that exists and works.
The Equity Funding material carries a specific burden and no more than that. It establishes that representation dependence, manufactured evidence, and detection from outside the assurance process all predate the environment this post describes. It does not establish anything about how common such frauds were, and one spectacular case is not a base rate.
None of which is a claim that AI has solved assurance. The argument is only that the same force making the old model untenable may be what makes a new one possible, and that leaves an obvious question, which is the subject of the companion piece. If continuous assurance has been imaginable for decades, why did it never happen? The answer is not that nobody tried. The accounting firms went after professional judgment directly with expert systems in the 1980s and could not keep the encoded knowledge current. What kept the model in place was a cost structure, in which software kept getting cheaper at administration while interpretation stayed expensive, and four constraints of which AI moves only two. The two it does not move are about liability and willingness, and they are the ones that decide whether any of this happens.
The last fifty years were about expanding the scope of audit. The next era has to be about expanding what we are actually capable of knowing.
Sources
- PCAOB, AS 1000: General Responsibilities of the Auditor, and AS 2315: Audit Sampling. AS 1000 · AS 2315
- PCAOB, AS 2201: An Audit of Internal Control Over Financial Reporting.
- ISACA, 55 Years of Impact, historical milestones.
- ISACA, 50th anniversary history and the incorporation of the EDPAA.
- NIST SP 500-57, Audit and Evaluation of Computer Security II, workshop held 28–30 November 1978.
- U.S. Census Bureau, Computer and Internet Use in the United States: 2003.
- U.S. Census Bureau, Computer and Internet Use in the United States: 2013.
- U.S. Census Bureau, Computer and Internet Use in the United States: 2021.
- SEC, Proposed Rule: Semiannual Reporting, Release No. 33-11414, 5 May 2026.
- SEC Chairman Paul S. Atkins, statement on the semiannual reporting proposal, 5 May 2026.
- PCAOB, AS 1301: Communications with Audit Committees.
- PCAOB, auditor independence rules and archived AU 220.
- U.S. GAO, Public Accounting Firms: Mandated Study on Consolidation and Competition, GAO-03-864.
- European Parliament, Update on the Wirecard case.
- ESMA, Follow-up Report to the Wirecard Peer Review, July 2024.
- CISA, Supply Chain Compromise, 7 January 2021.
- CISA, Emergency Directive 21-01 and SolarWinds mitigation materials.
- Cyber Safety Review Board, Review of the Summer 2023 Microsoft Exchange Online Intrusion, March 2024.
- Federal Reserve, Review of the Supervision and Regulation of Silicon Valley Bank, April 2023.
- Federal Reserve, press release summarising the SVB review, 28 April 2023.
- Office of Justice Programs, The Equity Funding Papers: The Anatomy of a Fraud. The fraud began at least as early as 1964 and continued until discovery in early 1973, despite examination by outside auditors and analysts throughout.
- BRG, The Computer Crime of the Century, on the program that generated fictitious policies and the filtering that concealed them from auditors.
- See for example Automated Population-Level Audit Assurance via AI-Based Document Intelligence, arXiv:2605.05252, as an indication that population-scale testing is an active research direction rather than a hypothetical one.
- Cloudflare, Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1, 4 September 2025. Twelve certificates issued February 2024 to August 2025; the post-mortem details three monitoring failures and notes that most DNS clients do not require CT inclusion, so detection depended on the CA having logged them.
- Google, Cultivating a robust and efficient quantum-safe HTTPS, February 2026. The announcement lists evolving the third-party oversight model toward complete, continuous, and externally verifiable monitoring among its proposed governance changes, and states that this could replace the function of annual third-party audits. The phrasing is conditional throughout and the corresponding policy framework has not been published.
- CA/Browser Forum, Ballot SC-081v3: Introduce Schedule of Reducing Validity and Data Reuse Periods, passed April 2025, scheduling maximum TLS certificate validity from 398 days to 47 days between March 2026 and March 2029.
- Executive Order 14306, Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity, 6 June 2025. The order directs NIST, CISA and OMB, within one year, to establish a pilot program of a rules-as-code approach for machine-readable versions of the cybersecurity policy and guidance they publish and manage.
Check your understanding
Fourteen questions on the assurance model and why its reach is shrinking. Options shuffle every run.