Compliance monitoring is the difference between a compliance management system that knows whether its controls work and one that finds out when a regulator asks. ISO 37301 requires performance evaluation, and monitoring is the part that runs continuously rather than annually — which is exactly why it is the part most often reduced to a training completion percentage.
This guide covers what to monitor, how a monitoring plan is built, the difference between monitoring and audit, and the indicators worth reporting to a board.

What compliance monitoring is for
Every compliance obligation is discharged by a control somewhere in the business, and compliance monitoring is how you find out whether it works. Monitoring answers one question about each of them: is it working now? Not was it designed, not was it trained, not was it audited eighteen months ago.
ISO 37301 frames this as determining what needs to be monitored and measured, the methods, when it is done, and when the results are analysed and evaluated. The standard leaves the content to you — which is a freedom that quietly becomes the problem, because a programme with no defined monitoring universe defaults to monitoring whatever is easiest to count.
Monitoring, audit and assurance are not the same
| Who | Frequency | Question | |
|---|---|---|---|
| Business self-checks | The team performing the control | Continuous | Did we follow the process today? |
| Compliance monitoring | The compliance function | Risk-based, through the year | Is the control working, on evidence? |
| Internal audit | Independent of both | Periodic | Is the whole system, including monitoring, adequate? |
Compliance monitoring sits in the middle deliberately. It is close enough to the business to test controls frequently and independent enough that the answer is not self-reported.
Building the monitoring plan
- Start from the obligations register. Every monitored item should trace to an obligation and the control that discharges it. Our guide to the compliance obligations register covers the source document.
- Rank by compliance risk. Likelihood of breach and consequence — regulatory, financial, and harm. High-risk obligations get tested more often and more deeply; low-risk ones get a light annual check.
- Pick a method per item. Sample testing of records, system-generated exception reports, direct observation, mystery shopping, re-performance, or interview. Say which, and why it is capable of detecting failure.
- Define the sample and the pass mark before testing. Deciding what counts as acceptable after seeing the results is how monitoring loses its credibility inside the business.
- Route findings like any other nonconformity. Owner, root cause, action, due date, and a check that the action worked.
- Report trend, not volume. Repeat findings, ageing, and areas that have improved. A count of tests performed tells the board nothing about compliance.
What compliance monitoring should actually test
Prefer things that fail visibly. Approvals that should exist and do not. Thresholds crossed without escalation. Records missing where the process requires one. Timeliness against a regulatory deadline. Conflicts declared against a population where you would expect some. Compare these with the softer measures — training completion, policy attestation — which prove awareness, not compliance, and which are the default answer when nobody has designed a monitoring plan.
Where compliance monitoring programmes fail
Everything is monitored annually. A uniform cycle ignores risk and consumes the entire capacity of a small team. Concentrate.
Monitoring reports nobody acts on. Findings without owners and dates accumulate until the report becomes background noise, and the function loses its standing.
Testing the documentation. Confirming a procedure exists is not monitoring the control. The test has to reach the transaction, the file, the approval, the record.
No independence at all. Where the business self-assesses and compliance collates, you have reporting, not monitoring. Some sampling has to be done by someone who does not own the outcome.
Nothing ever fails. A monitoring programme reporting full compliance across every area is either testing the wrong things or testing them too gently.
Frequently asked questions
What does ISO 37301 require for monitoring?
That you determine what needs monitoring and measuring, by what methods, when, and when results are analysed and evaluated — with documented information as evidence. The design is yours; the discipline is required.
How often should controls be monitored?
By risk. High-risk obligations quarterly or more often, moderate ones annually, low ones on a longer cycle or through exception reporting alone.
Who should perform it?
The compliance function, with enough independence from the process owner that findings are credible. Internal audit tests the monitoring itself rather than replacing it.
Is monitoring the same as continuous control monitoring?
Continuous control monitoring is an automated technique inside a monitoring programme — valuable where the data supports it, and not a substitute for the risk-based plan around it.
What should the board see?
Coverage against plan, findings by severity and age, repeat findings, and the areas where testing found nothing — with an honest note about what was not tested this period.
Where this leaves you
Build compliance monitoring from the obligations register outward: rank by risk, choose a method capable of detecting failure, and fix the sample and the pass mark before you test anything. Test transactions rather than documents, route findings through the same corrective action process as everything else, and report trends with an explicit statement of what was left uncovered. A programme where nothing ever fails is not evidence of compliance — it is evidence about the programme.
References
- ISO 37301:2021 — compliance management systems, including performance evaluation.
- US DOJ — Evaluation of Corporate Compliance Programs — how prosecutors test whether monitoring actually works.
More on compliance management
- Compliance monitoring — you are here
- ISO 37301 explained
- The compliance obligations register
- The whistleblowing policy
Monitoring plans, test scripts and finding registers are in the ISO 37301 Compliance Management Toolkit, or start with the free ISO templates.