September 29, 2026

From Snapshot to Stream: Why Compliance Needs to Move from Readiness to Continuous Proof

On September 15, 2026 the GRC World Forums hosted #RISK Digital Global, a live online event that brought together more than 30 risk, compliance and cyber leaders from around the world for a full day of panels and discussions. One of the sessions tackled a question that is quickly moving up the agenda for compliance teams everywhere.

Most compliance programs are built to pass a test on a given day. But regulators, auditors and boards are increasingly asking a harder question: can you prove your controls were working every day? That shift was the focus of the panel "The Automation Shift: Moving from Compliance Readiness to Continuous Proof" which brought together practitioners from both sides of the Atlantic to discuss how automation and connected GRC can turn compliance from a periodic scramble into an always-on capability.

The panel was moderated by Priyanka Chatterjee, CEO of the London School of Cybersecurity, and featured Rene Clayton, an automation and machine learning specialist with a background in banking and payments; Stefano Barone, an independent advisor on financial crime and sports integrity with experience in law enforcement, the World Customs Organization and FIFA's Ethics Committee; Christoph Becker, Compliance Solutions Director at Impero; and Mick Amelishko, AI Advocate and Senior Engineering Manager at Sumsub.

The problem with point-in-time compliance

Stefano opened with an analogy that set the tone for the whole discussion: reactive, point-in-time compliance treats a control framework like a photograph. It shows the organization looked compliant on audit day but says nothing about the rest of the year.

In his experience investigating financial crime, the failures that cause real damage are rarely failures of policy on paper. They're failures of monitoring cadence, such as transaction rules that haven't been recalibrated since the last audit, or due diligence files that were complete at onboarding but never updated as a client's risk profile changed.

The deeper cost, he argued, isn't the fine. It's reconstruction. When a regulator asks you to show that you knew, and the honest answer is a six-week effort to rebuild a paper trail across systems that don't talk to each other, that delay itself becomes evidence of weak governance. "From an enforcement standpoint," he said, "an unprovable control might as well not exist."

The visible and invisible costs of manual evidence

Christoph built on this by describing the reporting lag he's seen repeatedly in organizations. A request for control evidence arrives on Monday; numbers are pulled from Excel and evidence from SharePoint. Tuesday is review and management sign-off. By Wednesday, when it reaches internal or external audit, the information is already out of date.

He drew a distinction between visible and invisible costs. The visible cost is the annual tooling license. The invisible cost hides in salaries: teams pulled away from their regular work into audit task forces, reproducing evidence that already exists, and assembling 200-page PowerPoint decks to prove a process still works. On top of that comes the motivational toll of repetitive manual work, and the risk that management is signing off on the effectiveness of the internal control system based on stale data.

What continuous proof actually looks like

So what's the alternative? Mick described continuous proof as the ability to access any piece of evidence at the moment it's needed, and to always know how current that evidence is.

The key insight was the difference between push and pull. Pushing data into a central system creates a copy that starts aging immediately, because the real artifact keeps changing at its source. A continuous model instead pulls evidence directly from where it lives, on demand.

Rene explained how to make that work in practice: APIs and federated data rather than a single data lake. The chain that makes continuous proof possible is requirements mapped to systems, systems mapped to controls, and controls mapped to live evidence. She also offered a warning that resonated throughout the session: "Just because everything's green, doesn't mean it's green."

Where AI agents fit in

Mick noted that AI is strongest exactly where people get tired, which is processing large volumes of information without fatigue. Delegating that work to agents frees compliance professionals to focus on the calls and decisions that matter. Emerging infrastructure like MCP and agent-friendly APIs is making integrations easier to build.

But he highlighted two areas where the work is getting harder. First, agents need task-based permissions so they only access data relevant to a specific audit, rather than mixing information across cases or customers. Second, explainability is non-negotiable. "The agent decided" is not an acceptable answer. Every recommendation needs a full audit trail showing the inputs and the reasoning behind it.

Keeping a single source of truth

With so many connected systems, how do you know which one to trust? Christoph's answer was that each system should keep hosting its own data (the ERP holds financial data, the ticketing system holds incidents), while the GRC system holds the risks and controls and connects to those sources for evidence.

He stressed that a single source of truth starts with methodology, not tooling. Many organizations lack a common risk register, with departments and entities each running their own risk assessments. The ideal is a connected chain: external regulation drives internal policy, policy drives controls, and controls connect via API to the source systems where evidence lives.

Is human judgment keeping up?

Priyanka raised a concern many leaders share: the better an AI-generated report looks, the more authoritative it feels, whether or not it's correct. Rene pointed to the risk of drift as models and data change underneath you, and suggested a simple test for leaders: can your team explain what's going on in a dashboard within 60 seconds?

Stefano offered a concrete safeguard from the AML world. Teams that stop asking why an alert fired and clear it because the score was low have effectively handed the decision to the model. His fix is a mandatory periodic override review, where a senior person reinvestigates a sample of dismissed low-risk alerts to test whether the system's confidence is still earned. Human judgment in the loop, as he put it, should exist "by design, not by hope."

Priyanka added a cautionary tale from her own work: in one AI-assisted security operation, the human in the loop had gradually started approving everything the agent suggested by reflex, prompting a rethink of what meaningful oversight really requires.

Where to start

To close, each panelist shared one first step toward continuous assurance:

Rene recommended investing in a strong red team that deliberately tries to break your systems and keeps testing them. Stefano urged organizations to stop treating evidence as something gathered after the question is asked and start treating it as a byproduct of everyday work. Christoph suggested identifying the controls you test most often and automating those first. And Priyanka tied it together: start with one control, build evidence production into the control itself, and grow from there. Start small, grow bigger.

You can watch the full recording here.

Continue the conversation in London

Impero was proud to sponsor #RISK Digital Global, and we'll be exhibiting at #RISK Expo Europe at ExCeL London on November 10–11, 2026. If this discussion raised questions about your own path to continuous proof, we'd love to pick it up in person. Book a meeting with our team to talk through where automation could make the biggest difference in your compliance program.

Get the latest from Impero in your inbox.

Stay informed on all things Impero — webinar & event invites, exclusive content, product launches, and more! Or let us show you why Impero is the right choice for your risk and compliance needs.

You might also like...

Explore insights, product updates, and practical guidance to navigate the world of risk & internal controls.

Insighs & Inspiration

Webinar Recap: Expanding your internal control framework

Read more

Insights & Inspiration

3 lessons for boards: VOR risk management statement

Read more

Insights & Inspiration

Women leading the way: takeaways on the future of GRC

Read more