Compliance Unfiltered is TCT’s tell-it-like-it is podcast, dedicated to making compliance suck less. It’s a fresh, raw, uncut alternative for anyone who needs honest, reliable, compliance expertise with a sprinkling of personality.

Show Notes: Audit Fatigue and How to Effectively Navigate It

Listen on Apple Podcasts
Listen on Google Podcasts

Quick Take

Caught in a cycle of audit requests, evidence chaos, and burnout? Discover a way out in this episode.

Compliance Expert Adam Goslin joins Todd Coshow to reveal the hidden causes of audit fatigue and share strategies to lighten your load.

Learn why audit fatigue is intensifying and how fragmented compliance efforts fuel chaos. Uncover tactics to centralize evidence, reduce duplication, and implement improvements.

Tune in to reclaim control over your compliance universe.

Read The Transcript

So let’s face it, managing compliance sucks. It’s complicated, it’s hard to keep organized, and it requires a ton of expertise in order to survive the entire process.

Welcome to Compliance Unfiltered, a podcast dedicated to making compliance suck less. Now, here’s your host, Todd Coshow, with Adam Goslin.

Todd Coshow:
Welcome in to another edition of Compliance Unfiltered. I’m Todd Coshow, alongside the hot and fresh Belgian waffle to your complimentary compliance breakfast, Mr. Adam Goslin. How the heck are you, sir?

Adam Goslin:
I am doing fantabulous today, Todd. How about you?

Todd Coshow:
Man, I cannot complain. I truly can’t. Though, to be fair, it is that time of year where everybody’s getting run down. It’s feeling a little bit of fatigue across the board. You shared with me you’re in a similar boat. I know that I’m feeling something similar, and I’m sure our listeners out there are feeling something similar as well.

So today we’re going to talk about audit fatigue. But before we do, I want to, as always, thank all the fine listeners to this podcast. Let you know that we greatly appreciate your time and your input.

With that in mind, if you have a topic, a comment, a favorite recipe, or something you want to share, please do reach out to us at [email protected]. We’d love to hear what you have to say.

Adam, audit fatigue. Talk to me about why it’s getting worse and what to do about it. Let’s be honest. Compliance teams of companies undergoing compliance everywhere are exhausted. Audit fatigue feels like it is at an all-time high right now. Why does it seem like this problem is getting worse year over year instead of better?

Adam Goslin:
It’s a real issue. One would think that with better tooling and a program going into its year two, year three, etc., things would start getting easier, but it almost feels like the opposite’s happening for a lot of organizations.

Honestly, there’s been very few organizations that I’ve worked with over the years where everything just stayed static. You’ve got growing scope. You’ve got new requests for additional frameworks that need to get folded in. Expectations of assessors continue to go up, not down.

So, in a lot of cases, instead of going through just one audit, there are teams that feel like they’re on this never-ending circular bicycle track, where it’s a continuous, never-ending cycle of audits, evidence requests, and follow-ups. You get done with one, another one pops up. I feel like we’re playing assessment whack-a-mole. That would be a good way to put it.

Todd Coshow:
That’s pretty fair. But the question is, what’s really driving that? Is it just more frameworks like PCI and SOC or ISO, or is there something deeper going on?

Adam Goslin:
That’s a big part of it. The bigger issue that underlies the real problem is fragmentation.

You’ve got a lot of organizations that are managing compliance in silos. There’s different frameworks, different teams, different tools, and at the end of the day, all of that leads to duplicated effort. You’re proving out the same control in five different ways to five different audiences.

You got spreadsheets. You got shared drives. You’ve got crap spread all over Hell’s Half Acre.

I’ve talked about that ad nauseam in the past, where you’ve got stuff coming at you through email, text messages, meetings, hallway conversations, people swinging by your desk. For whatever reason, I had somebody back in the day printing their effing evidence out. They printed it out on the printer, walked by, and dropped it on my desk.

You’ve got network drives. You’ve got SharePoints. You’ve got the assessor systems. It’s an effing nightmare.

There are a lot of organizations that end up with different assessors through this process. Let’s say you got one organization. They start out and get somebody to evaluate them against HIPAA. Then all of a sudden, the business says, “Wait a second. We’ve got to throw PCI into the mix.”

Now, when they have to go to PCI, they go back to their HIPAA assessor: “Do you guys do PCI?” Nope. Then we’ll go look and find a PCI assessor. So they throw a PCI assessor into the mix. Now I got two.

Then somebody gets a brilliant idea that, “You know what? We really need to go through SOC 2.” So they go to the HIPAA assessor: “Do you do SOC 2?” Nope. They go to the PCI assessor: “Do you do SOC 2?” Nope. Neither of them are with the AICPA, so now I’ve got a third assessor in the mix. That’s the way it rolls out.

For a lot of organizations, it feels like things are getting worse and worse, not better. Worse yet, it’s really not scalable.

Todd Coshow:
When you’re stuck in that cycle, it’s not just annoying. It has real consequences. Talk about the business impact that exists there.

Adam Goslin:
It’s big. There are a lot of various factors that come into play, all of which have real-world impact to the business.

First up, there’s burnout. Typically, on a security and compliance engagement, the control owners in that space are not the administrative assistant, the intern in HR, etc. We’re literally talking about your very best people being involved.

They’re the ones busily spending their time getting burnt out, chasing screenshots, evidence, files, config files, pictures of this and that and the other thing, etc. They’re spending a whole bunch of time chasing around this evidence.

Especially for the folks in the IT arena, instead of them focusing on security, the best people in the organization, the worst part is they’re also the people that are in the highest demand. If I’m really knowledgeable in my particular field within the organization, then you’ve got somebody that has limited time on their hands. Now we’re extracting from that limited pool a block of time that’s getting devoted, or some people would say donated, to the assessment gods.

It’s rough. You end up with blind spots through the process. You’re so focused on passing the audit that you’re not doing things that are effectively strengthening the posture of the organization, because I am eyeball deep in checking boxes of various chunks of evidence.

The one that really grinds everybody’s biscuit is that it’s slowing the business down. I can’t tell you how many times I freaking heard that, especially from the uppity-ups within the organization. They just want to know when the music’s going to stop so everybody can grab a chair.

Every single new initiative that starts to hit the plate for something that the organization wants to do all of a sudden becomes an internal joke about how much more painful this is going to make our compliance process.

It’s tough. If you think about it, for any given company, just talk about the sheer complexity involved in these engagements. The organization may have one or more hosting facilities. They may leverage one or more underlying operating systems, have one or more firewalls or NSCs thrown into the mix. They’ve got one or more locations, one or more solutions that are in scope for the assessment.

The list just keeps going. For all of that complication, then you’ve got a potentially complicated workflow that all of that nonsense needs to flow through. You’ve got control owners passing information to an internal QA department before it goes to your security compliance consultant, before it goes to the assessor, before it goes to QA, and that’s all before it gets to complete.

You take the complexity of the average security compliance engagement and the number of potential intersections for all of these various states of the evidence is literally staggering.

Todd Coshow:
It really is.

Let’s talk about the elephant in the room, Adam: the back-and-forth with the assessors. That’s where a lot of the frustration comes from. Why does that process break down so often?

Adam Goslin:
It typically comes out of lack of clarity and lack of consistency.

Before I get anything into it, one of the biggest challenges on compliance engagements is just keeping track of everything. I was talking about all these intersections, potential states of intersection, the states of your evidence across all these cross-sections and the workflow.

Just trying to keep your eyeball or hands on, “Where the hell is this piece of evidence? I know I sent it up the food chain last week. Is it still continuing on its merry way toward complete? Did it get rejected? Did it get rejected by the assessor to the consultant to sit in their hands? Have I gotten it back yet?”

The communication problems on these engagements are absolutely effing huge.

We were talking earlier about how you’ve got evidence stored in a bunch of different spots, and it’s not clear how things are mapping through to specific controls against your requirements. The assessor’s asking for something. Teams ship something up. They think it’s right, and then we get into this back-and-forth cycle.

You and I talked many times in the past about how the other part of the problem with communication, when it’s being handled in some form of manual or semi-manual process, is it’s human nature to wait for the next compliance meeting.

Maybe your compliance meeting’s typically on a Tuesday. All of a sudden, Wednesday, somebody has some type of an issue where they got to ask a question. Do they immediately ship that over to whoever to ask the question? Typically not.

Usually, they’ll sit, add it to a list, wait until next Tuesday, then ask their question. You’re dropping gobs of calendar time in the inefficiencies that you’ve got built into this.

Don’t get me wrong. It’s not that the assessors are trying to be difficult. It’s just that the way a lot of organizations structure their process for tracking and managing this stuff is simply not set up to make everybody’s jobs simplistic or easy.

The fact that you’ve got the same piece of evidence leveraged across several to several hundred different requirements, things get complicated really freaking quickly.

Todd Coshow:
They do. What are the teams doing that don’t feel this level of audit fatigue?

Adam Goslin:
The big shift is going from point-in-time compliance to continuous compliance.

Back in 2016, we built operational compliance into the TCT Portal. It’s because, as practitioners in the space, we were seeing organizations that were struggling with not having the appropriate or right information collected up, not finding out about it until late in the game, etc.

When you are in this mode of continuous gathering of evidence, pushing it through the review process, instead of collecting an entire year’s worth of stuff, where maybe there’s some stuff that got missed, we collect it more often.

Maybe it’s once a quarter. We go in and collect evidence across the quarter. That way, I know in compliance Q1 that I can flag a potential issue. We can go get that solved. We can make all of the adjustments. We can fix it as we’re rocking into quarter two.

By the time that I get to the back end of the engagement, the assessor gets this feeling that, “These guys are really on it. They’re identifying issues early. They’re making quick corrections. Even if there was turnover on the team, they’re maintaining pace.”

It’s awesome because the assessor can actually see the benefits of what’s happening.

The other part is collecting the control evidence once and mapping it across the various frameworks. If I can do that, now I don’t need to—I’ve seen so many inane things with the way people set up their engagements.

They have one repository for Cert 1, another repository for Cert 2, another repository for Cert 3. Even if I’m in one of these standard frameworks and certifications, let’s call it PCI for the sake of this discussion. If I take a particular piece of evidence in PCI and that needs to get attached to 15 different requirements, the minute that I shift over to either SOC or HIPAA, the same piece of evidence needs to be duplicated there as well.

For somebody sitting there and trying to hold all of this together, if you’re doing it right, being able to collect it once and automagically map it everywhere, all stored in a centralized system, the real benefit is, as you get to the assessment, you’re not just starting from scratch. You’ve got everything in great shape.

You’re ready to roll. You’re ready to engage the process and watch it unfold. It’s fun when the light bulb goes on for organizations that really get it.

Todd Coshow:
It sounds great in theory, but from a practical application standpoint, for someone listening right now who’s buried in audit chaos, where do they even start digging out?

Adam Goslin:
Try to make it as simplistic as you can and start to build from there. The very first task is centralize your evidence.

I talked earlier about it being scattered all over Hell’s Half Acre—inboxes, network shares, SharePoints, etc. Centralize the evidence into a single location.

Then standardize how we’re collecting and labeling evidence so it’s consistent. Make sure that we’ve got information tied to the right requirements, named properly, etc.

Then look for opportunities to do some control mapping across your various frameworks. The big key here is starting to deduplicate the rounds of effort that you and your team need to go through.

One thing that a lot of organizations struggle with is they’d like to be able to walk in and, poof, fix everything right away. But it’s the whole, “How do you eat an elephant? One bite at a time.”

Nothing applies more appropriately than as you’re trying to navigate from compliance chaos to an organized engagement. You need to get into the notion of making small, incremental changes. Keep layering them in over time. Things will get better. There’s an end to the small changes that you need to make.

You can really grind away at reducing that burden.

Todd Coshow:
Throw out a Compliance Unfiltered pro tip. If you’re looking to streamline your process, we do know a company that can help. Go to www.tct.com and contact TCT. We’ll be happy to give you a how-to guide and use our expertise to help you through the process.

There are definitely ways to make your world substantively easier.

Adam Goslin:
No doubt. That’s really what it’s all about. That’s the goal: less chaos, more control.

Todd Coshow:
Basically, because compliance isn’t going away, but the pain around it doesn’t have to be permanent, right?

Adam Goslin:
Exactly. The organizations that put their head down and get this stuff figured out, they’re not working harder. They’re just working smarter. Going through that process is ultimately what is going to help alleviate audit fatigue.

Todd Coshow:
Parting shots and thoughts for the folks this week, Adam.

Adam Goslin:
I really wasn’t joking about it. Just think about it. There are very few individuals that are going to wake up on some miscellaneous Tuesday, leap out of bed in the morning with the declaration of, “It’s all in season one.” It’s just not happening.

There might be a couple seriously sick individuals that will do that. I know the listeners are chuckling right about now, but it feels insurmountable.

It’s part of why I got into this space. I literally was the person that’s listening to this podcast back in the day. I was struggling with this gigantic, insurmountable feeling of a tidal wave washing over me, with pain at every corner and having problems with being able to get things organized.

I felt like I was in a continuous state—it wasn’t even controlled drowning back in the day. It was almost like my head was constantly about two feet below the waterline. That’s how it felt.

I had rigged up this extension straw of straw stuffed into straw, stuffed into straw, stuffed into straw, just to get a breath every now and then. That’s exactly how it felt.

Since then, having helped and assisted numerous organizations with getting their programs together—and in some cases, it’s small organizations; in some cases, it’s large international-style firms that we’ve helped through this process—take solace that the compliance tooling goes a long way.

But it also helps a lot to get some help, assistance, and guidance from somebody that’s been there, that knows what you’re going through, and that can actually help alleviate that pain.

Todd Coshow:
And that right there, that’s the good stuff.

That’s all the time we have for this episode of Compliance Unfiltered. I’m Todd Coshow.

Adam Goslin:
And I’m Adam Goslin.

Todd Coshow:
Hope we helped to get you fired up to make your compliance suck less.

KEEP READING...

You may also like