rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/compliance-monitoring-assurance-plan-design
Printed 28 August 2026
Compliance monitoring and assurance plans: designing testing that proves the controls work
Building an annual compliance monitoring plan: design vs operating effectiveness, what to test and how often, sample sizes, and recording results.
What a monitoring and assurance plan is
A monitoring and assurance plan is a dated schedule of tests, each aimed at a specific control, with a defined method, sample, tester and reporting destination. Its output is evidence that the controls on the obligations register actually work — not evidence that they exist.
The distinction is the whole point. A control register says a control exists. A policy says what it should do. Only testing establishes that it operated as intended across a period. Regulators and auditors treat untested controls as unproven.
Written as an annual plan, it typically covers between twelve and forty tests for a mid-sized business, weighted toward the obligations carrying the highest residual risk on the risk register.
Design effectiveness versus operating effectiveness
Every test answers one of two questions, and conflating them is the most common design error.
| Aspect | Design effectiveness | Operating effectiveness |
|---|---|---|
| Question | If this control operated as documented, would it satisfy the obligation? | Did it actually operate that way across the period? |
| Method | Walkthrough, document review, comparison against the obligation | Sampling transactions, records or events over a defined period |
| Evidence | Procedure, system configuration, one worked example | Population listing plus tested sample with results |
| When it fails | The control is inadequate even if performed perfectly | The control is adequate but was not performed |
| Fix | Redesign the control | Fix execution, training, capacity or system enforcement |
Test design first. Testing whether a control operated is wasted effort if the control could never have satisfied the obligation.
A design test is also the correct response to a new or amended obligation. When a regime changes, the first question is whether the existing control still discharges the new duty — a question the obligations register change intake should raise automatically.
Choosing what to test and how often
Rank by residual risk, then apply four modifiers. The plan should be defensible on its face, so record the reasoning.
Base ranking: residual risk rating from the risk register.
Modifiers that increase frequency:
- The control is manual rather than system-enforced.
- The control failed, or an incident touched it, in the last twelve months.
- The obligation changed recently, or the underlying process changed.
- The control depends on a third party — see contractor and supplier compliance.
- Staff turnover in the operating role.
Modifiers that reduce frequency:
- The control is fully automated with change control over the configuration.
- It has passed testing without exception in consecutive periods.
- Independent assurance already covers it (certification audit, external audit, regulator inspection).
A workable default pattern:
| Control profile | Testing frequency |
|---|---|
| Manual, high residual risk, event-driven | Quarterly |
| Manual, high residual risk, periodic lodgement | Each cycle, sampled |
| Manual, moderate risk | Semi-annual or annual |
| Automated, high residual risk | Annual, plus configuration change review |
| Automated, low risk | Annual walkthrough only |
| Covered by external certification | Rely on the certification, review the findings |
Publish the plan at the start of the year and treat additions as amendments recorded with a reason. A plan quietly reshaped mid-year to avoid a difficult test is a governance failure in itself.
Sample sizes and evidence in a small business
Small populations defeat statistical sampling, and pretending otherwise produces indefensible conclusions. Practical approach:
- Small population (under 25 items): test all of them. It is usually faster than justifying a sample.
- Moderate population: test a judgemental sample weighted toward higher-value, higher-risk or period-end items, and say in the working paper that the sample was judgemental and why.
- Large, automated population: test the configuration plus a small validation sample, and rely on system controls for the rest.
- Event-driven controls (incident notification, breach reporting): test every event in the period. Populations are small and each one matters. The incident register is the population listing.
Evidence retained for each test should let a second person reach the same conclusion without asking questions: the obligation and control tested, the period, the population source and how it was extracted, the sample and how it was selected, the attribute tested, the results item by item, exceptions and their disposition, the conclusion, the tester and the date.
Never conclude "satisfactory" without recording the population source. A test over a list supplied by the person operating the control, with no independent extraction, is the finding most likely to be reversed on review.
Recording results and the issue that follows
A test with an exception generates an issue, and the issue is the artefact that gets tracked — not the test.
Each issue should carry a rating, a root cause, an owner who is senior enough to fix it, an agreed action, a target date, and a verification step confirming the fix worked. The verification step is the one most often skipped, and it is the one an auditor tests.
| Issue rating | Typical criteria | Escalation |
|---|---|---|
| High | Obligation not met, notification triggered, or systemic control failure | Board at next meeting, or immediately if reportable |
| Medium | Control operated inconsistently; obligation met but by chance or manual recovery | Executive, board summary |
| Low | Documentation or timeliness weakness with no obligation impact | Tracked, reported in aggregate |
Where a test reveals that an obligation was actually breached, the issue crosses into the incident and breach register and starts any statutory clock — reportable situations under ASIC's RG 78, data breach assessment obligations, or sector-specific notification duties. The monitoring plan is a common discovery route for breaches, and the handoff between the two registers should be written into the procedure.
Independent evaluation and external assurance
Some assurance must come from outside the monitoring function.
- Regime-mandated independent evaluation. Reporting entities under the anti-money laundering regime must have the program independently evaluated at least once every three years under the reformed rules, with staggered first-evaluation deadlines under the Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (checked August 2026). AUSTRAC's guidance sets out what the evaluator must cover, including the risk assessment, policy design, and whether risk was actually identified, mitigated and managed in practice: AUSTRAC — conduct an independent evaluation.
- Assurance engagements over non-financial information. Where an assurance report is required or sought over sustainability, compliance or other non-financial subject matter, the engagement standard framework is covered in ASAE 3000 assurance engagements. Climate reporting brings phased assurance requirements — see the ASRS Group 1 disclosure walkthrough.
- Certification surveillance. Where certifications are held, surveillance audits provide independent coverage over the certified scope. Scope them deliberately; a narrow certified scope provides narrow assurance.
- Regulator inspections and external audit management letters. Both are assurance output. Track the findings in the same issues log as internal testing.
Reporting the plan and its results
The board should see the plan once and the results every cycle. A usable report has five elements:
- Plan status. Tests completed against planned, with reasons for any deferral.
- Results summary. Pass, pass with exceptions, fail — by obligation domain, not by test number.
- Open issues. Ageing, by rating, with overdue items named and their owners.
- Repeat findings. Issues raised previously and found again. This is the strongest single indicator of program health.
- Coverage. Which high-risk obligations have not been tested in the last twenty-four months, and why.
The fifth element is the one boards ask for once and then always want. Reporting structure is covered further in board and committee compliance reporting.
Frequently asked
What is the difference between monitoring and assurance?
Monitoring is ongoing testing performed by the second line — the compliance or risk function — over controls operated by the business. Assurance is independent evaluation provided to the governing body by someone outside both, such as internal audit, an external reviewer or a certification body. Both are needed: monitoring finds problems early; assurance tells the board whether the monitoring itself can be relied on.
How many controls should an annual monitoring plan cover?
There is no fixed number. Cover every obligation rated high residual risk at least annually, every control that failed or was touched by an incident in the last twelve months, and every control affected by a recent regulatory or process change. For a mid-sized Australian business that commonly produces between twelve and forty tests a year.
Can a control owner test their own control?
Self-assessment by the control owner is a legitimate input and useful for coverage, but it is not monitoring and it is not assurance. Testing that is relied on for reporting to the board should be performed by someone who does not operate the control, and the working paper should record who performed it.
What sample size is defensible for a small business?
For populations under about twenty-five items, test the whole population — it is usually faster than defending a sample. For larger populations, a judgemental sample weighted to higher-risk and period-end items is acceptable provided the working paper states that the sample was judgemental and explains the basis. For event-driven obligations such as incident notification, test every event.
What happens when monitoring finds an actual breach?
The issue moves into the incident and breach register and any statutory clock starts from the point of awareness, not from the point the test report is finalised. Where the regime carries a notification duty — reportable situations, data breach assessment, work health and safety incident notification, sector-specific reporting — the notification pathway runs in parallel with remediation.
Does external audit count as compliance assurance?
Partly. A statutory financial audit is scoped to the financial report, not to the compliance program, so it provides assurance only over controls relevant to that scope. Management letter points arising from it are legitimate assurance output and should be tracked alongside internal findings, but the audit does not substitute for a compliance monitoring plan.
Related
Related reading
ASAE 3000 Assurance Engagements explained
ASAE 3000 is the AUASB standard governing Australian assurance engagements other than audits or reviews of historical financial information. Who it applies to and how.
AML/CTF program — Part A and Part B explained
How a reporting entity's AML/CTF program splits into a Part A general program and a Part B customer identification program under the AML/CTF Act.
The three lines model applied to an Australian SMB
How the three lines model works without a compliance department: mapping the roles, keeping second line independent, and third-line options for an SMB.
Incident and breach registers: capturing, escalating and closing compliance events
Running one incident and breach register: the fields that matter, the statutory clocks that start on logging, escalation thresholds, closure and retention.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/compliance-monitoring-assurance-plan-design