Compyl
Sponsored by:

Annual Audits Are Dead (Long Live Continuous Assurance)

An ISO certificate proves your controls passed a test on one day of the year. Your buyers, your regulators, and your board are starting to ask about the other 364. That question is changing how security programs run, and how they’re audited.

The two sides of the assurance table, David from the certification body perspective and Stas from the technology platform perspective, discuss how continuous assurance is reshaping audits, strengthening trust between certification cycles, and changing what customers expect from vendors.

Stas Bojoukha, Founder and CEO of Compyl
Stas Bojoukha
Founder & CEO
COMPYL20+ years as a CISO across financial services, real estate, and energy
David Forman, Founder and CEO of Mastermind
David Forman
Founder & CEO
MASTERMINDFounder of the audit-only certification body whose academy trains lead auditors industry-wide

Moderated by Daniel Tangney, Compyl

Who it’s for: CISOs, GRC leads, and compliance managers at mid-market companiesFormat: 60-minute live conversation between David and Stas, moderated by Dan. Live Q&A during the final 15 minutes. The recording will be shared with all registrants afterward.

What we’ll cover

  • What an ISO 27001 certificate actually proves, and what it doesn’t.
  • Why buyers have shifted from “Are you certified?” to “Can you show me your security posture today?”
  • The visibility gap between annual audits, and why it matters for both customers and auditors.
  • How continuous control monitoring is transforming audits through better evidence, reduced effort, and greater confidence.
  • Why annual certification and continuous assurance are complementary, not competing. David’s data point: roughly 85% of ISO 27001 and SOC 2 controls overlap.
  • What the future of audits looks like when evidence is collected continuously instead of once a year.
“Most organizations experience up to 85% overlap between ISO 27001 Annex A controls and the SOC 2 criteria. Almost nobody takes advantage of it.”David FormanFounder & CEO, Mastermind, IAS-accredited certification body for ISO 27001, 27701, 42001, and CSA STAR

If your certificate is doing more talking than your monitoring, this hour is for you.

When
July 23, 2026
Time
1:00 pm –
2:00 pm

We will cover:

  • What an ISO 27001 certificate actually proves, and what it doesn’t
  • Why buyers have shifted from “Are you certified?” to “Can you show me your security posture today?”
  • The visibility gap between annual audits, and why it matters for both customers and auditors
  • How continuous control monitoring is transforming audits through better evidence, reduced effort, and greater confidence
  • Why annual certification and continuous assurance are not competing approaches but complementary, with approximately 85% of ISO 27001 and SOC 2 controls overlapping
  • What the future of audits looks like when evidence is collected continuously instead of once a year
Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies