The rise of endless auditing 

The rise of endless auditing 

Audits are on the rise in Europe and greater demands are now being placed on European businesses. Indeed, regular audits are now a fact of life for even SMEs. Selim Ourtani, CEO at Secrato, explores the aggressive rise of audits, what’s causing them and how organisations can adapt.

A security or compliance audit used to be something a business did once or twice a year at most. Even then, this was mostly an expectation for large enterprises. That’s changing. Increasingly, businesses of all sizes are undergoing audits at levels they’ve never seen and aren’t prepared for.  

A mix of regulatory shifts, emerging new technologies and looming cyberthreats have had a profound effect. In turn, European regulators have set into motion a new wave of compliance obligations that is having consequences all over the business world.  

While only a few years ago, security and compliance audits were an occasional consideration, they are now a fact of life for many organisations. This will be a steep learning curve for many, who now not only have to ensure compliance, but ensure that they can demonstrate it at short notice.  

Rising audits 

Many organisations are reporting a sharp rise in audits over the last few years. Before that, most organisations would only have to undergo these once or twice a year, and even then, most of those were enterprises. According to one report, nearly 60% of organisations underwent at least four audits in 2025 and 35% conducted six or more over the same period. 

Enterprises are still the most audited size category of business, but small- and – medium sized businesses are also catching up. In fact, according to A-LIGN’s 2026 Compliance report, the average mid-sized business now goes through five audits a year – the same amount as an enterprise – compared to just two in 2024. 

Emboldened regulators 

The simplest explanation for this intensification of audit cadence has been the mere growth of European security regulation. Around 70% of European organisations have been audited since the dawn of the European General Data Protection Regulation (GDPR).  

In turn, European businesses have become more active in their compliance. Data from DLA Piper shows that in 2025, data breach notifications reached an all-time high of 443 per day. Each of those notifications will likely prompt an audit, providing some rationale for this rising phenomenon. What is true of the GDPR and its effect on auditing, is also true of the European regulations that followed in its wake. 

Regulating the European supply chain 

As regulators’ understanding of cyber-risk and data protection has matured, regulations have emerged which attempt to bring resilience to the region as a whole. Network and Information Security 2 (NIS2), the Digital Operational Resilience Act (DORA) and the EU AI Act have all emerged in the last few years and instead of focusing on regulated organisations as discrete entities, they instead see these as part of a connected whole.  

Regulators are now focusing on the regional and global linkages which define the European market and holding individual businesses accountable for the security of their partners and suppliers.  

NIS2 applies to large businesses and organisations regulators deem to be critical to the functioning of European society – such as those involved in critical infrastructure or digital services – which it labels ‘essential entities’. The regulation makes plain that these organisations – and those organisation’s executives – will be held legally liable for the subpar security practices of their vendors, partners and suppliers and states that compliant organisations should incorporate that into SLAs and contracts. 

DORA focuses on financial organisations. However, given that the European financial sector is involved in and relies on a wide array of sectors and partners, particular emphasis is put on the security stance of software suppliers and IT service providers. Like NIS2, it demands that these be incorporated into SLAs and contracts.  

The EU AI act does largely the same for companies building AI products in which they must ensure the security of the models and components they use – and that their partners have undergone the correct audits, or risk penalties, investigations or being completely barred from selling AI products.  

Compliance by contract 

This regulatory revolution might focus on ‘essential entities’ and large firms but, given the interconnection of these large hubs, their suppliers, vendors and partners are all required to comply whether explicitly beholden to it or not. This is sometimes known as ‘cascading compliance’. 

As a result, regular audits to ensure compliance are now increasingly a condition of engagement with businesses. For fear of endangering their own compliance, many businesses – especially large enterprises – will require their partners to undergo regular audits and provide continuous assurance that they won’t endanger their clients or compliance status.   

Cyber-insurance also plays a key role in this rise of continuous auditing. Insurance firms now often require client organisations to undergo regular audits in order to justify their policies and premiums.  

More audits for enterprises and large organisations are now trickling down to small- and medium-sized organisations, who now have to prove not only their own compliance, but that they won’t endanger their partners compliance status either.  

Continuous assurance  

The price of business for many is now constant audit readiness and continuous assurance. To achieve that, automation and centralisation of audit and compliance processes needs to be a key focus. 

Compliance monitoring, governance and crucially, evidence collection all need to be automated to the greatest extent possible. To do that any platform or tool used to achieve this must be able to integrate into an organisations’ full tech stack and monitor them centrally. From that central point of management, all audits – whether they be external, internal or for compliance purposes – can be strategically managed and monitored from the same place.  

Centralising will also allow an organisation to unify these efforts, and map them across different audits, certifications and compliance obligations. That will deduplicate work between different efforts and shift audit and compliance work from a periodic task to an integrated, continuous business operation.  

Businesses now need to be continuously ready for audits and provide constant assurance that they’re remaining compliant and safe to do business with. Security and compliance audits are no longer a checkbox task, but a strategic imperative which will permit or deny a business access to regulated clients and markets. European business’ next step needs to use automation and centralisation to transform their ad-hoc auditing and compliance activities from a matter of periodic preparation to a continuous business process.  

Browse our latest issue

Intelligent SME.tech

View Magazine Archive