Caught in a cycle of audit requests, evidence chaos, and burnout? Discover a way out in this episode. Compliance Expert Adam Goslin joins Todd Coshow to reveal the hidden causes of audit fatigue and share strategies to lighten your load. Learn why audit fatigue is intensifying and how fragmented compliance efforts fuel chaos. Uncover tactics to centralize evidence, reduce duplication, and implement improvements. Tune in to reclaim control over your compliance universe.
Episode Transcript:
So today we’re going to talk about audit fatigue. But before we do, I want to, as always, thank all the fine listeners to this podcast. Let you know that we greatly appreciate your time and your input.
With that in mind, if you have a topic, a comment, a favorite recipe, or something you want to share, please do reach out to us at complianceunfiltered@totalcompliancetracking.com. We’d love to hear what you have to say.
Adam, audit fatigue. Talk to me about why it’s getting worse and what to do about it. Let’s be honest. Compliance teams of companies undergoing compliance everywhere are exhausted. Audit fatigue feels like it is at an all-time high right now. Why does it seem like this problem is getting worse year over year instead of better?
Adam Goslin:
It’s a real issue. One would think that with better tooling and a program going into its year two, year three, etc., things would start getting easier, but it almost feels like the opposite’s happening for a lot of organizations.
Honestly, there’s been very few organizations that I’ve worked with over the years where everything just stayed static. You’ve got growing scope. You’ve got new requests for additional frameworks that need to get folded in. Expectations of assessors continue to go up, not down.
So, in a lot of cases, instead of going through just one audit, there are teams that feel like they’re on this never-ending circular bicycle track, where it’s a continuous, never-ending cycle of audits, evidence requests, and follow-ups. You get done with one, another one pops up. I feel like we’re playing assessment whack-a-mole. That would be a good way to put it.
Todd Coshow:
That’s pretty fair. But the question is, what’s really driving that? Is it just more frameworks like PCI and SOC or ISO, or is there something deeper going on?
Adam Goslin:
That’s a big part of it. The bigger issue that underlies the real problem is fragmentation.
You’ve got a lot of organizations that are managing compliance in silos. There’s different frameworks, different teams, different tools, and at the end of the day, all of that leads to duplicated effort. You’re proving out the same control in five different ways to five different audiences.
You got spreadsheets. You got shared drives. You’ve got crap spread all over Hell’s Half Acre.
I’ve talked about that ad nauseam in the past, where you’ve got stuff coming at you through email, text messages, meetings, hallway conversations, people swinging by your desk. For whatever reason, I had somebody back in the day printing their effing evidence out. They printed it out on the printer, walked by, and dropped it on my desk.
You’ve got network drives. You’ve got SharePoints. You’ve got the assessor systems. It’s an effing nightmare.
There are a lot of organizations that end up with different assessors through this process. Let’s say you got one organization. They start out and get somebody to evaluate them against HIPAA. Then all of a sudden, the business says, “Wait a second. We’ve got to throw PCI into the mix.”
Now, when they have to go to PCI, they go back to their HIPAA assessor: “Do you guys do PCI?” Nope. Then we’ll go look and find a PCI assessor. So they throw a PCI assessor into the mix. Now I got two.