Continuous Compliance Is Not a Slogan — Here's What It Actually Looks Like Inside Microsoft 365
8/22/2026 · Compliance365
"Continuous compliance" gets used by almost every GRC vendor as a slogan and almost none as a literal description. Most compliance programs are still, mechanically, a point-in-time exercise — a scramble every 12 months to reconstruct evidence nobody kept current in between.
This post skips the marketing framing and describes the actual mechanism: what runs unattended, on what schedule, where the data goes, and who gets told what — inside Checkpoint, running entirely in your own Microsoft 365 tenant.
The default state most organisations are actually in
A control gets marked “Implemented” at certification time, evidence gets attached, and then — nothing checks it again until the next audit cycle. A vendor’s SOC 2 report expires quietly. An overdue remediation action sits in a spreadsheet with an owner’s name against it that nobody follows up. None of this is negligence; it’s just what happens when the only thing driving a re-check is a human remembering to look.
Auditors read this pattern correctly: a control that hasn’t been re-verified in fourteen months reads the same as one that was never properly implemented, regardless of what actually happened in between.
What actually runs on a schedule
An optional Azure Function — deployed into your own Azure subscription, not ours — re-runs the same posture checks the interactive app runs, daily, with no browser open and no user signed in:
Reads live Entra, Intune and Defender signals and writes a new scored scan record — the same evidence trail as a manual scan, on autopilot.
A check that scored pass yesterday and fails today raises an alert the moment it happens — not at next quarter's review.
Overdue remediation actions, controls due for re-verification, stalled policy attestation campaigns — each raised as its own alert, once, until acknowledged.
A vendor's reassessment due date, or the expiry of the SOC 2 report / certificate you're relying on for them, gets chased the same way — 30 days ahead, and again if it's missed.
Findings land in the same alerts register the interactive app already shows on the Dashboard — and, as of this week, can also post straight into a Microsoft Teams channel, so the people who need to see it see it where they’re already working, not in an inbox they check once a day.
Where the evidence actually goes
Every one of those scheduled scans writes to the same SharePoint lists your interactive sessions write to — in your own tenant, not ours. There’s no separate “automation database” to reconcile against your manual records, because there’s only ever one record. Evidence behind each check is hashed (SHA-256) at the moment it’s captured, so what an auditor is shown a year later is provably the same thing the scan actually saw, not a document that could have been edited in between.
What this replaces
The one thing this deliberately doesn’t do is write anything on your behalf. Every alert is a nudge to a human, not an automated remediation — a control gets marked Implemented, an action gets closed, a policy gets approved, only when a practitioner actually does it. The automation’s job is making sure nothing sits silently overdue, not taking the decision out of anyone’s hands.
Where to start
This is entirely optional and additive — Checkpoint works exactly the same without it, as an on-demand tool a practitioner runs interactively. Turning it on just adds the unattended half. If you’re already running Checkpoint, it’s a short deployment guide away. If you’re not yet, book a free 30-minute call and we’ll show you the whole thing running against a demo tenant.
We deliver ISO 27001, Essential Eight, SOC 2, ISO 42001 and ISO 27701 for Australian mid-market organisations — fixed-price, inside your existing Microsoft 365 environment, with audit-ready evidence at every step. Explore our services →
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources