Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT NewsCompliance

From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments

Cloud Native Now, Thursday, August 27th, 2026

Periodic compliance audits can't keep pace with cloud-native infrastructure that changes hourly.

Author Ramachander Rao Thallada argues that 'point-in-time controls verification just isn't going to cut it anymore' for infrastructure built on Kubernetes, serverless and infrastructure-as-code, since a compliance snapshot from one month can be irrelevant by the next as services and permissions change.

He proposes shifting from 'were we compliant last quarter?' to 'are we compliant right now?' using controls-as-code tools like OPA and Kyverno, automated evidence generation from CI/CD pipelines, real-time drift detection, and dynamic risk scoring.

Success requires GRC teams to embed directly with engineering and accept real-time visibility over polished quarterly reports, starting small on critical controls before expanding.

more →  ·  More from Compliance →