1.2. Compliance as an Ongoing Discipline
💡 First Principle: Compliance isn't a certificate you earn once — it's a continuous cycle of proving, to regulators, customers, and your own leadership, that your controls actually match the rules you're supposed to follow, over and over, as both the rules and your environment keep changing.
Think about why this has to be continuous: a company might be perfectly compliant with a data-residency law on Monday and then a new employee spins up a storage account in the wrong region on Tuesday, silently breaking that same compliance posture. Regulations themselves change too — new privacy laws, new industry standards, new government requirements — so "we passed our audit last year" tells you almost nothing about today. This is exactly why Microsoft builds tooling (which you'll meet in Phase 5) around continuous assessment and scoring rather than one-time certificates.
Compliance work generally separates into a few related activities: governance (setting the policies and decision rights in the first place), risk management (identifying and prioritizing what could go wrong), and audit (independently verifying that controls are actually working as designed). Together these three make up what the industry calls GRC — governance, risk, and compliance — a term you'll see formally in Phase 2.
⚠️ Exam Trap: A completed audit is a snapshot, not a guarantee. Exam scenarios that describe "we were compliant last quarter" as proof of current compliance are testing whether you understand that compliance requires continuous verification.
Reflection Question: Why might an organization be compliant with a regulation today and non-compliant with that exact same regulation three months from now, without a single regulation having changed?