What the Function Maintains
Incidents, close-calls and Sunset post-mortems feed a loop that refines the framework; methodology evolves on documented triggers.
One-Page Posture Statement Row
The Auditor's Question
"Show me how your framework has evolved in the past 12 months and what triggered each revision."
Editorial Framing
Continuous learning is Element 5 because it is the loop that closes. Incidents, close-calls and Sunset post-mortems feed the framework; methodology evolves on documented triggers. A function with continuous learning improves quarter on quarter; a function without operates the same framework today as 12 months ago, regardless of what it has learned.
Cross-cutting across all 9 Risk Taxonomy classes — Continuous learning is most active in Sunset because the post-mortem closes the cycle, but it operates across Operate as well.
Evidence Artefacts
- Incident response log
- Close-call disclosure mechanism activity
- Sunset post-mortem record
- Methodology version history with documented triggers
- Quarterly framework refinement log
Common Failure Modes
- Incidents handled but not fed into methodology revision
- Close-call disclosure mechanism exists but is unused (punitive culture)
- Sunset post-mortem skipped — the learnings die with the capability
- Methodology revisions ungated — changes happen without documented triggers