Platform · Automated control testing
Every control, tested against every record in the period.
Automated control testing runs each of your controls against the full population of accounts and transactions, not a sample, and lists every exception against the record that caused it. The result is signed, so your examiner, your bank or your auditor can check it.
The problem it removes
A sample can only speak for itself
- Sample-based testing pulls twenty-five or sixty items and extrapolates. It can't say which of the records it didn't pull have a problem.
- Testing by hand is slow, so it happens once a year, and a control that broke in March is found the following spring.
- When the data behind a test is incomplete, a sample can quietly pass anyway.
What you see
An exception list, not a percentage
Each run produces a result per control: how many records were in scope, how many were tested, which failed, and why. A record that could not be tested because data was missing is reported as missing, never as a pass.
| Period | In scope | Tested | Exceptions | Data gaps |
|---|---|---|---|---|
| Q2 2026 | 48,212 | 48,190 | 37 | 22 |
| Account | Opened | Result | Rule |
|---|---|---|---|
| AC-0419-8812 | 2026-04-19 | Exception ownership recorded 6 days after opening | 31 CFR 1010.230 |
| AC-0502-1177 | 2026-05-02 | Exception no controller identified | 31 CFR 1010.230 |
| AC-0611-0093 | 2026-06-11 | Data gap entity type field empty | n/a |
| AC-0614-4410 | 2026-06-14 | Pass | 31 CFR 1010.230 |
Illustrative example with invented accounts. Every exception links to the record, the rule and the test that produced it.
How it works
Map, check the data, test, sign
- Map. Each control is tied to the requirements it satisfies in your regulatory inventory, so a test result says which rule it speaks to.
- Check the data. The exports your systems already produce are checked for completeness before any test runs.
- Test. Written rules test every record in the period. The same data gives the same result every time.
- Review and sign. A practitioner reviews the exceptions, decides the ones that need judgment, and signs the run.
Each run is a point-in-time assessment, repeated on the schedule you set, quarterly or monthly.
Guardrails
What it will never do
- It doesn't watch your controls around the clock. It tests them on a schedule, and says so.
- It doesn't test controls we built or fixed for you. That independence is checked before any engagement.
Where it shows up
The work this part does for you
Plain English
What this is, and how anyone does it
Reference articles from our library, cited to the published rules and standards. No sales copy.
- ReferenceControl Testing Methods: Design, Operating Effectiveness and SamplingHow controls are tested under PCAOB, AICPA and IIA methodology: design versus operating effectiveness, test of one, sampling and full-population testing, data-quality checks, and exception documentation.
- Field GuideBSA/AML Independent Testing: The Third PillarThe third pillar in practice: what independent testing covers, who can perform it, how often it runs, and how examiners and sponsor banks read the findings.
Connected parts
What it works with
Talk to a practitioner
Book a 15-minute chat with our founder.
A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.