Automated control testing
Twenty-five files tell you about twenty-five files. Test every record.
Control testing on the full population of your records, run on the schedule you set, with every exception listed against the record that caused it and every finding priced in dollars.
Your problem
You cannot say whether a control works on the records nobody pulled
- Most control testing pulls twenty-five items, tests them by hand and extrapolates to the rest.
- It runs once a year, so a control that broke in March is found the following spring.
- Your sponsor bank, your examiner and your board all ask the same question: does the control work on the records you actually have?
- A clean sample result isn't an answer to that question, and everyone in the room knows it.
What you get
An answer about every record, not an estimate
- An exception list for each control, record by record, so the fix starts with names and account numbers rather than a percentage.
- Work papers an examiner or internal auditor can follow from the population to the result.
- Every finding cited and priced, so remediation is ordered by what each gap is worth.
- A signed report for each run, and a tested population your independent tester can rely on.
How we do it
Map, check the data, test, repeat
- We map each control to the requirements it satisfies, from your regulatory inventory.
- We take the exports your systems already produce and check the data before any test runs, so a gap in the data is reported as a gap in the data, not as a clean result.
- The engine tests every control against every record in the period and lists each exception with the record that caused it.
- It runs again on the schedule you set, quarterly or monthly. Each run is a point-in-time assessment of the full population.
- We never test controls we built or fixed for you. Remediation is a separate engagement.
What the testing runs against
A regulatory inventory built from your facts
Before anything is tested, the engine builds the regulatory regulatory inventory for your company: every requirement that applies to you, cited to the rule, with the facts behind each one labelled by how we know them.
The inventory is delivered with the engagement, and it's the list your examiner can walk through line by line.
How the work is done
The audit you already buy, performed by an engine.
- Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
- Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
- Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
- A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.
Pricing
The testing you already fund, on every record
This replaces sample-based control testing, whether it sits with internal audit, a second-line testing team or an outside firm.
Price: Priced at scoping. How pricing works
The published method
How this is normally done
The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.
- ReferenceControl Testing Methods: Design, Operating Effectiveness and SamplingHow controls are tested under PCAOB, AICPA and IIA methodology: design versus operating effectiveness, test of one, sampling and full-population testing, data-quality checks, and exception documentation.
- Field GuideDesign vs. Operating Effectiveness: The Two Scores That Decide a Training-Program AuditHow auditors grade a training program on two separate scores: design effectiveness (the program as written) and operating effectiveness (the program as run). The regulatory floor, and where best practice takes over.
- ReferenceAudit Evidence and Workpapers: What They Are and What They ContainWhat audit evidence and workpapers are, the documentation standards that govern them, what a workpaper contains, retention, integrity controls, and how examiners use them.
What happens next
Three steps from here.
- 01
A scoping call
Which controls matter most, which systems hold the records, and how often you want them tested.
- 02
A data check
We look at a sample of your exports first and tell you plainly what can be tested and what cannot.
- 03
The first run
Every control against every record in the period, with the exception lists, the work papers and a signed report.