Skip to content

Automated control testing

Twenty-five files tell you about twenty-five files. Test every record.

Control testing on the full population of your records, run on the schedule you set, with every exception listed against the record that caused it and every finding priced in dollars.

Your problem

You cannot say whether a control works on the records nobody pulled

  • Most control testing pulls twenty-five items, tests them by hand and extrapolates to the rest.
  • It runs once a year, so a control that broke in March is found the following spring.
  • Your sponsor bank, your examiner and your board all ask the same question: does the control work on the records you actually have?
  • A clean sample result isn't an answer to that question, and everyone in the room knows it.

What you get

An answer about every record, not an estimate

  • An exception list for each control, record by record, so the fix starts with names and account numbers rather than a percentage.
  • Work papers an examiner or internal auditor can follow from the population to the result.
  • Every finding cited and priced, so remediation is ordered by what each gap is worth.
  • A signed report for each run, and a tested population your independent tester can rely on.

How we do it

Map, check the data, test, repeat

  • We map each control to the requirements it satisfies, from your regulatory inventory.
  • We take the exports your systems already produce and check the data before any test runs, so a gap in the data is reported as a gap in the data, not as a clean result.
  • The engine tests every control against every record in the period and lists each exception with the record that caused it.
  • It runs again on the schedule you set, quarterly or monthly. Each run is a point-in-time assessment of the full population.
  • We never test controls we built or fixed for you. Remediation is a separate engagement.

What the testing runs against

A regulatory inventory built from your facts

Before anything is tested, the engine builds the regulatory regulatory inventory for your company: every requirement that applies to you, cited to the rule, with the facts behind each one labelled by how we know them.

The inventory is delivered with the engagement, and it's the list your examiner can walk through line by line.

How the work is done

The audit you already buy, performed by an engine.

  1. Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
  2. Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
  3. Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
  4. A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.

Pricing

The testing you already fund, on every record

This replaces sample-based control testing, whether it sits with internal audit, a second-line testing team or an outside firm.

Price: Priced at scoping. How pricing works

The published method

How this is normally done

The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.

What happens next

Three steps from here.

  1. 01

    A scoping call

    Which controls matter most, which systems hold the records, and how often you want them tested.

  2. 02

    A data check

    We look at a sample of your exports first and tell you plainly what can be tested and what cannot.

  3. 03

    The first run

    Every control against every record in the period, with the exception lists, the work papers and a signed report.

Ask for a quote