Control Testing
Test control design and operating effectiveness on a schedule
Plan and perform control tests on a defined cadence, capture results, evidence and exceptions, and feed operating-effectiveness outcomes straight back into residual risk — so control assurance is evidenced rather than assumed. A control that is documented but never tested is only an intention; assurance comes from evidence that it actually works. OnyxOne Control Testing turns testing into a managed, repeatable programme: tests scheduled by risk and control criticality, executed against defined procedures, exceptions raised and remediated, and every result written back to the control it assessed and the risk it affects, so the whole organisation sees a live picture of what is genuinely working.
How it works, visually
How policies map to controls and controls mitigate risks — traceable both ways for audit.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Controls are assumed to work until they don't
Most controls are documented once and never tested. The framework looks complete on paper, but nobody has evidence that the controls actually operate, so the first sign of failure is often the incident the control was meant to prevent.
Testing is ad hoc and inconsistent
When testing does happen, the procedure, sample and standard vary by tester and by cycle. Two people testing the same control reach different conclusions, and the firm cannot show that testing is performed to a consistent, repeatable standard.
Results don't reach the risk picture
A control fails a test, the result is noted in a workpaper, and the residual risk the control was supposed to mitigate carries on showing green. Testing outcomes and the risk register live apart, so a known control failure does not move the risk it affects.
Exceptions are found but not driven to closure
Testing surfaces exceptions and deficiencies, but follow-up depends on whoever remembers. Remediation drifts, the same deficiency reappears next cycle, and testing becomes a ritual that documents problems without resolving them.
Coverage and cadence are invisible
Nobody can easily say which controls were tested, when they are next due, or whether the key controls are covered at all. Testing effort is not demonstrably aligned to risk, and gaps in coverage only surface when an auditor points them out.
How OnyxOne addresses it
A scheduled, risk-based testing programme
Tests are scheduled on a cadence set by control criticality and the risk behind them, so key controls are tested more often and coverage across the framework is planned rather than accidental. The programme is visible: what is due, what is done, and where the gaps are.
Defined test procedures and consistent execution
Each control is tested against a defined procedure — the steps, the sample approach, the pass criteria — so testing is repeatable and comparable regardless of who performs it. Design and operating effectiveness are assessed distinctly, and the standard holds from cycle to cycle.
Results fed straight into residual risk
Operating-effectiveness outcomes write back to the control and the risks it mitigates, so a failed test moves the residual risk it affects instead of leaving it green. The risk picture reflects what testing actually found rather than what the framework hoped.
Exceptions raised and driven to closure
Exceptions and deficiencies raise remediation actions with owners and due dates, tracked through follow-up and re-testing. Testing does not just document a deficiency; it drives it to resolution and verifies the fix before the exception is closed.
Evidence captured once, reusable everywhere
Test evidence is captured against the control and preserved on an immutable trail, reusable by audit and other assurance activities. Evidence is gathered once and produced on demand, rather than re-collected every time a different function asks the same question.
What's in the module
Turn on what you need and add more as your programme scales.
Test planning & scheduling
Schedule control tests on a cadence set by control criticality and the underlying risk, with coverage planned across the framework.
Test procedures
Define the steps, sample approach and pass criteria for each control so testing is repeatable and comparable.
Design vs operating effectiveness
Assess whether a control is well designed and whether it actually operates, as distinct conclusions.
Sampling
Support risk-based and statistical sampling so operating-effectiveness conclusions rest on an appropriate basis.
Evidence capture
Attach test evidence to the control and the result, preserved on an immutable trail and reusable across assurance.
Exception & deficiency management
Raise exceptions from failed tests, rate them, and drive remediation through to closure and re-testing.
Effectiveness write-back
Feed operating-effectiveness outcomes into the control framework and the residual risk of linked risks.
Re-testing
Re-test remediated controls to verify the deficiency is resolved before an exception is closed.
Tester independence & review
Support maker-checker review of test work and keep testers independent of the controls they own.
Immutable testing trail
Every test, result, exception, evidence item and re-test is versioned and preserved for audit.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Testing programme view
Tests planned, in progress, completed and overdue across the framework, with coverage aligned to control criticality and risk.
Effectiveness results
Design and operating-effectiveness outcomes by control and process, with failures and weak controls surfaced.
Exception board
Open exceptions and deficiencies by severity, owner and due date, tracked through remediation and re-testing to closure.
Coverage & cadence tracker
Which controls are tested, when each is next due, and whether key controls are covered — so gaps are visible early.
Assurance dashboard
A live view of control assurance for risk and audit committees, drawn from real testing results rather than assertion.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Test scheduling
Tests are generated and assigned on their cadence by control criticality and risk, and overdue tests are chased automatically.
Effectiveness write-back
A recorded test result updates the control's effectiveness status and recalculates residual risk on linked risks without manual re-entry.
Exception-to-remediation
A failed test automatically raises a rated exception and a remediation action to the control owner with a due date.
Re-test triggering
Closing a remediation action schedules the re-test needed to verify the fix before the exception can be closed.
Overdue & coverage alerts
Overdue tests and untested key controls are flagged automatically so coverage gaps do not accumulate unnoticed.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Sample-selection assistance
Suggests a risk-based sample for a test from the population attributes, which the tester reviews and adjusts before executing.
Exception-severity suggestion
Proposes a severity rating for a deficiency from its characteristics and linked risk, leaving the tester to confirm and own the rating.
Result-summary drafting
Drafts the conclusion and exception narrative from captured test evidence for the tester to verify, edit and sign off.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Plan the programme
Tests are scheduled by control criticality and underlying risk, so coverage across the framework is deliberate and key controls are tested most.
Define the test
Each control's test procedure — steps, sample approach and pass criteria — is set so execution is repeatable and comparable.
Execute & evidence
The tester performs the procedure, captures evidence against the control, and records design and operating-effectiveness conclusions.
Raise exceptions
Failed tests raise rated exceptions with remediation actions, owners and due dates against the control that failed.
Update risk
Operating-effectiveness outcomes write back to the control and the residual risk of the risks it mitigates.
Remediate & re-test
Remediation is tracked to closure and the control is re-tested to verify the fix before the exception is closed.
What your team gains
Assurance on a cadence
Tests planned by control criticality and risk mean coverage is deliberate and key controls are assured regularly, not tested by chance.
Consistent testing standard
Defined procedures and pass criteria make testing comparable from tester to tester and cycle to cycle, so conclusions can be trusted.
Failures that move risk
Feeding operating effectiveness back into residual risk means a failed control changes the risk it affects rather than staying green on paper.
Deficiencies resolved, not just noted
Exceptions raise tracked remediation and re-testing, so testing drives problems to resolution instead of cataloguing them.
Evidence gathered once
Test evidence captured against the control and reusable across audit and assurance means the same evidence is not collected again and again.
Coverage you can prove
A visible programme of what was tested and when demonstrates that assurance is aligned to risk rather than left to chance.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Tests the controls held in the internal-controls framework and writes design and operating-effectiveness results back to each control
- Feeds operating-effectiveness outcomes into residual risk on the risks each tested control mitigates
- Stores and reuses test evidence through the evidence-management module so it is captured once and produced on demand
- Shares testing results and evidence with audit so engagements can rely on second-line testing where appropriate
- Routes test assignments, exception remediation and re-test reminders through your existing email and messaging tools
Security, compliance & reporting
Security & data handling
- Test plans, results, evidence and exceptions are encrypted in transit and at rest, with access governed by granular, role-based permissions.
- Test conclusions and evidence are attributable, so who tested a control and reached which conclusion is always clear.
- Segregation of duties keeps testers independent of the controls they own, so a control cannot be self-tested where policy requires independence.
- Every test, result, exception, evidence item and re-test is written to an append-only audit trail.
- Data residency and retention for testing records are configurable to your regulatory and internal-policy obligations.
Compliance support
- Supports control-testing practice aligned to recognised internal-control models such as COSO
- Underpins second-line control assurance and testing within a three-lines-of-defence model
- Provides design and operating-effectiveness evidence expected by audit and regulators
- Supports management assertions on the effectiveness of internal control where required
- Supplies documented, dated, sampled testing evidence for internal and external audit
- OnyxOne is a technology vendor — responsibility for testing conclusions remains with your assurance functions
Reports & exports
- Test-plan and coverage reports by control, process and risk
- Design and operating-effectiveness result reports
- Exception and deficiency reports with severity and status
- Remediation and re-test outcome reports
- Testing-programme progress and overdue-test reports
- Control-assurance management information for risk and audit committees
How to get the most from it
Schedule testing by risk, not evenly
Test key controls behind high risks more often, and lower-criticality controls less. Even coverage wastes effort on controls that barely matter while under-testing the ones whose failure hurts.
Separate design from operation
Ask both whether a control is well designed and whether it actually operates. A control can be beautifully designed and never run, or run diligently while being the wrong control — the two conclusions are different.
Write results back to risk
Make every operating-effectiveness outcome flow into residual risk. A failed control that leaves the risk green defeats the whole point of testing.
Close exceptions with re-testing
Do not close a deficiency on the promise of a fix — re-test to confirm it worked. Verified remediation is the only remediation that changes the assurance picture.
Questions, answered
What is the difference between design and operating effectiveness?
Design effectiveness asks whether a control, if it operates as intended, would actually mitigate the risk. Operating effectiveness asks whether it is in fact operating that way in practice. OnyxOne assesses them as distinct conclusions, because a well-designed control that is not being performed and a poorly-designed control that is diligently performed are different problems.
How do testing results affect risk?
Operating-effectiveness outcomes write back to the tested control and to the residual risk of the risks it mitigates. A control that fails testing moves the residual risk it was meant to cover, so the risk picture reflects what testing actually found rather than staying green on the strength of a documented control.
How are exceptions handled?
A failed test raises a rated exception with a remediation action, owner and due date against the control that failed. Remediation is tracked to closure, and the control is re-tested to verify the deficiency is resolved before the exception is closed — so testing drives problems to resolution rather than merely recording them.
Can test evidence be reused?
Yes. Test evidence is captured against the control and preserved on an immutable trail through evidence management, so it can be reused by audit and other assurance activities. Evidence is gathered once and produced on demand instead of being re-collected every time a different function asks.
Does OnyxOne decide whether a control passed?
No. OnyxOne structures the test, captures the evidence and records the conclusion, but the tester reaches and owns the pass/fail judgement under review. OnyxOne is a technology vendor and decision-support software; responsibility for testing conclusions remains with your assurance functions.
Related modules
See Control Testing in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.