Platform
Audit & Controls

Control Testing

Test control design and operating effectiveness on a schedule

Plan and perform control tests on a defined cadence, capture results, evidence and exceptions, and feed operating-effectiveness outcomes straight back into residual risk — so control assurance is evidenced rather than assumed. A control that is documented but never tested is only an intention; assurance comes from evidence that it actually works. OnyxOne Control Testing turns testing into a managed, repeatable programme: tests scheduled by risk and control criticality, executed against defined procedures, exceptions raised and remediated, and every result written back to the control it assessed and the risk it affects, so the whole organisation sees a live picture of what is genuinely working.

At a glance

How it works, visually

Controls, policies & risksSchematic
POLICIESAML policyData protectionSanctions policyCode of conductCONTROLSKYC checksScreeningAccess controlTransaction monitoringApprovalsRISKSFinancial crimeRegulatory breachData lossReputational harmPolicies map to controls; controls mitigate risks — traceable both ways for audit.

How policies map to controls and controls mitigate risks — traceable both ways for audit.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Controls are assumed to work until they don't

Most controls are documented once and never tested. The framework looks complete on paper, but nobody has evidence that the controls actually operate, so the first sign of failure is often the incident the control was meant to prevent.

Testing is ad hoc and inconsistent

When testing does happen, the procedure, sample and standard vary by tester and by cycle. Two people testing the same control reach different conclusions, and the firm cannot show that testing is performed to a consistent, repeatable standard.

Results don't reach the risk picture

A control fails a test, the result is noted in a workpaper, and the residual risk the control was supposed to mitigate carries on showing green. Testing outcomes and the risk register live apart, so a known control failure does not move the risk it affects.

Exceptions are found but not driven to closure

Testing surfaces exceptions and deficiencies, but follow-up depends on whoever remembers. Remediation drifts, the same deficiency reappears next cycle, and testing becomes a ritual that documents problems without resolving them.

Coverage and cadence are invisible

Nobody can easily say which controls were tested, when they are next due, or whether the key controls are covered at all. Testing effort is not demonstrably aligned to risk, and gaps in coverage only surface when an auditor points them out.

The approach

How OnyxOne addresses it

A scheduled, risk-based testing programme

Tests are scheduled on a cadence set by control criticality and the risk behind them, so key controls are tested more often and coverage across the framework is planned rather than accidental. The programme is visible: what is due, what is done, and where the gaps are.

Defined test procedures and consistent execution

Each control is tested against a defined procedure — the steps, the sample approach, the pass criteria — so testing is repeatable and comparable regardless of who performs it. Design and operating effectiveness are assessed distinctly, and the standard holds from cycle to cycle.

Results fed straight into residual risk

Operating-effectiveness outcomes write back to the control and the risks it mitigates, so a failed test moves the residual risk it affects instead of leaving it green. The risk picture reflects what testing actually found rather than what the framework hoped.

Exceptions raised and driven to closure

Exceptions and deficiencies raise remediation actions with owners and due dates, tracked through follow-up and re-testing. Testing does not just document a deficiency; it drives it to resolution and verifies the fix before the exception is closed.

Evidence captured once, reusable everywhere

Test evidence is captured against the control and preserved on an immutable trail, reusable by audit and other assurance activities. Evidence is gathered once and produced on demand, rather than re-collected every time a different function asks the same question.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Test planning & scheduling

Schedule control tests on a cadence set by control criticality and the underlying risk, with coverage planned across the framework.

Test procedures

Define the steps, sample approach and pass criteria for each control so testing is repeatable and comparable.

Design vs operating effectiveness

Assess whether a control is well designed and whether it actually operates, as distinct conclusions.

Sampling

Support risk-based and statistical sampling so operating-effectiveness conclusions rest on an appropriate basis.

Evidence capture

Attach test evidence to the control and the result, preserved on an immutable trail and reusable across assurance.

Exception & deficiency management

Raise exceptions from failed tests, rate them, and drive remediation through to closure and re-testing.

Effectiveness write-back

Feed operating-effectiveness outcomes into the control framework and the residual risk of linked risks.

Re-testing

Re-test remediated controls to verify the deficiency is resolved before an exception is closed.

Tester independence & review

Support maker-checker review of test work and keep testers independent of the controls they own.

Immutable testing trail

Every test, result, exception, evidence item and re-test is versioned and preserved for audit.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Testing programme view

Tests planned, in progress, completed and overdue across the framework, with coverage aligned to control criticality and risk.

Effectiveness results

Design and operating-effectiveness outcomes by control and process, with failures and weak controls surfaced.

Exception board

Open exceptions and deficiencies by severity, owner and due date, tracked through remediation and re-testing to closure.

Coverage & cadence tracker

Which controls are tested, when each is next due, and whether key controls are covered — so gaps are visible early.

Assurance dashboard

A live view of control assurance for risk and audit committees, drawn from real testing results rather than assertion.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Test scheduling

Tests are generated and assigned on their cadence by control criticality and risk, and overdue tests are chased automatically.

Effectiveness write-back

A recorded test result updates the control's effectiveness status and recalculates residual risk on linked risks without manual re-entry.

Exception-to-remediation

A failed test automatically raises a rated exception and a remediation action to the control owner with a due date.

Re-test triggering

Closing a remediation action schedules the re-test needed to verify the fix before the exception can be closed.

Overdue & coverage alerts

Overdue tests and untested key controls are flagged automatically so coverage gaps do not accumulate unnoticed.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Sample-selection assistance

Suggests a risk-based sample for a test from the population attributes, which the tester reviews and adjusts before executing.

Exception-severity suggestion

Proposes a severity rating for a deficiency from its characteristics and linked risk, leaving the tester to confirm and own the rating.

Result-summary drafting

Drafts the conclusion and exception narrative from captured test evidence for the tester to verify, edit and sign off.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Plan the programmeTests are scheduled by control criticality and underlying risk, so coverage acrossthe framework is deliberate and key controls are tested most.02Define the testEach control's test procedure — steps, sample approach and pass criteria — is set soexecution is repeatable and comparable.03Execute & evidenceThe tester performs the procedure, captures evidence against the control, andrecords design and operating-effectiveness conclusions.04Raise exceptionsFailed tests raise rated exceptions with remediation actions, owners and due datesagainst the control that failed.05Update riskOperating-effectiveness outcomes write back to the control and the residual risk ofthe risks it mitigates.06Remediate & re-testRemediation is tracked to closure and the control is re-tested to verify the fixbefore the exception is closed.

Every result, decision and override is captured against the record it belongs to.

01

Plan the programme

Tests are scheduled by control criticality and underlying risk, so coverage across the framework is deliberate and key controls are tested most.

02

Define the test

Each control's test procedure — steps, sample approach and pass criteria — is set so execution is repeatable and comparable.

03

Execute & evidence

The tester performs the procedure, captures evidence against the control, and records design and operating-effectiveness conclusions.

04

Raise exceptions

Failed tests raise rated exceptions with remediation actions, owners and due dates against the control that failed.

05

Update risk

Operating-effectiveness outcomes write back to the control and the residual risk of the risks it mitigates.

06

Remediate & re-test

Remediation is tracked to closure and the control is re-tested to verify the fix before the exception is closed.

The value

What your team gains

Scheduled

Assurance on a cadence

Tests planned by control criticality and risk mean coverage is deliberate and key controls are assured regularly, not tested by chance.

Repeatable

Consistent testing standard

Defined procedures and pass criteria make testing comparable from tester to tester and cycle to cycle, so conclusions can be trusted.

Connected

Failures that move risk

Feeding operating effectiveness back into residual risk means a failed control changes the risk it affects rather than staying green on paper.

Closed

Deficiencies resolved, not just noted

Exceptions raise tracked remediation and re-testing, so testing drives problems to resolution instead of cataloguing them.

Evidence gathered once

Test evidence captured against the control and reusable across audit and assurance means the same evidence is not collected again and again.

Coverage you can prove

A visible programme of what was tested and when demonstrates that assurance is aligned to risk rather than left to chance.

Built for

Industries it serves

BankingFinancial ServicesInsuranceInvestment FirmsFintechHealthcareManufacturingPublic SectorRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Internal controls
  • Tests the controls held in the internal-controls framework and writes design and operating-effectiveness results back to each control
Enterprise & operational risk
  • Feeds operating-effectiveness outcomes into residual risk on the risks each tested control mitigates
Evidence management
  • Stores and reuses test evidence through the evidence-management module so it is captured once and produced on demand
Audit
  • Shares testing results and evidence with audit so engagements can rely on second-line testing where appropriate
Collaboration & notification
  • Routes test assignments, exception remediation and re-test reminders through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • Test plans, results, evidence and exceptions are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Test conclusions and evidence are attributable, so who tested a control and reached which conclusion is always clear.
  • Segregation of duties keeps testers independent of the controls they own, so a control cannot be self-tested where policy requires independence.
  • Every test, result, exception, evidence item and re-test is written to an append-only audit trail.
  • Data residency and retention for testing records are configurable to your regulatory and internal-policy obligations.

Compliance support

  • Supports control-testing practice aligned to recognised internal-control models such as COSO
  • Underpins second-line control assurance and testing within a three-lines-of-defence model
  • Provides design and operating-effectiveness evidence expected by audit and regulators
  • Supports management assertions on the effectiveness of internal control where required
  • Supplies documented, dated, sampled testing evidence for internal and external audit
  • OnyxOne is a technology vendor — responsibility for testing conclusions remains with your assurance functions

Reports & exports

  • Test-plan and coverage reports by control, process and risk
  • Design and operating-effectiveness result reports
  • Exception and deficiency reports with severity and status
  • Remediation and re-test outcome reports
  • Testing-programme progress and overdue-test reports
  • Control-assurance management information for risk and audit committees
Best practice

How to get the most from it

Schedule testing by risk, not evenly

Test key controls behind high risks more often, and lower-criticality controls less. Even coverage wastes effort on controls that barely matter while under-testing the ones whose failure hurts.

Separate design from operation

Ask both whether a control is well designed and whether it actually operates. A control can be beautifully designed and never run, or run diligently while being the wrong control — the two conclusions are different.

Write results back to risk

Make every operating-effectiveness outcome flow into residual risk. A failed control that leaves the risk green defeats the whole point of testing.

Close exceptions with re-testing

Do not close a deficiency on the promise of a fix — re-test to confirm it worked. Verified remediation is the only remediation that changes the assurance picture.

FAQ

Questions, answered

What is the difference between design and operating effectiveness?

Design effectiveness asks whether a control, if it operates as intended, would actually mitigate the risk. Operating effectiveness asks whether it is in fact operating that way in practice. OnyxOne assesses them as distinct conclusions, because a well-designed control that is not being performed and a poorly-designed control that is diligently performed are different problems.

How do testing results affect risk?

Operating-effectiveness outcomes write back to the tested control and to the residual risk of the risks it mitigates. A control that fails testing moves the residual risk it was meant to cover, so the risk picture reflects what testing actually found rather than staying green on the strength of a documented control.

How are exceptions handled?

A failed test raises a rated exception with a remediation action, owner and due date against the control that failed. Remediation is tracked to closure, and the control is re-tested to verify the deficiency is resolved before the exception is closed — so testing drives problems to resolution rather than merely recording them.

Can test evidence be reused?

Yes. Test evidence is captured against the control and preserved on an immutable trail through evidence management, so it can be reused by audit and other assurance activities. Evidence is gathered once and produced on demand instead of being re-collected every time a different function asks.

Does OnyxOne decide whether a control passed?

No. OnyxOne structures the test, captures the evidence and records the conclusion, but the tester reaches and owns the pass/fail judgement under review. OnyxOne is a technology vendor and decision-support software; responsibility for testing conclusions remains with your assurance functions.

See Control Testing in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.