Platform
Audit & Controls

Internal Controls

One control framework mapped to risks and obligations

Maintain a single, structured library of internal controls — each mapped to the risks it mitigates and the obligations it satisfies, with an owner, a design and an effectiveness status — so control is a managed framework rather than a scattered set of assertions. Controls are the connective tissue of GRC: risk is reduced by controls, compliance is met by controls, and audit tests controls. When they live in disconnected spreadsheets, the same control is documented differently in three places and nobody can say with confidence what is actually mitigating a given risk. OnyxOne Internal Controls makes the framework the shared backbone that risk, compliance and audit all draw on, so a control is defined once, owned by someone, and its effectiveness is known.

At a glance

How it works, visually

Controls, policies & risksSchematic
POLICIESAML policyData protectionSanctions policyCode of conductCONTROLSKYC checksScreeningAccess controlTransaction monitoringApprovalsRISKSFinancial crimeRegulatory breachData lossReputational harmPolicies map to controls; controls mitigate risks — traceable both ways for audit.

How policies map to controls and controls mitigate risks — traceable both ways for audit.

The challenge

The problems this module solves

The operational realities that make this hard for compliance and risk teams today.

Controls are scattered and duplicated

The same control is described in a risk spreadsheet, a compliance matrix and an audit workpaper — each slightly differently. There is no single library, so nobody can say authoritatively what controls exist, what they mitigate, or which of the three versions is correct.

Controls float free of the risks they mitigate

A control exists, but the risk it is supposed to reduce is recorded elsewhere with no link between them. Residual risk is asserted rather than derived from whether the control actually works, and a failed control does not visibly move the risk it was meant to cover.

Ownership and design are unclear

Controls have no named owner, or an owner who has moved on, and the design — what the control does, how often, and what evidences it — is vague. When something goes wrong, it is unclear who was responsible for the control that should have caught it.

One control satisfies many obligations, but nobody can see it

A single access-control or approval process may satisfy several regulatory obligations and frameworks at once, but because obligations and controls are mapped in separate documents, the overlap is invisible. The firm over-builds in some places and leaves gaps in others.

Effectiveness is unknown between audits

The only time a control's effectiveness is assessed is when audit happens to test it. Between those points the framework is a static list of intentions, and management has no live view of which controls are actually operating and which have quietly failed.

The approach

How OnyxOne addresses it

One structured control library

Every control lives once in a single library with a clear description, type, frequency, owner and the evidence that demonstrates it. Risk, compliance and audit all draw on the same definitions, so there is one authoritative answer to what controls exist and what they do.

Controls mapped to risks and obligations

Each control is linked to the risks it mitigates and the obligations and frameworks it satisfies. Residual risk is derived from tested control effectiveness rather than asserted, and the coverage of every risk and obligation by real controls is visible at a glance.

Clear ownership and documented design

Every control has a named owner accountable for its operation and a documented design — what it does, how often, and what evidences it. When a control matters, it is clear who is responsible and exactly what the control is supposed to achieve.

Shared controls, mapped once

A control that satisfies several obligations or frameworks is mapped to all of them from one definition, so the overlap is visible and the firm can rationalise its control set — testing once and satisfying many — instead of duplicating effort and missing gaps.

Live effectiveness, not just at audit

Control effectiveness flows in from testing and attestation on a defined cadence, so the framework shows which controls are operating, which are weak and which have failed — and residual risk updates accordingly — rather than being unknown between audits.

Capabilities

What's in the module

Turn on what you need and add more as your programme scales.

Control library

A single structured register of controls with description, type, frequency, owner and evidencing requirements.

Risk-to-control mapping

Link each control to the risks it mitigates so residual risk derives from real control effectiveness.

Obligation & framework mapping

Map controls to the obligations and frameworks they satisfy, revealing coverage and overlap.

Control ownership

Assign a named owner accountable for each control's operation, attestation and remediation.

Design & operating attributes

Capture what a control does, how often, whether it is preventive or detective, and how it is evidenced.

Effectiveness status

Hold a live design- and operating-effectiveness status fed by testing and attestation.

Control attestation

Require owners to attest that controls are operating on a defined cadence, with exceptions captured.

Key-control designation

Flag the controls that matter most so testing and oversight focus where failure hurts.

Remediation of control gaps

Raise and track actions where controls are missing, weak or failing, through to closure.

Immutable control history

Every control change, mapping, attestation and effectiveness update is versioned and preserved.

Dashboards

The views your team works from

Purpose-built dashboards and views, each answering a question a specific role needs to act on.

An executive viewIllustrative
ILLUSTRATIVE EXAMPLEOPEN CASES128SLA ADHERENCE96%SCREENING ALERTS1.2kOVERDUE REVIEWS14Cases by categoryAMLKYCFraudSanctionsConductOtherRisk mixby tierHighMediumLow

A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.

Control library view

The full control inventory with type, frequency, owner and effectiveness status, filterable by process, risk and obligation.

Coverage map

Risks and obligations against the controls that mitigate and satisfy them, with gaps and over-coverage highlighted.

Effectiveness heatmap

Design and operating effectiveness across the framework, with weak and failed controls surfaced for attention.

Key-control register

The controls designated most critical, their status, ownership and the testing focused on them.

Attestation & remediation board

Outstanding control attestations and open remediation actions by owner and due date, tracked to closure.

Automation

What the platform automates

Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.

Attestation cycles

Control owners are prompted to attest that controls are operating on their cadence, and outstanding attestations are chased automatically.

Effectiveness-to-risk propagation

When a control's effectiveness changes, the residual risk on the risks it mitigates is recalculated without manual re-scoring.

Failed-control remediation

A control that fails testing or attestation automatically raises a remediation action to its owner with a due date.

Coverage-gap alerts

Risks or obligations left without an effective mapped control are flagged automatically so gaps are closed deliberately.

Key-control monitoring

Designated key controls are surfaced for review when their status changes, so critical failures are never buried.

AI assistance

Where AI helps the analyst

Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.

Control-mapping suggestion

Proposes which risks and obligations a control likely relates to from its description, which an owner reviews and confirms before the mapping is set.

Duplicate-control detection

Highlights controls that appear to describe the same activity so the library can be rationalised, with a person deciding what to merge.

Design-description drafting

Drafts a clear control-design description from captured attributes for the owner to refine and approve, improving consistency across the library.

The workflow

The enterprise workflow

A defined, end-to-end process with clear ownership at every stage.

The workflow, step by stepSchematic
01Build the libraryControls are captured once in a structured library with description, type,frequency, owner and how each is evidenced.02Map to risks & obligationsEach control is linked to the risks it mitigates and the obligations and frameworksit satisfies, exposing coverage and overlap.03Assign ownershipEvery control is given a named owner accountable for its operation, and key controlsare designated for closer oversight.04Assess effectivenessDesign and operating effectiveness are assessed through testing and attestation on adefined cadence, updating each control's status.05Derive residual riskResidual risk on linked risks reflects real control effectiveness, so a weak orfailed control visibly moves the risk it covers.06Remediate gapsMissing, weak or failing controls raise remediation actions with owners and dates,tracked to closure and re-assessment.

Every result, decision and override is captured against the record it belongs to.

01

Build the library

Controls are captured once in a structured library with description, type, frequency, owner and how each is evidenced.

02

Map to risks & obligations

Each control is linked to the risks it mitigates and the obligations and frameworks it satisfies, exposing coverage and overlap.

03

Assign ownership

Every control is given a named owner accountable for its operation, and key controls are designated for closer oversight.

04

Assess effectiveness

Design and operating effectiveness are assessed through testing and attestation on a defined cadence, updating each control's status.

05

Derive residual risk

Residual risk on linked risks reflects real control effectiveness, so a weak or failed control visibly moves the risk it covers.

06

Remediate gaps

Missing, weak or failing controls raise remediation actions with owners and dates, tracked to closure and re-assessment.

The value

What your team gains

Single library

One authoritative control set

Controls defined once and shared by risk, compliance and audit end the three-versions problem and give one answer to what controls exist.

Mapped

Coverage you can see

Controls linked to risks and obligations make coverage and gaps visible, so the firm knows exactly what is mitigating each risk.

Owned

Clear accountability

Every control has a named owner and documented design, so it is always clear who is responsible and what the control is meant to do.

Live

Effectiveness known, not assumed

Effectiveness fed by testing and attestation means management sees which controls actually operate rather than a static list of intentions.

Test once, satisfy many

Mapping shared controls to all the obligations they satisfy lets the firm rationalise its control set and avoid duplicated testing and effort.

Residual risk grounded in reality

Deriving residual risk from tested effectiveness means a failed control moves the risk it covers, rather than leaving risk asserted on paper.

Built for

Industries it serves

BankingFinancial ServicesInsuranceInvestment FirmsFintechHealthcareManufacturingPublic SectorRegulated Enterprises
Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.

Enterprise & operational risk
  • Links controls to the risks they mitigate in the enterprise and operational risk registers so residual risk reflects control effectiveness
Compliance management
  • Maps controls to the obligations and frameworks they satisfy so compliance coverage draws on the same control set
Control testing
  • Feeds design and operating-effectiveness results from the control-testing module back into each control's live status
Audit
  • Shares the control framework with audit so engagements and findings reference the same authoritative controls
Collaboration & notification
  • Routes attestation requests, remediation actions and reminders through your existing email and messaging tools
Assurance

Security, compliance & reporting

Security & data handling

  • The control library, mappings and effectiveness data are encrypted in transit and at rest, with access governed by granular, role-based permissions.
  • Control ownership and attestation are attributable, so who owns and who attested to each control is always clear.
  • Segregation of duties can prevent a control owner from also signing off the testing of their own control where policy requires independence.
  • Every control change, mapping, attestation and effectiveness update is written to an append-only audit trail.
  • Data residency and retention for control records are configurable to your regulatory and internal-policy obligations.

Compliance support

  • Supports an internal-control framework aligned to recognised models such as COSO Internal Control and, for IT controls, COBIT
  • Underpins control mapping for obligations across frameworks the firm is subject to
  • Provides the control design, ownership and effectiveness evidence expected by audit and regulators
  • Supports the first and second lines within a three-lines-of-defence model
  • Supplies documented, dated control evidence for internal and external audit
  • OnyxOne is a technology vendor — responsibility for control design and operation remains with your organisation

Reports & exports

  • Control library and control-inventory reports
  • Risk-to-control and obligation-to-control coverage reports
  • Control-effectiveness status and failed-control reports
  • Key-control register and attestation-completion reports
  • Control-gap and remediation-status reports
  • Control-framework management information for risk and audit committees
Best practice

How to get the most from it

Define each control once

Keep a single library and have risk, compliance and audit reference it, rather than each maintaining their own. One authoritative definition ends the reconciliation problem before it starts.

Map controls to what they mitigate and satisfy

Link every control to its risks and obligations. Coverage and overlap only become visible — and residual risk only becomes real — once the mappings exist.

Give every control an owner

An unowned control is a control nobody is operating. A named owner accountable for operation, attestation and remediation is the difference between a framework and a wish list.

Focus effort on key controls

Designate the controls that matter most and concentrate testing and oversight there. Treating every control as equally critical spreads assurance too thin to catch the failures that count.

FAQ

Questions, answered

What makes this a framework rather than a list?

Every control is defined once, given an owner and a documented design, and mapped to the risks it mitigates and the obligations it satisfies, with a live effectiveness status. That mapping and ownership is what turns a static inventory into a managed framework that risk, compliance and audit all draw on.

How does control effectiveness stay current?

Design and operating-effectiveness results flow in from the control-testing module and from owner attestations on a defined cadence. Each control carries a live status, and because controls are linked to risks, a weak or failed control visibly moves the residual risk it was meant to cover.

Can one control satisfy several obligations?

Yes, and making that visible is a core benefit. A control is defined once and mapped to all the obligations and frameworks it satisfies, so the firm can see the overlap, test once to satisfy many, and rationalise a control set that would otherwise be duplicated across documents.

How does this relate to control testing and audit?

Internal Controls holds the authoritative framework. Control Testing assesses whether those controls work and feeds the results back. Audit references the same controls when it plans engagements and raises findings. All three share one control set instead of maintaining separate copies.

Does OnyxOne operate the controls?

No. OnyxOne is a technology vendor that gives you the framework to define, own, map and assess controls. The controls themselves are designed and operated by your organisation; responsibility for their design and operation remains with you.

See Internal Controls in your programme

Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.