Solutions
Governance & Assurance

Audit & Assurance

Test controls, capture evidence, and prove the programme works

Assurance is how a firm proves — to itself, its board and its regulators — that its controls actually operate. This programme composes audit management, control testing and evidence management into one assurance function, so controls are tested on a plan, findings are tracked to closure, and the evidence lives against the control it proves. Audit readiness becomes a property of how work is captured, not a project before a review.

At a glance

One programme, on one platform

Audit & Assurance on OnyxOneSchematic
Your teamsCompliance · risk · legalAnalysts & investigatorsScreen, review and decideOversight & approvalsSign-off and reportingOnyxOneCompliance & risk OSScreening · Due diligenceCases · Risk · MonitoringPolicy · Reporting · AuditSystems & sourcesConfigured per deploymentScreening data providersSanctions · PEP · mediaYour systems of recordOnboarding · core systemsOne platform for the whole programme — not a stack of disconnected tools and spreadsheets.

Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.

The programme

What this programme is, and why it matters

A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.

Oversight & the three lines of defenceSchematic
Board & audit committeeSets risk appetite · holds the programme accountable1st lineOperational managementOwns and manages risk dayto day2nd lineRisk & complianceSets policy, oversees andmonitors3rd lineInternal auditIndependent, objectiveassuranceExternal audit & regulators

How accountability is structured across the first line, risk and compliance, and independent assurance — the model the programme supports.

Assurance over the same controls the business runs

The programme tests against the shared control library the governance and risk programmes use, so the third line is assuring the exact controls the first line operates — not a separate, divergent list. Findings land where they matter.

Evidence against the control it proves

Every test captures its evidence against the control record, so the proof that a control works is never separated from the control itself — and never has to be reconstructed when an auditor or regulator asks.

Findings tracked to closure

Testing that surfaces a weakness only adds value if the weakness is fixed. The programme tracks findings with owners, actions and deadlines through to verified closure, so assurance drives improvement rather than just observation.

Independent, but connected

The assurance function keeps its independence while working on the same platform as the rest of the programme — so it draws on real control and risk data instead of requesting it, and its results feed straight into board reporting.

The challenge

What makes this hard today

The operational realities this programme is designed to resolve.

Assurance on a parallel universe

When audit tests a separate copy of the controls, findings don't map to what the business runs and improvement stalls.

Evidence scattered and stale

Test evidence held in folders and email cannot be tied reliably to the control it proves, and goes out of date.

Findings that never close

Weaknesses tracked in spreadsheets lose owners and deadlines, so the same issues recur review after review.

Testing as an annual scramble

Assurance treated as a periodic project means readiness is rebuilt each cycle rather than maintained continuously.

No line of sight for the board

Without connected data, the board sees assurance results late and in fragments rather than as a current picture.

How it works

The operating model, at a glance

How the composed programme runs — from the data it takes in to the decisions and evidence it produces.

A representative flowSchematic
Item receivedOnboarding / eventRiskthreshold?Auto-clearLow risk · loggedEscalate to reviewAnalyst investigatesRecord &auditNoYes — parallel review paths

Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.

01

Plan the assurance

Build a risk-based audit and testing plan against the shared control library, with scope, owners and cadence.

02

Test the controls

Execute control tests, capturing method, sample, result and evidence against each control record.

03

Raise findings

Where a control falls short, raise a finding with severity, owner and remediation action.

04

Track to closure

Drive findings through remediation to verified closure, with progress recorded against the finding.

05

Report assurance

Report testing coverage, results and open findings to the audit committee and board from live data.

Capabilities

What the programme gives you

The concrete capabilities the composed programme provides, end to end.

Risk-based audit planning

Build and manage an assurance plan against the shared control library, scoped and prioritised by risk.

Control testing

Execute tests with defined method and sampling, recording result and evidence against each control.

Evidence management

Capture and hold test evidence against the control it proves, so proof is never separated from the control.

Findings & remediation

Raise findings with severity and owner and track them through remediation to verified closure.

Assurance coverage

See which controls have been tested, when and with what result, so assurance coverage is visible not assumed.

Board & committee reporting

Report testing coverage, results and open findings to the audit committee and board from live, connected data.

The workflow

The end-to-end workflow

A defined process with clear ownership at every stage, captured against the record it belongs to.

The workflow, step by stepSchematic
01PlanA risk-based assurance plan is built against the shared control library with scopeand cadence.02ScopeEach engagement is scoped to the controls, processes and evidence it will test.03TestControls are tested with defined method and sampling, and evidence is capturedagainst each control.04FindShortfalls are raised as findings with severity, owner and remediation actions.05RemediateFindings are driven through remediation to verified closure, recorded against thefinding.06ReportCoverage, results and open findings are reported to the audit committee and board.

Every result, decision and override is captured against the record it belongs to.

01

Plan

A risk-based assurance plan is built against the shared control library with scope and cadence.

02

Scope

Each engagement is scoped to the controls, processes and evidence it will test.

03

Test

Controls are tested with defined method and sampling, and evidence is captured against each control.

04

Find

Shortfalls are raised as findings with severity, owner and remediation actions.

05

Remediate

Findings are driven through remediation to verified closure, recorded against the finding.

06

Report

Coverage, results and open findings are reported to the audit committee and board.

Integrations

Works with your existing systems

Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.

Controls & governance
  • Tests against the shared control library used by the governance and risk programmes
Evidence sources
  • Attaches evidence from your existing systems and document stores against the control tested
Issue & remediation tracking
  • Connects to your action or ticketing tools so remediation progress stays in sync
Reporting & analytics
  • Feeds assurance coverage and findings into executive and board reporting
Collaboration & notification
  • Routes test assignments, findings and remediation reminders through your existing email and messaging tools
Assurance

Security & reporting

Security & data handling

  • Audit working papers, test results and evidence are encrypted in transit and at rest.
  • Access is role-based, preserving the independence and confidentiality of assurance work.
  • Every test, result, finding and remediation step is written to an append-only audit trail.
  • Evidence is captured against the control it proves with timestamp and attribution.
  • Data residency and retention are configurable to your obligations.

Reports & returns

  • Assurance plan and testing-coverage reports
  • Control-testing results and effectiveness reporting
  • Findings register with severity, ageing and closure status
  • Remediation progress and overdue-action reporting
  • Audit committee and board assurance reporting
The value

What your team gains

Assurance that maps to reality

Testing the same controls the business runs means findings are relevant and improvement actually lands.

Evidence you can always produce

Proof captured against the control it belongs to is ready the moment an auditor or regulator asks.

Findings that close

Owners, actions and verified closure turn assurance into improvement rather than repeated observation.

Continuous readiness

Because evidence and results accumulate as work happens, the firm is examination-ready all the time, not just at cycle end.

FAQ

Questions, answered

Does audit work on the same controls as the business?

Yes. The assurance programme tests against the shared control library the governance and risk programmes use, so the third line assures the exact controls the first line operates — findings map to reality.

How is evidence handled?

Test evidence is captured against the control it proves, with timestamp and attribution, so proof is never separated from the control and is ready the moment it is requested.

Can it keep us continuously ready for examination?

Because results and evidence accumulate as testing happens rather than being assembled before a review, readiness is a standing property of the programme rather than an annual scramble.

Does independence get compromised by sharing a platform?

No. Access is role-based to preserve the independence and confidentiality of assurance work; the benefit of the shared platform is that audit draws on real control and risk data rather than a divergent copy.

Are SOC 2 or ISO 27001 held?

Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.

Stand up your Audit & Assurance programme

Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.