Audit & Assurance
Test controls, capture evidence, and prove the programme works
Assurance is how a firm proves — to itself, its board and its regulators — that its controls actually operate. This programme composes audit management, control testing and evidence management into one assurance function, so controls are tested on a plan, findings are tracked to closure, and the evidence lives against the control it proves. Audit readiness becomes a property of how work is captured, not a project before a review.
One programme, on one platform
Your compliance, risk and legal teams run the programme in OnyxOne, which composes the relevant modules onto one record and connects to the systems and data sources your deployment requires.
What this programme is, and why it matters
A solution is a programme, not a single tool — the outcome a set of platform capabilities add up to when they run on one record.
How accountability is structured across the first line, risk and compliance, and independent assurance — the model the programme supports.
Assurance over the same controls the business runs
The programme tests against the shared control library the governance and risk programmes use, so the third line is assuring the exact controls the first line operates — not a separate, divergent list. Findings land where they matter.
Evidence against the control it proves
Every test captures its evidence against the control record, so the proof that a control works is never separated from the control itself — and never has to be reconstructed when an auditor or regulator asks.
Findings tracked to closure
Testing that surfaces a weakness only adds value if the weakness is fixed. The programme tracks findings with owners, actions and deadlines through to verified closure, so assurance drives improvement rather than just observation.
Independent, but connected
The assurance function keeps its independence while working on the same platform as the rest of the programme — so it draws on real control and risk data instead of requesting it, and its results feed straight into board reporting.
What makes this hard today
The operational realities this programme is designed to resolve.
Assurance on a parallel universe
When audit tests a separate copy of the controls, findings don't map to what the business runs and improvement stalls.
Evidence scattered and stale
Test evidence held in folders and email cannot be tied reliably to the control it proves, and goes out of date.
Findings that never close
Weaknesses tracked in spreadsheets lose owners and deadlines, so the same issues recur review after review.
Testing as an annual scramble
Assurance treated as a periodic project means readiness is rebuilt each cycle rather than maintained continuously.
No line of sight for the board
Without connected data, the board sees assurance results late and in fragments rather than as a current picture.
The operating model, at a glance
How the composed programme runs — from the data it takes in to the decisions and evidence it produces.
Work is triaged, escalated when it matters, and recorded either way — every path lands on the audit trail.
Plan the assurance
Build a risk-based audit and testing plan against the shared control library, with scope, owners and cadence.
Test the controls
Execute control tests, capturing method, sample, result and evidence against each control record.
Raise findings
Where a control falls short, raise a finding with severity, owner and remediation action.
Track to closure
Drive findings through remediation to verified closure, with progress recorded against the finding.
Report assurance
Report testing coverage, results and open findings to the audit committee and board from live data.
The modules this solution composes
A solution is a curated set of platform modules working as one programme. Turn on what the programme needs and add more as it scales.
What the programme gives you
The concrete capabilities the composed programme provides, end to end.
Risk-based audit planning
Build and manage an assurance plan against the shared control library, scoped and prioritised by risk.
Control testing
Execute tests with defined method and sampling, recording result and evidence against each control.
Evidence management
Capture and hold test evidence against the control it proves, so proof is never separated from the control.
Findings & remediation
Raise findings with severity and owner and track them through remediation to verified closure.
Assurance coverage
See which controls have been tested, when and with what result, so assurance coverage is visible not assumed.
Board & committee reporting
Report testing coverage, results and open findings to the audit committee and board from live, connected data.
The end-to-end workflow
A defined process with clear ownership at every stage, captured against the record it belongs to.
Every result, decision and override is captured against the record it belongs to.
Plan
A risk-based assurance plan is built against the shared control library with scope and cadence.
Scope
Each engagement is scoped to the controls, processes and evidence it will test.
Test
Controls are tested with defined method and sampling, and evidence is captured against each control.
Find
Shortfalls are raised as findings with severity, owner and remediation actions.
Remediate
Findings are driven through remediation to verified closure, recorded against the finding.
Report
Coverage, results and open findings are reported to the audit committee and board.
Industries this programme serves
The sectors this programme is most often deployed in. The same programme, framed around each sector's obligations.
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems the programme requires, configured per implementation.
- Tests against the shared control library used by the governance and risk programmes
- Attaches evidence from your existing systems and document stores against the control tested
- Connects to your action or ticketing tools so remediation progress stays in sync
- Feeds assurance coverage and findings into executive and board reporting
- Routes test assignments, findings and remediation reminders through your existing email and messaging tools
Security & reporting
Security & data handling
- Audit working papers, test results and evidence are encrypted in transit and at rest.
- Access is role-based, preserving the independence and confidentiality of assurance work.
- Every test, result, finding and remediation step is written to an append-only audit trail.
- Evidence is captured against the control it proves with timestamp and attribution.
- Data residency and retention are configurable to your obligations.
Reports & returns
- Assurance plan and testing-coverage reports
- Control-testing results and effectiveness reporting
- Findings register with severity, ageing and closure status
- Remediation progress and overdue-action reporting
- Audit committee and board assurance reporting
What your team gains
Assurance that maps to reality
Testing the same controls the business runs means findings are relevant and improvement actually lands.
Evidence you can always produce
Proof captured against the control it belongs to is ready the moment an auditor or regulator asks.
Findings that close
Owners, actions and verified closure turn assurance into improvement rather than repeated observation.
Continuous readiness
Because evidence and results accumulate as work happens, the firm is examination-ready all the time, not just at cycle end.
Questions, answered
Does audit work on the same controls as the business?
Yes. The assurance programme tests against the shared control library the governance and risk programmes use, so the third line assures the exact controls the first line operates — findings map to reality.
How is evidence handled?
Test evidence is captured against the control it proves, with timestamp and attribution, so proof is never separated from the control and is ready the moment it is requested.
Can it keep us continuously ready for examination?
Because results and evidence accumulate as testing happens rather than being assembled before a review, readiness is a standing property of the programme rather than an annual scramble.
Does independence get compromised by sharing a platform?
No. Access is role-based to preserve the independence and confidentiality of assurance work; the benefit of the shared platform is that audit draws on real control and risk data rather than a divergent copy.
Are SOC 2 or ISO 27001 held?
Not yet. Both are on our roadmap; we will publish attestations in the Trust Center once they are held rather than claim them beforehand.
Stand up your Audit & Assurance programme
Book a walkthrough and we'll show how the composed programme fits your obligations, workflows and systems — then scope an implementation.