Internal Controls
One control framework mapped to risks and obligations
Maintain a single, structured library of internal controls — each mapped to the risks it mitigates and the obligations it satisfies, with an owner, a design and an effectiveness status — so control is a managed framework rather than a scattered set of assertions. Controls are the connective tissue of GRC: risk is reduced by controls, compliance is met by controls, and audit tests controls. When they live in disconnected spreadsheets, the same control is documented differently in three places and nobody can say with confidence what is actually mitigating a given risk. OnyxOne Internal Controls makes the framework the shared backbone that risk, compliance and audit all draw on, so a control is defined once, owned by someone, and its effectiveness is known.
How it works, visually
How policies map to controls and controls mitigate risks — traceable both ways for audit.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Controls are scattered and duplicated
The same control is described in a risk spreadsheet, a compliance matrix and an audit workpaper — each slightly differently. There is no single library, so nobody can say authoritatively what controls exist, what they mitigate, or which of the three versions is correct.
Controls float free of the risks they mitigate
A control exists, but the risk it is supposed to reduce is recorded elsewhere with no link between them. Residual risk is asserted rather than derived from whether the control actually works, and a failed control does not visibly move the risk it was meant to cover.
Ownership and design are unclear
Controls have no named owner, or an owner who has moved on, and the design — what the control does, how often, and what evidences it — is vague. When something goes wrong, it is unclear who was responsible for the control that should have caught it.
One control satisfies many obligations, but nobody can see it
A single access-control or approval process may satisfy several regulatory obligations and frameworks at once, but because obligations and controls are mapped in separate documents, the overlap is invisible. The firm over-builds in some places and leaves gaps in others.
Effectiveness is unknown between audits
The only time a control's effectiveness is assessed is when audit happens to test it. Between those points the framework is a static list of intentions, and management has no live view of which controls are actually operating and which have quietly failed.
How OnyxOne addresses it
One structured control library
Every control lives once in a single library with a clear description, type, frequency, owner and the evidence that demonstrates it. Risk, compliance and audit all draw on the same definitions, so there is one authoritative answer to what controls exist and what they do.
Controls mapped to risks and obligations
Each control is linked to the risks it mitigates and the obligations and frameworks it satisfies. Residual risk is derived from tested control effectiveness rather than asserted, and the coverage of every risk and obligation by real controls is visible at a glance.
Clear ownership and documented design
Every control has a named owner accountable for its operation and a documented design — what it does, how often, and what evidences it. When a control matters, it is clear who is responsible and exactly what the control is supposed to achieve.
Shared controls, mapped once
A control that satisfies several obligations or frameworks is mapped to all of them from one definition, so the overlap is visible and the firm can rationalise its control set — testing once and satisfying many — instead of duplicating effort and missing gaps.
Live effectiveness, not just at audit
Control effectiveness flows in from testing and attestation on a defined cadence, so the framework shows which controls are operating, which are weak and which have failed — and residual risk updates accordingly — rather than being unknown between audits.
What's in the module
Turn on what you need and add more as your programme scales.
Control library
A single structured register of controls with description, type, frequency, owner and evidencing requirements.
Risk-to-control mapping
Link each control to the risks it mitigates so residual risk derives from real control effectiveness.
Obligation & framework mapping
Map controls to the obligations and frameworks they satisfy, revealing coverage and overlap.
Control ownership
Assign a named owner accountable for each control's operation, attestation and remediation.
Design & operating attributes
Capture what a control does, how often, whether it is preventive or detective, and how it is evidenced.
Effectiveness status
Hold a live design- and operating-effectiveness status fed by testing and attestation.
Control attestation
Require owners to attest that controls are operating on a defined cadence, with exceptions captured.
Key-control designation
Flag the controls that matter most so testing and oversight focus where failure hurts.
Remediation of control gaps
Raise and track actions where controls are missing, weak or failing, through to closure.
Immutable control history
Every control change, mapping, attestation and effectiveness update is versioned and preserved.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Control library view
The full control inventory with type, frequency, owner and effectiveness status, filterable by process, risk and obligation.
Coverage map
Risks and obligations against the controls that mitigate and satisfy them, with gaps and over-coverage highlighted.
Effectiveness heatmap
Design and operating effectiveness across the framework, with weak and failed controls surfaced for attention.
Key-control register
The controls designated most critical, their status, ownership and the testing focused on them.
Attestation & remediation board
Outstanding control attestations and open remediation actions by owner and due date, tracked to closure.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Attestation cycles
Control owners are prompted to attest that controls are operating on their cadence, and outstanding attestations are chased automatically.
Effectiveness-to-risk propagation
When a control's effectiveness changes, the residual risk on the risks it mitigates is recalculated without manual re-scoring.
Failed-control remediation
A control that fails testing or attestation automatically raises a remediation action to its owner with a due date.
Coverage-gap alerts
Risks or obligations left without an effective mapped control are flagged automatically so gaps are closed deliberately.
Key-control monitoring
Designated key controls are surfaced for review when their status changes, so critical failures are never buried.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Control-mapping suggestion
Proposes which risks and obligations a control likely relates to from its description, which an owner reviews and confirms before the mapping is set.
Duplicate-control detection
Highlights controls that appear to describe the same activity so the library can be rationalised, with a person deciding what to merge.
Design-description drafting
Drafts a clear control-design description from captured attributes for the owner to refine and approve, improving consistency across the library.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Build the library
Controls are captured once in a structured library with description, type, frequency, owner and how each is evidenced.
Map to risks & obligations
Each control is linked to the risks it mitigates and the obligations and frameworks it satisfies, exposing coverage and overlap.
Assign ownership
Every control is given a named owner accountable for its operation, and key controls are designated for closer oversight.
Assess effectiveness
Design and operating effectiveness are assessed through testing and attestation on a defined cadence, updating each control's status.
Derive residual risk
Residual risk on linked risks reflects real control effectiveness, so a weak or failed control visibly moves the risk it covers.
Remediate gaps
Missing, weak or failing controls raise remediation actions with owners and dates, tracked to closure and re-assessment.
What your team gains
One authoritative control set
Controls defined once and shared by risk, compliance and audit end the three-versions problem and give one answer to what controls exist.
Coverage you can see
Controls linked to risks and obligations make coverage and gaps visible, so the firm knows exactly what is mitigating each risk.
Clear accountability
Every control has a named owner and documented design, so it is always clear who is responsible and what the control is meant to do.
Effectiveness known, not assumed
Effectiveness fed by testing and attestation means management sees which controls actually operate rather than a static list of intentions.
Test once, satisfy many
Mapping shared controls to all the obligations they satisfy lets the firm rationalise its control set and avoid duplicated testing and effort.
Residual risk grounded in reality
Deriving residual risk from tested effectiveness means a failed control moves the risk it covers, rather than leaving risk asserted on paper.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Links controls to the risks they mitigate in the enterprise and operational risk registers so residual risk reflects control effectiveness
- Maps controls to the obligations and frameworks they satisfy so compliance coverage draws on the same control set
- Feeds design and operating-effectiveness results from the control-testing module back into each control's live status
- Shares the control framework with audit so engagements and findings reference the same authoritative controls
- Routes attestation requests, remediation actions and reminders through your existing email and messaging tools
Security, compliance & reporting
Security & data handling
- The control library, mappings and effectiveness data are encrypted in transit and at rest, with access governed by granular, role-based permissions.
- Control ownership and attestation are attributable, so who owns and who attested to each control is always clear.
- Segregation of duties can prevent a control owner from also signing off the testing of their own control where policy requires independence.
- Every control change, mapping, attestation and effectiveness update is written to an append-only audit trail.
- Data residency and retention for control records are configurable to your regulatory and internal-policy obligations.
Compliance support
- Supports an internal-control framework aligned to recognised models such as COSO Internal Control and, for IT controls, COBIT
- Underpins control mapping for obligations across frameworks the firm is subject to
- Provides the control design, ownership and effectiveness evidence expected by audit and regulators
- Supports the first and second lines within a three-lines-of-defence model
- Supplies documented, dated control evidence for internal and external audit
- OnyxOne is a technology vendor — responsibility for control design and operation remains with your organisation
Reports & exports
- Control library and control-inventory reports
- Risk-to-control and obligation-to-control coverage reports
- Control-effectiveness status and failed-control reports
- Key-control register and attestation-completion reports
- Control-gap and remediation-status reports
- Control-framework management information for risk and audit committees
How to get the most from it
Define each control once
Keep a single library and have risk, compliance and audit reference it, rather than each maintaining their own. One authoritative definition ends the reconciliation problem before it starts.
Map controls to what they mitigate and satisfy
Link every control to its risks and obligations. Coverage and overlap only become visible — and residual risk only becomes real — once the mappings exist.
Give every control an owner
An unowned control is a control nobody is operating. A named owner accountable for operation, attestation and remediation is the difference between a framework and a wish list.
Focus effort on key controls
Designate the controls that matter most and concentrate testing and oversight there. Treating every control as equally critical spreads assurance too thin to catch the failures that count.
Questions, answered
What makes this a framework rather than a list?
Every control is defined once, given an owner and a documented design, and mapped to the risks it mitigates and the obligations it satisfies, with a live effectiveness status. That mapping and ownership is what turns a static inventory into a managed framework that risk, compliance and audit all draw on.
How does control effectiveness stay current?
Design and operating-effectiveness results flow in from the control-testing module and from owner attestations on a defined cadence. Each control carries a live status, and because controls are linked to risks, a weak or failed control visibly moves the residual risk it was meant to cover.
Can one control satisfy several obligations?
Yes, and making that visible is a core benefit. A control is defined once and mapped to all the obligations and frameworks it satisfies, so the firm can see the overlap, test once to satisfy many, and rationalise a control set that would otherwise be duplicated across documents.
How does this relate to control testing and audit?
Internal Controls holds the authoritative framework. Control Testing assesses whether those controls work and feeds the results back. Audit references the same controls when it plans engagements and raises findings. All three share one control set instead of maintaining separate copies.
Does OnyxOne operate the controls?
No. OnyxOne is a technology vendor that gives you the framework to define, own, map and assess controls. The controls themselves are designed and operated by your organisation; responsibility for their design and operation remains with you.
Related modules
See Internal Controls in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.