
Evaluate, test, and monitor the effectiveness of internal controls
Combine self-assessments and control tests to identify weaknesses, strengthen the accountability of the areas, and guide corrective actions based on evidence.

✦ Challenge
Do you have difficulty to assess and verify whether the internal controls are actually effective?
Symptoms that your organization's internal control management is not yet an efficient process:
The organization cannot verify whether the registered controls actually work in practice.
The self-assessments are performed in spreadsheets, emails, or disconnected forms.
Each area uses different criteria to evaluate its controls.
The evidence and justifications are incomplete or difficult to trace.
The tests are conducted without planning, periodicity, or a standardized methodology.
Identified weaknesses are not converted into actions that are followed through to completion.
✦ Solution
Evaluate the effectiveness of controls with criteria, evidence, and traceability
The Solution Management of Internal Controls structure the continuous evaluation of internal controls by combining the Control Self-Assessment, conducted by managers and those responsible for controls, with tests planned and executed by the Risk, Controls or Audit departments.
In addition, it centralizes questionnaires, criteria, evidence, justifications, validations and results, linking the controls to the risks and allowing to identify deficiencies, update the residual risk assessment and follow the action plans until their completion.

Standardized evaluation
Structure criteria, questionnaires, and evidence so that different departments can evaluate their controls consistently.
Validation of effectiveness
Combine self-assessments and control tests to verify that the controls are functioning as expected.
Treatment of weaknesses
Translate identified deficiencies into action plans and monitor responsibilities, deadlines, and corrective measures.
✦ Implementation steps
How to evaluate, test and strengthen internal controls
Structure a continuous process for registering controls, conducting self-assessments, performing tests, consolidating results, and addressing weaknesses.
01Structuring internal controls
- Register and organize the controls.
- Define your function as preventative or corrective.
- Relate controls to risks, causes, and consequences.
- Define responsibilities and the frequency of review.
02Planning the self-assessments
- Define the period, scope, and participants’ controls.
- Configure questionnaires and evaluation criteria.
- Establish mandatory fields, justifications, and evidence.
- Designate areas and responsible parties.
03Conduct the Control Self-Assessment
- Gather the managers' perception of the controls.
- Record responses, justifications, and evidence.
- Track pending, initiated and completed assessments.
- Keep the history of the changes.
04Planning and executing control tests
- Select the controls that will be tested.
- Define the objectives, criteria, period and scope of the tests.
- Record procedures, evidence, and conclusions.
- Identify effective, partially effective, or ineffective controls.
05Validate and consolidate the results
- To approve or disapprove the self-assessments.
- Compare the responses from the areas with the test results.
- Evaluate the individual or combined effectiveness of the controls.
- Update the residual risk assessment.
06Treating deficiencies and monitoring the evolution
- Create action plans based on the identified weaknesses.
- Define responsibilities, deadlines, and corrective measures.
- Send alerts about pending revisions, tests, and validations.
- Monitor the evolution of controls and actions.
Who is this solution for?
The solution connects the different professionals involved in the definition, execution, validation and supervision of internal controls, providing a common view on effectiveness, risks and corrective actions.
Responsible for Internal Controls
It structures the methodology and monitors the effectiveness of the controls.
Risk and Compliance Professional
It relates the results of the controls to the exposure to the risks.
Manager or owner of control
It conducts self-evaluations and presents evidence of its implementation.
Internal Audit or Assurance Area
Plans and performs tests to validate the effectiveness of controls.
Senior management and committees
They include deficiencies, residual risks, and corrective actions.
✦ Features
Resources for to evaluate, test and monitor internal controls
Centralize the necessary resources to structure controls, perform self-assessments and tests, monitor deficiencies, and maintain informed leadership about the effectiveness of controls.

Risks and Controls

Risk Matrix
Control Tests
Control Self-Assessment
Control reviews
Action plan
Dashboards
Executive presentations

Meetings
✦ Schedule your demo
Have more confidence in the effectiveness of your internal controls
Discover the Actio solution for Internal Control Management and learn how to standardize assessments, validate controls, and direct corrective actions based on evidence.
✦ Frequently Asked Questions
Clear your doubts about internal control management
Objective answers for organizations that need to evaluate controls in a structured way, verify their effectiveness, and monitor weaknesses until correction is made.
What is internal control management?
It is the process of structuring, evaluating, testing, and monitoring controls used by the organization to reduce risks and support the fulfillment of internal objectives and processes.
What is Control Self-Assessment?
It is the self-evaluation carried out by managers or those responsible for the controls to record their perception of the execution and effectiveness of the controls, accompanied by justifications and evidence.
What is the difference between self-evaluation and a control test?
The self-assessment registers the responsible party's perception of the functioning of the control system. The test, on the other hand, is planned and executed to validate its effectiveness based on criteria, procedures, and evidence.
Is it possible to relate controls to risks?
Yes. The controls can be related to risks, causes, and consequences, allowing us to assess how their effectiveness influences exposure and residual risk.
How does the solution help identify ineffective controls?
The platform allows results from self-assessments to be compared with the tests performed and controls to be classified as effective, partially effective or ineffective.
What happens when a deficiency is identified?
The fragility can generate an action plan with responsible parties, deadlines, and corrective measures, which remains monitored until its completion.
How is the leadership monitoring the situation regarding controls?
Dashboards and consolidated information allow for the monitoring of deficiencies, residual risks, revisions, and corrective actions, providing a clearer view of the evolution of controls.