# Controls that are proven to work, not just documented.

XGRC® is internal controls software that lets organisations design, implement, test, and assure controls in a structured way. Every control is linked to the risk it mitigates and the assurance provider testing it, so control effectiveness is demonstrable at any time.

**Frameworks:** COSO, ISO 31000, King V, Combined Assurance, Internal Audit, Control Assurance

## Untested controls create false assurance.

A control that exists on paper but has never been tested gives management false confidence. Weaknesses stay hidden until an audit, incident, or loss exposes them.

- Controls documented in policy but never tested in practice
- No clear owner accountable for whether a control is working
- Control deficiencies identified but not tracked to remediation
- Internal audit, risk, and compliance test the same controls independently

## A structured, testable control environment.

- Define the control framework and map controls to risks
- Assign a named owner accountable for each control
- Test control design and operating effectiveness on a set schedule
- Classify and track deficiencies through to remediation
- Align control testing with combined assurance coverage
- Report control effectiveness to management and the audit committee

## How it works

- Central control register linked to the risk register
- Configurable testing schedules by risk rating
- Structured deficiency classification and remediation tracking
- Combined assurance mapping to avoid duplicated testing
- Real-time dashboards on control status and test results

## On the platform

**One connected view of control assurance** — XGRC® links every control to the risk it addresses, the tests performed against it, and the assurance provider responsible for that testing. Deficiencies are tracked to verified remediation, not just logged and forgotten.

## The same control environment, without the blind spots.

| Manual approach | With XGRC® |
| --- | --- |
| Controls documented but rarely tested | Controls mapped to risks with named owners |
| No clear control ownership | Scheduled design and operating effectiveness testing |
| Deficiencies tracked in spreadsheets or not at all | Deficiencies tracked to verified closure |
| Duplicated testing across functions | Combined assurance mapping eliminates duplication |

## One platform across every control type.

- Financial and operational controls
- IT and information security controls
- Compliance controls
- Combined assurance testing

## Frequently asked questions

### What is internal controls software?

Internal controls software lets organisations design, test and assure controls in a structured way, linking each control to the risk it mitigates so effectiveness can be demonstrated rather than assumed from documentation alone.

### Does XGRC® test whether controls actually work, not just whether they exist?

Yes. Controls are tested for design and operating effectiveness on a set schedule, with deficiencies classified and tracked through to verified remediation rather than logged and forgotten.

### How does this avoid duplicated control testing across teams?

Combined assurance mapping shows which assurance provider is already testing a given control, so internal audit, risk and compliance are not independently re-testing the same control.

### Which frameworks does internal controls management align to?

Internal controls align to COSO, ISO 31000 and King V, and connect directly to combined assurance and internal audit elsewhere on the platform.

## Related solution

- [Integrated Assurance](https://xgrcsoftware.com/integrated-assurance)

---

Source: https://xgrcsoftware.com/use-cases/internal-controls
