Use Case · Integrated Assurance

Controls that are proven to work, not just documented.

XGRC® is internal controls software that lets organisations design, implement, test, and assure controls in a structured way. Every control is linked to the risk it mitigates and the assurance provider testing it, so control effectiveness is demonstrable at any time.

Book a demo
The problem

Untested controls create false assurance.

A control that exists on paper but has never been tested gives management false confidence. Weaknesses stay hidden until an audit, incident, or loss exposes them.

Controls documented in policy but never tested in practice

No clear owner accountable for whether a control is working

Control deficiencies identified but not tracked to remediation

Internal audit, risk, and compliance test the same controls independently

The XGRC® approach

A structured, testable control environment.

01

Define the control framework and map controls to risks

02

Assign a named owner accountable for each control

03

Test control design and operating effectiveness on a set schedule

04

Classify and track deficiencies through to remediation

05

Align control testing with combined assurance coverage

06

Report control effectiveness to management and the audit committee

How it works

Built for control owners. Visible to assurance functions.

  • Central control register linked to the risk register
  • Configurable testing schedules by risk rating
  • Structured deficiency classification and remediation tracking
  • Combined assurance mapping to avoid duplicated testing
  • Real-time dashboards on control status and test results

One connected view of control assurance

XGRC® links every control to the risk it addresses, the tests performed against it, and the assurance provider responsible for that testing. Deficiencies are tracked to verified remediation, not just logged and forgotten.

From manual to XGRC®

The same control environment, without the blind spots.

Manual approach
  • Controls documented but rarely tested
  • No clear control ownership
  • Deficiencies tracked in spreadsheets or not at all
  • Duplicated testing across functions
XGRC® approach
  • Controls mapped to risks with named owners
  • Scheduled design and operating effectiveness testing
  • Deficiencies tracked to verified closure
  • Combined assurance mapping eliminates duplication
Free resource

Internal Controls Checklist

  • Control framework and design
  • Control implementation
  • Control testing
  • Deficiency management
  • Combined assurance alignment
  • Monitoring and reporting
PDF · COSO-aligned · v1.0
Standards and frameworks

Assure controls against the frameworks that matter.

  • COSO
  • ISO 31000
  • King V
  • Combined Assurance
  • Internal Audit
  • Control Assurance
Scope of application

One platform across every control type.

  • Financial and operational controls
  • IT and information security controls
  • Compliance controls
  • Combined assurance testing
Frequently asked

Common questions.

What is internal controls software?

Internal controls software lets organisations design, test and assure controls in a structured way, linking each control to the risk it mitigates so effectiveness can be demonstrated rather than assumed from documentation alone.

Does XGRC® test whether controls actually work, not just whether they exist?

Yes. Controls are tested for design and operating effectiveness on a set schedule, with deficiencies classified and tracked through to verified remediation rather than logged and forgotten.

How does this avoid duplicated control testing across teams?

Combined assurance mapping shows which assurance provider is already testing a given control, so internal audit, risk and compliance are not independently re-testing the same control.

Which frameworks does internal controls management align to?

Internal controls align to COSO, ISO 31000 and King V, and connect directly to combined assurance and internal audit elsewhere on the platform.

See internal controls as a tested, assured process.

Book a demo to see how XGRC® turns control design, testing, and remediation into one connected, auditable workflow.

Book a demo