Internal Control System

Your control is described.
But is it effective?

Reduce risk, improve processes.
Run, evidence and assess your controls continuously. Existence and effectiveness evidenced.

Control cockpit continuously updated
84%
evidenced effective
+12 points year on year
100controls in the inventory
9findings open
7not yet tested
What the platform takes care of
  • Controls distributed automatically, with due date and reminder
  • Evidence is produced during execution, not afterwards
  • Effectiveness evidenced, audit ready at any time
no more spreadsheets by emailaudits in days instead of weekscontrol gaps surface early

Trusted by leading organizations

What makes the difference

From an annual scramble
to continuous control operation

Processes, risks and controls are documented in most organizations. What sets them apart is whether the controls actually run day to day.

The common starting point

An ICS that wakes up for the season

The risk control matrix lives in Excel and evidence arrives by email. Shortly before the audit, everything is tested at once.

  • Control matrix in Excel, evidence by email
  • Control owners do not know what is due when
  • Testing happens just before the audit, all at once
  • Findings are recorded but not followed through
With the SwissGRC® Platform

An ICS that keeps working all year

Controls are distributed, confirmed and evidenced automatically. Effectiveness builds up over the year, not in December.

  • Controls distributed automatically, with due date and reminder
  • Evidence attached directly to the control execution
  • Control tests and assessments spread across the year
  • Findings with action, owner and due date
The SwissGRC® Platform at a glance

Your entire ICS,
in one place

Model, link, execute, assess, test and report. Click through the six views.

BPMN 2.0

Processes, risks and controls in one picture

Management, core and support processes modelled, with roles in swim lanes. Risks and controls sit right on the process step.

  • Process hierarchy from management to support processes
  • Risks marked on the process step, not in a side list
  • PDF export, approval and version held on the process
BPMN process model with risks on the process step in the SwissGRC Platform
RCM

Every risk with its control

The matrix brings process, risk and control together, with owner, frequency and relevance. Control design and effectiveness visible in one column.

  • Grouped by process, key controls flagged
  • Control frequency from daily to event driven
  • Adequacy and effectiveness at a glance
Risk control matrix grouped by process in the SwissGRC Platform
Control execution

The control reaches the right person

The platform distributes due controls to their owners automatically and reminds them of deadlines. Execution is confirmed and evidenced.

  • Automatic notification with a link to the task
  • Task with due date, assignment and status
  • Evidence and findings attached to the task
Automated control confirmation with task and notification in the SwissGRC Platform
Adequacy and effectiveness

Adequate and effective, assessed

Controls are assessed regularly for adequacy and effectiveness. The dashboard shows where it breaks down, by process and organizational unit.

  • Controls evaluated by process and effectiveness
  • Filter by organizational unit, category and process
  • Key controls assessed separately
Dashboard assessing adequacy and effectiveness of controls
Testing and findings

Effectiveness tested, deficiencies documented

Walkthrough, design test and overall rating structured per control. Findings and recommendations emerge during the test, not afterwards.

  • Test questionnaire ordered by area and control
  • Walkthrough, design test and overall rating documented
  • Findings and recommendations captured directly
Control testing with walkthrough, design test and findings in the SwissGRC Platform
Reporting

Control results for the right audience

Execution status, adequacy and effectiveness in one dashboard. One picture that both management and the statutory auditor can rely on.

  • Execution status by open, in progress and completed
  • Adequacy and effectiveness per period
  • ICS report and risk control matrix as ready analyses
ICS dashboard with execution status, adequacy and effectiveness
Built on recognized methods and standards, from process modelling through to the control test.
COSO Internal Control Art. 728a Swiss CO PS 890 BPMN 2.0 Key controls Segregation of duties
Evidence and audit

Existence is mandatory.
Effectiveness pays off.

In a statutory audit the auditor verifies that an ICS exists (Art. 728a para. 1 no. 3 Swiss CO, PS 890). Evidencing effectiveness beyond that shortens the audit and produces information you can steer with.

Evidence held on the control
Records, timestamps, ownership and history are produced during execution. The ICS documentation is ready to show at any time.
Existence evidenced, effectiveness tested
Control design and execution are documented, walkthrough and test result sit on the control. Voluntary effectiveness audits are prepared for.
Findings and actions
Deficiencies are rated, given an owner and a due date and tracked through to closure. Nothing is left sitting on a list.
Document management
Process documentation, directives and manuals versioned, reviewed and approved, referenced from the process and from the control.
One control set, several disciplines
The same processes and controls carry ICS, internal audit and risk management. Maintain once, use many times.
Advantages and added value

More effectiveness,
less year end pressure

Comprehensive and simple at the same time. That is what drives adoption and lifts maturity.

Process, risk and control connected

Every control hangs on the process step and on the risk. The connection can be queried, not reconstructed.

Continuous operation instead of a year end run

Controls are distributed and confirmed automatically. Effectiveness builds up across the year.

Audit ready at any time

Evidence is produced during execution. The auditor finds what they need without weeks of chasing.

Part of a connected GRC system

The ICS shares one foundation with risk management, ISMS, BCM, compliance and internal audit.

Control owners involved day to day

Workflows and reminders bring the control to the responsible person, without chasing by email.

Higher maturity through standards

Built on COSO: one consistent, automated approach across every process and unit.

Contact and demo

See our ICS solution
in action

In a personal demo we walk you through the SwissGRC® Platform and show how processes, risks, controls and evidence work together.