Sign in

For compliance, risk and internal audit teams

Control coverage analytics for compliance teams. Every obligation, every control, every test.

Which obligations have no mapped control. Which entities have not been reviewed inside their cycle. Which controls were tested, which failed, and which have never been tested at all. From the obligations register, the control library and the testing log, reconciled so the board pack and the regulator see the same numbers.

Upload sample data to try itSee a demoAI analytics for ComplianceWorks with GRC exports and spreadsheets. Runs in a separate tenant on Enterprise.
Obligations · financial crime · by control statusQ3
Mapped and testedMapped, test overdueNo control mapped
Per obligationcontrols mapped, tested, passed
Per entityreviews due against reviews done
100%reconciled to the obligations register

Coverage is the compliance question

Regulators ask whether every obligation is covered by a control and every control is tested. Most teams answer from three spreadsheets. Covirage joins the register, the library and the log, asserts that they reconcile, and lets the team ask the follow-up.

Obligation coverage

Obligations against mapped controls, by regulation, business line and entity.

Testing cadence

Controls against their test schedule. Overdue and never-tested, ranked by risk rating.

Ask the regulator's question

"Which high-risk obligations in payments have an untested control?" Answered from the rows.

How it works

Three steps, in this order.

Load the three sources

Obligations register, control library, testing log. Spreadsheets are fine.

Confirm the mapping

We show obligations with no control and controls with no obligation.

Run the quarter

Compliance leads see gaps by business line. The board pack is drafted from the same figures.

“The regulator asked how many obligations had an untested control. The honest answer took us three weeks. Now it takes a question.”A head of compliance at a mid-size bank

Questions this industry asks

Short answers. The Help centre has the long ones.

Is this a GRC system?

No. It reads the GRC system or the spreadsheets and answers the coverage questions they do not.

Can it run inside the firm?

Yes. The Enterprise plan runs in a separate pseudonymised tenant, and that is where most compliance teams will want it.

Does it produce the board pack?

The board reporting function drafts the narrative from the same reconciled figures, with every number cited.

Read more

Analytics software for compliance, compared · Alternatives to named products

Written for this desk: the measures, the data you already hold, and the arithmetic.

Coverage and territory · Compliance

Incident reporting against activity: the unit that reports nothing is not the safest one

How a compliance team reads its incident and near-miss reports against the activity that produces them, from the incident register and the activity data: reports per unit of activity, transactions, trades, accounts opened, the units well below the firm's own rate, the rate against the unit's audit findings, why a low reporting rate with high findings is a culture measure, and the list of units where the register is quiet and the evidence is not.

16 Sept 20262 min read
Board and management reporting · Compliance

Issue ageing by owner: open findings past their remediation date

How a compliance or internal audit team reports the findings that are open past their agreed remediation date, from the issue register: ageing bands per owner and business unit, the extensions granted and how many times, the high-rated issues past date, and the trend that shows a remediation programme slipping before the board asks why the same finding is on the pack for the third quarter.

16 Sept 20263 min read
Coverage and territory · Compliance

Obligation-to-control coverage, asserted: the compliance roll-up

How a compliance function measures control coverage from the obligations register, the control library and the testing log: obligations with no mapped control, controls past their test date, entities outside their review cycle, and the reconciliation that lets the board pack and the regulator see one number.

16 Sept 20263 min read
Coverage and territory · Compliance

Regulatory change coverage: new obligations with no control mapped yet

How a compliance team tracks the gap between regulatory change and control coverage from its own obligation register and change log: obligations added or amended per period, the days each has been live with no mapped control, the business units where unmapped obligations concentrate, the ageing of the mapping backlog, and the identity that every obligation is either mapped, in progress or unmapped with a date.

16 Sept 20262 min read
Coverage and territory · Compliance

Ten questions a head of compliance asks, and the table that answers each

The ten questions a head of compliance puts to the business units and the compliance team, which obligations have no control, which controls were not tested on schedule, which findings are past their date and how many times extended, which regulatory changes have no mapping yet, who is overdue on training, which units report nothing, which high-rated issues are open, what will a regulator find first, what did the last audit find that the register did not, and what changed, each with the table from the registers, the identity behind it, and the answer to send back.

16 Sept 20262 min read
Board and management reporting · Compliance

Testing cadence: controls tested on schedule, and the ones that slipped

How a compliance team measures whether each control was tested when its plan said it would be, from the control register and the testing log: cadence adherence per control owner and business unit, the slipped-test list ranked by the risk the control covers, and the trend that shows a testing programme quietly falling behind before the regulator asks.

16 Sept 20262 min read