For compliance, risk and internal audit teams
Which obligations have no mapped control. Which entities have not been reviewed inside their cycle. Which controls were tested, which failed, and which have never been tested at all. From the obligations register, the control library and the testing log, reconciled so the board pack and the regulator see the same numbers.
Regulators ask whether every obligation is covered by a control and every control is tested. Most teams answer from three spreadsheets. Covirage joins the register, the library and the log, asserts that they reconcile, and lets the team ask the follow-up.
Obligations against mapped controls, by regulation, business line and entity.
Controls against their test schedule. Overdue and never-tested, ranked by risk rating.
"Which high-risk obligations in payments have an untested control?" Answered from the rows.
Three steps, in this order.
Obligations register, control library, testing log. Spreadsheets are fine.
We show obligations with no control and controls with no obligation.
Compliance leads see gaps by business line. The board pack is drafted from the same figures.
Short answers. The Help centre has the long ones.
No. It reads the GRC system or the spreadsheets and answers the coverage questions they do not.
Yes. The Enterprise plan runs in a separate pseudonymised tenant, and that is where most compliance teams will want it.
The board reporting function drafts the narrative from the same reconciled figures, with every number cited.
Analytics software for compliance, compared · Alternatives to named products
Written for this desk: the measures, the data you already hold, and the arithmetic.
How a compliance team reads its incident and near-miss reports against the activity that produces them, from the incident register and the activity data: reports per unit of activity, transactions, trades, accounts opened, the units well below the firm's own rate, the rate against the unit's audit findings, why a low reporting rate with high findings is a culture measure, and the list of units where the register is quiet and the evidence is not.
16 Sept 20262 min readHow a compliance or internal audit team reports the findings that are open past their agreed remediation date, from the issue register: ageing bands per owner and business unit, the extensions granted and how many times, the high-rated issues past date, and the trend that shows a remediation programme slipping before the board asks why the same finding is on the pack for the third quarter.
16 Sept 20263 min readHow a compliance function measures control coverage from the obligations register, the control library and the testing log: obligations with no mapped control, controls past their test date, entities outside their review cycle, and the reconciliation that lets the board pack and the regulator see one number.
16 Sept 20263 min readHow a compliance team tracks the gap between regulatory change and control coverage from its own obligation register and change log: obligations added or amended per period, the days each has been live with no mapped control, the business units where unmapped obligations concentrate, the ageing of the mapping backlog, and the identity that every obligation is either mapped, in progress or unmapped with a date.
16 Sept 20262 min readThe ten questions a head of compliance puts to the business units and the compliance team, which obligations have no control, which controls were not tested on schedule, which findings are past their date and how many times extended, which regulatory changes have no mapping yet, who is overdue on training, which units report nothing, which high-rated issues are open, what will a regulator find first, what did the last audit find that the register did not, and what changed, each with the table from the registers, the identity behind it, and the answer to send back.
16 Sept 20262 min readHow a compliance team measures whether each control was tested when its plan said it would be, from the control register and the testing log: cadence adherence per control owner and business unit, the slipped-test list ranked by the risk the control covers, and the trend that shows a testing programme quietly falling behind before the regulator asks.
16 Sept 20262 min read