← Industries Financial Services

The control has to work, and you have to be able to prove it did.

Program governance and quality discipline for regulated financial environments. What separates this sector is not that controls exist, it is that operating a control without evidence of operation is the same as not having it, and that reality has to be designed in rather than documented afterwards. Walk the five decisions, find your seat, then run the two-minute check.

The recurring finding
Reports relied on, not validated
Reliance on system reports without adequate validation is standard material weakness language. It is the information-produced-by-entity problem, and it is a design decision rather than an audit surprise.
01The Decision Room

Five calls that decide a regulated program

Each one determines whether the control environment is designed or inherited. Pick a decision.

D1Segregation of duties, at design
The room

Security gets configured to a role matrix that looks correct on paper, then tested by administrators who can see everything.

The call

Design segregation of duties into the role model before build, and test it as ordinary users at real permission levels.

Why it decides the outcome

Conflicts designed in are cheap to remove and expensive to find later, because by then people are doing their jobs through those roles. The remediation is not technical, it is organizational, and it lands during an audit window when there is no capacity to redesign access.

Take it to your programWho has tested our role model for conflicts as an ordinary user rather than an administrator?
D2Report validation
The room

Key reports get built, reviewed for whether the numbers look right, and put into production without documented completeness and accuracy validation.

The call

Inventory every report the close and the controls depend on, and document and test completeness and accuracy for each.

Why it decides the outcome

This is the single most common finding in the sector and it is entirely preventable. A report that feeds a control is itself part of the control environment. Building the inventory during the program costs days. Reconstructing it during a remediation costs months and happens under supervision.

Take it to your programWhich reports feed our key controls, and where is the validation evidence for each?
D3Change management on production
The room

The program moves fast, the change process is designed for steady state, and expedited paths appear informally to protect the schedule.

The call

Agree a program-scale change path with your control owners before build, including what an expedited change requires.

Why it decides the outcome

Either the process becomes the bottleneck or people route around it, and the second breaks the evidence trail. Agreeing the path in advance is cheap and rarely done, and the informal expedited route is precisely what shows up in a walkthrough.

Take it to your programWhat is our agreed program change path, and is anyone routing around it?
D4Data lineage for regulatory reporting
The room

Regulatory and management reporting gets built on aggregates, and the path from source transaction to reported figure is understood by a few people rather than documented.

The call

Design lineage deliberately, so every reported figure traces to source with the transformations documented.

Why it decides the outcome

The question that arrives is not whether the number is right, it is how you know. Lineage held in people rather than in design is a single point of failure that also fails an examination. Building it in is a design cost; retrofitting it is a project.

Take it to your programCan we trace a reported figure to source transactions without asking a specific person?
D5Steady-state control ownership
The room

The program owns the control environment while it is running, and ownership after go-live is assumed rather than assigned.

The call

Assign named steady-state owners for each key control and each key report before go-live, and fund the regression cycle.

Why it decides the outcome

Two vendor feature releases a year land on the control environment, permanently. Without named ownership, the first release after the program disbands is when a control quietly stops operating as designed, and the finding arrives a quarter later.

Take it to your programWho owns each key control after the program team leaves, by name?
02Your Seat

What those five mean for the chair you sit in

Programs here are judged by examiners and auditors as well as executives. Each seat's exposure, the early sign, and the question worth asking this quarter.

COO / Risk

Evidence of operation is the deliverable

A control that exists without documented evidence that it operated is a finding. The failure pattern is not missing controls, it is controls operating informally while the program protects its schedule. Expedited change paths and untested role models are the two places that happens most.

Early sign

Expedited changes are being approved verbally to protect the go-live date.

Ask this quarterWhat is our agreed change path, and who has approved anything outside it?
CFO

The close depends on reports nobody validated

Reliance on system reports without adequate validation is the recurring material weakness in this sector. Every report feeding a key control is part of the control environment, and building that inventory during the program is days of work against months of remediation later.

Early sign

No documented report inventory exists with validation status per line.

Ask this quarterWhich reports feed our key controls, and which have tested validation?
CHRO

Access and joiner-mover-leaver are control processes

Access provisioning, role change and termination are examined controls here, not HR conveniences. A mover who keeps prior access is a segregation of duties conflict created by an HR process, and it will be sampled. The design has to make the correct outcome the automatic one.

Early sign

Role change relies on someone remembering to remove prior access.

Ask this quarterWhat happens to prior access on a role change, automatically?
The Control Trail

Four points where the environment is decided

Decision two, drawn out. None of these are audit activities. They are design decisions that determine what an audit will find.

Role designConflicts, in or out Designed in, they are cheap to remove. Found later, the remediation is organizational rather than technical.
Report buildValidated, or relied upon A report feeding a control is part of the control. Completeness and accuracy evidence belongs here, not in a remediation.
Change pathAgreed, or informal A process sized for steady state either blocks the program or gets routed around. The second is the one that gets written up.
Go-liveOwnership, named Two vendor releases a year land on the control environment forever. Unowned, a control stops operating quietly.

Every one of these is cheaper as a design decision than as a remediation. The difference is usually a factor of ten and a supervised timeline.

03Dates That Do Not Move

Four items already on the calendar

None of these are sector-specific, and all four land harder in a regulated environment because each one touches the control estate.

2027-03-31 UKG Workforce Central on premises reaches end of life

Engineering stopped at the end of 2025. Moving off it is a reimplementation rather than an upgrade, and any shift-based workforce is in scope.

2027-12-31 SAP ECC mainstream maintenance ends

Extended maintenance runs to 2030 for a fee. If the target platform is a lift and shift of ECC, it arrives with a published expiry date attached.

Not a deadline PeopleSoft is not a burning platform

Oracle support runs past 2036. When an integrator sells urgency on that basis, the pressure is customization debt and scarce skills, not vendor abandonment. Knowing the difference is a negotiating position.

March and September Two Workday feature releases a year, with a five-week preview

Not a deadline, a treadmill. Two mandatory regression cycles annually, permanently, and the item most reliably missing from a post-go-live staffing plan.

04The Two-Minute Check

Five questions worth more than a readiness assessment

Answerable from memory, scored on this page, nothing captured and nothing emailed.

1How was the role model tested for conflicts?
2Is there a validated inventory of control-relevant reports?
3Has a program-scale change path been agreed?
4Can a reported figure be traced to source without asking a person?
5Who owns each key control after go-live?
Answer all five for a verdict.
0 / 10

These five are the start of the instrument. A full review also covers access recertification, interface controls, close automation and the regression plan for each vendor release. Or skip the tooling and book the program review.

76Client engagements
25+Years running large programs
$65MLargest single program
16Industries served

Building a control environment, not just a system?

Pre-SOW, mid-build, or remediating a finding with an examiner in the room. I sell no software and staff no builds, so these questions get asked out loud. Tell me where the program is and I will tell you what I see.