The control has to work, and you have to be able to prove it did.
Program governance and quality discipline for regulated financial environments. What separates this sector is not that controls exist, it is that operating a control without evidence of operation is the same as not having it, and that reality has to be designed in rather than documented afterwards. Walk the five decisions, find your seat, then run the two-minute check.
Five calls that decide a regulated program
Each one determines whether the control environment is designed or inherited. Pick a decision.
Security gets configured to a role matrix that looks correct on paper, then tested by administrators who can see everything.
Design segregation of duties into the role model before build, and test it as ordinary users at real permission levels.
Conflicts designed in are cheap to remove and expensive to find later, because by then people are doing their jobs through those roles. The remediation is not technical, it is organizational, and it lands during an audit window when there is no capacity to redesign access.
Who has tested our role model for conflicts as an ordinary user rather than an administrator?
Key reports get built, reviewed for whether the numbers look right, and put into production without documented completeness and accuracy validation.
Inventory every report the close and the controls depend on, and document and test completeness and accuracy for each.
This is the single most common finding in the sector and it is entirely preventable. A report that feeds a control is itself part of the control environment. Building the inventory during the program costs days. Reconstructing it during a remediation costs months and happens under supervision.
Which reports feed our key controls, and where is the validation evidence for each?
The program moves fast, the change process is designed for steady state, and expedited paths appear informally to protect the schedule.
Agree a program-scale change path with your control owners before build, including what an expedited change requires.
Either the process becomes the bottleneck or people route around it, and the second breaks the evidence trail. Agreeing the path in advance is cheap and rarely done, and the informal expedited route is precisely what shows up in a walkthrough.
What is our agreed program change path, and is anyone routing around it?
Regulatory and management reporting gets built on aggregates, and the path from source transaction to reported figure is understood by a few people rather than documented.
Design lineage deliberately, so every reported figure traces to source with the transformations documented.
The question that arrives is not whether the number is right, it is how you know. Lineage held in people rather than in design is a single point of failure that also fails an examination. Building it in is a design cost; retrofitting it is a project.
Can we trace a reported figure to source transactions without asking a specific person?
The program owns the control environment while it is running, and ownership after go-live is assumed rather than assigned.
Assign named steady-state owners for each key control and each key report before go-live, and fund the regression cycle.
Two vendor feature releases a year land on the control environment, permanently. Without named ownership, the first release after the program disbands is when a control quietly stops operating as designed, and the finding arrives a quarter later.
Who owns each key control after the program team leaves, by name?
What those five mean for the chair you sit in
Programs here are judged by examiners and auditors as well as executives. Each seat's exposure, the early sign, and the question worth asking this quarter.
Evidence of operation is the deliverable
A control that exists without documented evidence that it operated is a finding. The failure pattern is not missing controls, it is controls operating informally while the program protects its schedule. Expedited change paths and untested role models are the two places that happens most.
Expedited changes are being approved verbally to protect the go-live date.
What is our agreed change path, and who has approved anything outside it?
The close depends on reports nobody validated
Reliance on system reports without adequate validation is the recurring material weakness in this sector. Every report feeding a key control is part of the control environment, and building that inventory during the program is days of work against months of remediation later.
No documented report inventory exists with validation status per line.
Which reports feed our key controls, and which have tested validation?
Access and joiner-mover-leaver are control processes
Access provisioning, role change and termination are examined controls here, not HR conveniences. A mover who keeps prior access is a segregation of duties conflict created by an HR process, and it will be sampled. The design has to make the correct outcome the automatic one.
Role change relies on someone remembering to remove prior access.
What happens to prior access on a role change, automatically?
Four points where the environment is decided
Decision two, drawn out. None of these are audit activities. They are design decisions that determine what an audit will find.
Every one of these is cheaper as a design decision than as a remediation. The difference is usually a factor of ten and a supervised timeline.
Four items already on the calendar
None of these are sector-specific, and all four land harder in a regulated environment because each one touches the control estate.
Engineering stopped at the end of 2025. Moving off it is a reimplementation rather than an upgrade, and any shift-based workforce is in scope.
Extended maintenance runs to 2030 for a fee. If the target platform is a lift and shift of ECC, it arrives with a published expiry date attached.
Oracle support runs past 2036. When an integrator sells urgency on that basis, the pressure is customization debt and scarce skills, not vendor abandonment. Knowing the difference is a negotiating position.
Not a deadline, a treadmill. Two mandatory regression cycles annually, permanently, and the item most reliably missing from a post-go-live staffing plan.
Five questions worth more than a readiness assessment
Answerable from memory, scored on this page, nothing captured and nothing emailed.
These five are the start of the instrument. A full review also covers access recertification, interface controls, close automation and the regression plan for each vendor release. Or skip the tooling and book the program review.
Building a control environment, not just a system?
Pre-SOW, mid-build, or remediating a finding with an examiner in the room. I sell no software and staff no builds, so these questions get asked out loud. Tell me where the program is and I will tell you what I see.
