FEATURE / 01
Process Hierarchy Mapped to Financial Statements
Every process and control activity is fully referenced to the financial statement line item it supports.
BenefitEnsure the evaluation completely addresses all material financial statement line items and nothing is omitted. Reduce compliance costs by focusing audit scope on only relevant processes that pose a calculated risk of financial misstatement.
FEATURE / 02
Detailed Risk Assessments
The defining feature of OSA is a comprehensive risk assessment process to ensure the evaluation is aligned with process owners' responsibilities and priorities. Every control is documented based on a specified objective, as required by COSO. Process and control multi-level risk rankings are calculated based on measured impact and likelihood. A detailed, specific fraud risk assessment ensures adequate controls exist to mitigate loss and financial misstatement.
BenefitEvaluation is performed with clear focus and resource attention to high-risk areas with impactful results toward optimizing business processes and mitigating preventable risks. Every testing action is based on a defined risk assessment.
FEATURE / 03
Control Testing
Testing procedures, milestones, automated updates for percentage of completion based on sample size populations, auditor conclusions, planning timelines & resource allocations available in real-time.
BenefitQuantified, measurable testing, analysis, and results — packaged for management and audit committee reporting that shows direct compliance with COSO risk management requirements.
FEATURE / 04
Gap Tracking & Remediation
To ensure full accountability for gap correction — every identified deficiency is logged, assigned, and tracked through remediation with a full workflow history.
BenefitTimely gap remediation and control owner accountability with emphasis on risk mitigation, meeting assigned deadlines and prevention of financial loss and misstatement.
FEATURE / 05
KPI Management & Real-Time Reporting
Live dashboards with 22 KPIs across five categories — measuring evaluation status, aggregating testing progress, gaps. Analyze the underlying reporting data by clicking on graph components and transitioning to data details.
BenefitReal-time visibility for the audit committee and management, enabling prompt decision making. No delays or inefficient duplication of meetings for manual project status report compilation.
FEATURE / 06
Multi-Process Owner Certification
Process owner certification workflows are designed for ease of use, understanding, and risk mitigation for process owners who are not accountants. Clarity of understanding of risk management helps reduce the risk of financial misstatement by consolidating the foundation of internal controls responsibilities into a user-friendly experience.
BenefitEnhanced accountability of process owner oversight to ensure the operating effectiveness of internal controls. Timely resolution of gaps due to a clear understanding of the negative impact of unmitigated risks.
FEATURE / 07
Change Indicator Workflows
Automated compilation of changes in process, technology, personnel, policy, etc., to determine high-risk focus areas and an action plan to mitigate new risks.
BenefitIdentified changes are highlighted for re-active plans to implement preventative measures and mitigate potential risk of financial loss and misstatement. Versioning is enforced on all relevant data elements to maintain audit logs of all changes.
FEATURE / 08
Audit Planning
Build the annual ICFR testing calendar, assign reviewers, and track milestones against filing deadlines.
BenefitRelevant data for concise decision making to allocate resources to perform the evaluation within timelines required by external auditors, management, and audit committees.
FEATURE / 09
Secure User Access Management
Enforced role-based user access permissions ensure privacy of your entity data. Views and roles for non-accountants are simplified for a productive and transparent user experience.
BenefitDesigned to meet industry cybersecurity risk mitigation requirements to secure your internal controls data and user information and reduce the likelihood of a cybersecurity breach.