Features
Available nowControls and control testing
Define what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.
The problem it solves
A control list without owners and testing is an inventory, not a programme. When an assessor asks how a control operates, the answer is usually reconstructed from memory by whoever happens to be available.
How it works
- 1
Describe the operating expectation
Each control records what it does, how frequently it operates and what a satisfactory result looks like. That description is the reference point for every later test.
- 2
Assign accountable ownership
Ownership sits with a person, not a team inbox. Owners see what they are responsible for and when the next review falls due.
- Named owner with review cadence per control
- Implementation status maintained against the described expectation
- History retained when a control description or owner changes
- 3
Test and record the result
Test results are recorded against the control with the tester, the date and the evidence examined. Failures create remediation items instead of disappearing into a report.
Capabilities
Control library
One control set shared across activated frameworks.
Ownership and cadence
Named owners, review frequency and due dates.
Test records
Test outcomes with tester, date and the evidence examined.
Remediation tracking
Failed tests generate tracked actions with owners.
What people remain responsible for
- Approving control descriptions and operating expectations
- Performing and signing off control tests
- Deciding whether a deficiency is remediated or accepted
Related capabilities
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.