Governance, risk and compliance

SmartSuite for the Controls Testing Lead

The Controls Testing Lead plans and runs the control testing programme: sampling, test procedures, tester assignments, evidence standards and quality review. They make sure every key control is tested on schedule and that results are consistent enough to rely on.

What you own

  • Plan the testing calendar and sampling approach for key controls
  • Write and maintain test procedures and evidence standards
  • Assign testers and track completion against the schedule
  • Review test workpapers for quality and consistency
  • Log exceptions and route them to deficiency evaluation
  • Report testing status and exception trends

Where the role sits

Each name opens that role's page.

Reports to

Internal Controls Manager

Internal Controls Manager

See the role
Head of Internal Controls

Head of Internal Controls

See the role

Direct reports

Works closely with

Compliance Analyst

Compliance Analyst

See the role
Internal Auditor

Internal Auditor

See the role
Control Owner

Control Owner

See the role
SOX Program Manager

SOX Program Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

compliance

Touches

contributes or approves

audit, issues-actions, reporting

Depends on

consumes its output

risk

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Schedules and executes recurring control tests from a testing engine with procedures, samples and evidence attached to each test.

Internal audit. Keeps workpapers and sign-offs traceable for audit reliance.

Issues and actions. Logs exceptions and routes them to deficiency evaluation and remediation.

Reporting. Reports testing completion and exception trends by control, owner and period.

Industry reference

PCAOB AS 2201 and the AICPA's audit sampling guidance set the expectations for testing key controls: sample sizes by frequency, tests of design and operating effectiveness and workpapers a reviewer can re-perform. COSO 2013 defines the controls; the IIA's Standards cover engagement performance where internal audit relies on the work.

The same methods serve other attestations. SOC 2 examinations test operating effectiveness over a period; FedRAMP and CMMC assessments test NIST SP 800-53 controls; GAO's Yellow Book governs testing in government audits; HIPAA audits sample safeguards; bank examiners sample under FFIEC procedures.

In their words

Related roles

Internal Controls Manager

Internal Controls Manager

See the role
Head of Internal Controls

Head of Internal Controls

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.