KIRAN
Key Internal Risk and Assurance Navigator
- Position
- Controls Testing
- Value chain
- Monitor to Comply
- Role
- Tests defined control evidence across the whole population, and puts the exceptions in front of the people who grade them.
Steward · Monitor to Comply
Assurance is retrospective by construction. A control either was operating on the day or it was not, and the only way to answer that afterwards is to have been watching at the time. That is where the digital coworkers stand, inside the systems that already generate the evidence.
A control operating over eleven thousand transactions that failed twice will pass a test of forty, and those two are exactly the ones the control exists to catch. Everything on this chain follows from that arithmetic, including the part where the failure is found long after the transactions have cleared.
USD 20.9bn
Reported losses across more than a million complaints in a single year
FBI IC3 Internet Crime Report, 2025
USD 893M
AI-related fraud losses across 22,364 complaints, the first year the category was recorded
FBI IC3, 2025
77%
Share of countries where businesses report rising administrative compliance costs
OECD, 2026
AUD 21.27M
Model maximum monetary penalty for industrial manslaughter by a body corporate
Safe Work Australia model WHS Act, from 1 July 2026
Where the pressure shows up
Forty items are chosen on a defensible basis, and the population they stand in for is never the part that failed.
Who feels itHead of internal controls · population and control coverage
A control that stops operating is found at the next test, and everything that passed through it before then has cleared.
Who feels itInternal-controls analyst · deficiency detection lead time
The instruction is correctly formatted, correctly authorised and within delegated authority, and it is still not legitimate.
Who feels itHead of fraud and financial crime · high-risk alert time to review
Rules raise more alerts than anyone can work, so the cases that need an investigator wait behind the ones that do not.
Who feels itFraud analyst · false-positive alert rate
The same documents are asked for again because nobody can show which copy is the current, complete and approved one.
Who feels itAudit coordinator · request fulfilment time
Regulatory change arrives through advisers, filtered and pitched at the sector rather than at the processes you run.
Who feels itCompliance officer · detection-to-owner time
The work here is cross-cutting. Every other value chain owns a flow; this one owns a property of all of them, which is that they are under control and can be shown to be. What it needs is generated inside the eight chains it does not own, so its cost falls as the rest of the workforce grows.
The sequence, as the chain’s own definition enumerates it
what we must do
RROWAN
what could fail
·Held by your team
what prevents it
·Held by your team
does it operate
KKIRAN
what got through
FFARAH
can we prove it
AARTURO
what moved, back into 01
RROWAN
Stage 07 re-enters the obligation register at 01, so the chain has no final position and ROWAN holds both ends of it.
Who owns this chain today
Read down any position on a chart and it tells you who is accountable for it, what its holder may do without asking, and who picks up the call that is not theirs to make. A digital coworker is written up the same way, and the answers do not change because the holder is not a person.
KIRAN
Key Internal Risk and Assurance Navigator
KIRAN Controls Testing
KIRAN
My reading is a significant deficiency, and the grading is yours. If you agree, I propose to record it on that grading with the population, the window and the value at risk attached, and to queue the re-test behind whatever remediation you assign. Shall I proceed?
Head of Internal Controls Second line
Checked against the change log. The tolerance was amended and never reapproved. Grade it a significant deficiency, assign remediation to the control owner, and proceed.
Seen by KIRAN
KIRAN Controls Testing
Recorded on your grading, with the population, the window and the value at risk attached. Remediation assigned to the control owner as you directed, and the re-test queued behind it.
Deficiency graded by the Head of Internal Controls.
The four positions were written up so that whoever produces the evidence is never the one grading it, and whoever finds the pattern is never the one acting on it. That separation is what an audit committee is actually being asked to accept.
Nothing below replaces professional judgement or declares anything compliant. What changes is where the expert hours go: out of repetitive testing and evidence chasing, and into the exceptions. How much it moves for you is sized from your own data in the first session.
Population coverage, not a sample
Every in-scope item is tested against the defined control, so the tested set and the population become the same set.
KPIKIncreasePopulation coverage of key controls
A stopped control is found while it is stopped
Testing runs alongside the work rather than after the period, which closes the gap between a control failing and somebody owning it.
KPIKDecreaseDeficiency detection lead time
Alerts arrive as cases, not as volume
Duplicates are grouped and the counter-evidence is already searched, so an investigator opens a case pack rather than a queue.
KPIFDecreaseFalse-positive alert rate
Evidence produced once and reused
Evidence already accepted and still current is not produced again, which is the largest single source of avoidable audit effort in most organisations.
KPIAIncreaseEvidence reuse rate
Change reaches a named owner
Published change is classified, scoped to the entities it touches and routed to whoever owns the process, ahead of the effective date.
KPIRDecreaseDetection-to-owner time
Judgement stays where it belongs
Grading, control-design opinion, risk acceptance and closure remain with the people authorised to make them.
KPIKDecreaseReviewer rework on findings
A digital coworker works inside the systems, data, policies and authorisations you already have. It is given the access a person in the same position would be given, and no more. Your auditors test it in the environment they already know.
What the role works inside
Enterprise applications
ERP, risk, finance, case management and the operational systems where controls actually run.
Master data
Control register, obligation register, transaction, party and evidence records.
Policies and controls
Control descriptions, tolerances, monitoring rules and evidence acceptance criteria.
Authorisations
Defined permissions for every action performed by the role.
Governance
Security, privacy, service levels, change governance and escalation.
The control model
Defined actions, inside the authority you set.
Prepares the case and hands the decision up.
Anything outside the authority the role holds.
Both sides put a signature on the same page before anything is built, and the ProxyN lead who signs is accountable for it in the way your sponsor is. Nothing in it gets agreed after the result is known.
What gets signed
Five lines both sides sign before anything is built. Every one is a fact about your operation, not a forecast about ours.
What happens after signing
The order the work runs in, one role at a time. The seventh step is the first step of the next loop.
What we need from you
A past test cycle, case set or regulatory change to replay the role against before it goes live
The control and obligation registers and the evidence acceptance criteria the role will work inside
The accountable person for the number, in the room for the first session, with internal audit invited
Get started
Bring one workflow and the person accountable for it. In the first session we map the process, establish the baseline logic and tell you whether there is a number worth signing. If there is not, we will say so.