Insight

Proving a Control Costs More Than Running It

The evidence most institutions file to prove a control worked is a folder of screenshots. Here is what a defensible answer contains, and a test to run on yours.
A man works on a laptop in front of screens displaying code.
Brendan Miller
Written by
Brendan Miller
The evidence most institutions file to prove a control worked is a folder of screenshots, and a screenshot proves what a settings page looked like on the afternoon somebody opened it. Anyone who has assembled evidence for a review knows the routine. Open each settings page, capture it, name the file to the auditor's convention, upload it to the shared folder. The tools that are supposed to collect this automatically break often enough that a person ends up doing it by hand, and that person is usually whoever holds the admin credentials, which is usually an engineer you would rather have doing something else.

The expensive part of a control is proving, six months later, that it worked. Running it costs far less.

A regulated financial institution already holds most of the record. The transaction sits in one system. The approval sits in another. The policy lives somewhere else, and the amendment that changed it may be in a shared drive. The exception is in a case manager. The resolution is in a ticket or an email.

Then an examiner, auditor or oversight team asks a simple question: did this control operate as required, for everything in scope, across the period under review? That is when the project starts.

A screenshot shows a moment. The exam asks about a period.

A screenshot shows a setting was on for Tuesday. It cannot show the setting was on for the whole quarter. A log shows a system took an action. It cannot say whether that action matched the policy, contract or network rule in force at the time. A dashboard shows what is true now, and the exam asks what was true then.

The standard goes beyond a correct answer. Another person, months later, has to see how you reached it and reproduce it from the underlying record. That takes evidence captured with its context: the rule, the source and what people did about it.

A defensible answer has four parts

1. What actually happened. The transaction, balance, approval, settlement or account state as the source system recorded it. The record itself with its source attached, not a picture of it.

2. What should have happened. The contract clause, fee schedule, network mandate, control or internal policy that applied on that date. Version matters. "The policy" is not enough when an amendment changed the requirement halfway through the period.

3. What happened when the record and the rule disagreed. Who received the exception, who investigated it, who escalated it, who had authority to approve the resolution, and what they decided. Without that trail you have a finding and nothing to show for how it was handled.

4. A way to reproduce the answer. A different person runs the same check against the same historical record six months later and gets the same result. If proving the control means rebuilding an afternoon of screenshots, spreadsheets and memory, the evidence was never assembled.

Continuous assurance means checking every event against the rule in force when it happened

A population-wide claim needs the population checked. A sample does not carry it.

Evidence of how a system behaved cannot rest only on that system's account of its own performance.

When the rule changes over time, the evidence has to keep the version that applied when the event occurred.

Cordant keeps the source, the rule and the resolution together

Cordant is the command center for modern financial infrastructure. It reads the records across the financial operation, connects each one to the agreement or policy that governs it, and keeps the source, the rule, the exception and the action together. When someone asks what happened six months ago, the answer is a query instead of a project.

Cordant certifies nothing, replaces no examiner and does not judge whether a control is adequate. It assembles the evidence so it is traceable and reproducible, and the people making those judgments all see the same record.

Run the test on your own evidence

Open the folder from your last examination or control review and pick ten pieces of evidence. For each one, ask two questions. Could a different person reproduce it today without rebuilding it by hand? Can they see exactly which requirement was in force when the event occurred?

Count how many of the ten pass both. That count is how much of your last review you could defend today.

As financial operations add rails, counterparties and agents, rebuilding assurance after the fact is the part that stops scaling.

‍

‍

Continue reading
A man works with a laptop and notebook.
September 22, 2026
Insight
Put The Command Center in Place Before the Ai Operating System
Before an institution gives agents authority over financial operations, it needs a command center that can tell them what actually happened, what should have happened and which record is right when the systems disagree.
Read article
A man considers his work beside a laptop in an office.
September 21, 2026
Insight
Money Moves in Seconds. Finding Out What Happened to It Still Takes Days
Payments now settle in a quarter of the time they took five years ago, yet finding out what went wrong with one still takes as long as it always did, and this year's research shows why.
Read article
Traffic light trails run through a city financial district at night.
September 21, 2026
Insight
Your Best Operators Know What Your Systems Do Not
Your most experienced operators carry a working model of how your operation really behaves, none of your systems records it, and it is the context your agents will need most.
Read article