Kolena AI Agent

ERM Controls & Metric Review

Evaluate risk controls for design AND operating effectiveness, map them to the risk register, review KRIs and KPIs against appetite thresholds, and produce a severity-ranked findings register - with a citation on every conclusion.

Banking / LendingCompliance Testing

Impact

A control-effectiveness and metric review that took risk and audit analysts days of manual cross-referencing across the control testing procedure, risk register, process maps, and metric dashboards - produced in minutes, with separate design and operating conclusions, metric breach flags, and a citation on every line

per control review

Volume fit

Works best for

risk, compliance, and internal-audit teams reviewing many controls and metrics across a portfolio each quarter or testing cycle, and re-reviewing each time controls, risks, or thresholds change

Too small for

a one-off read of a single control with no risk register, testing procedure, or metrics to review against

Typical inputs

Documents

  • Control inventory / control documentation and control testing procedure (the methodology and required elements)
  • Risk register or RCSA (the risk taxonomy the controls are mapped against)
  • Business process maps (to confirm control placement)
  • Control testing results and exception / issue reports
  • KRI / KPI / KCI dashboards, scorecards, or monitoring reports with defined thresholds

Systems

  • GRC / risk-and-control platform
  • Risk register / RCSA system
  • Workflow / BPM platform and the system of record
  • Metric / KRI dashboard and reporting tools

Output

An ERM controls & metric review - a review-scope summary, a control inventory, a risk-to-control mapping with inherent/residual ratings, separate control design and operating-effectiveness assessments, a per-control effectiveness rating with deficiency severity, a KRI/KPI metric-vs-threshold review with breach flags, a severity-ranked issues-and-findings register, an overall control-environment verdict, a metric-appetite verdict, and a cited executive summary

Delivered to

  • GRC / control-inventory system
  • Issue / remediation tracker
  • Risk committee and board risk reporting pack
  • Internal audit and examination workpapers

What it extracts

· 11 fields
  • Form

    Review Scope Summary

    A one-look roll-up of what is under review - the business line and products, the frameworks applied (COSO, Three Lines), the control testing procedure, risk register, process maps, and metric sources referenced, and the review period - so a reviewer can orient before the control and metric detail.

  • Table

    Control Inventory

    The controls under review parsed into one row each, with a stable ID, objective, first-line owner, line of defense, control type (preventive/detective/corrective), nature (automated/manual/IT-dependent), frequency, products covered, system dependencies, and governing procedure.

  • Table

    Risk Register and Risk-to-Control Mapping

    Each in-scope risk from the register mapped to the control(s) that mitigate it, with risk category, inherent and residual ratings, and a mapping-adequacy call; risks with no adequate control are flagged as gaps.

  • Table

    Control Design Assessment

    Per control, whether it is adequately DESIGNED - the required What/Who/How/How Often elements present, its placement in the process map, and its frequency adequacy - judged from design and documentation, not test results.

  • Table

    Control Operating Effectiveness Assessment

    Per control, whether it actually OPERATED effectively across the period - the test and its population, the results, and any bypasses, failures, overrides, or non-performance and whether they were remediated.

  • Table

    Control Effectiveness Rating

    Design and operating conclusions combined into one effectiveness rating per control (Effective / Needs improvement / Ineffective) plus a deficiency-severity classification (deficiency / significant deficiency / material weakness).

  • Table

    KRI and KPI Metric and Threshold Review

    The metric side of the review - each KRI/KPI/KCI compared to its appetite/tolerance threshold, placed in a Green/Amber/Red zone with a breach flag and trend, and the governance response owed on a breach.

  • Table

    Issues and Findings Register

    The severity-ranked action list - one row per risk-coverage gap, per control rated needs-improvement or ineffective, and per metric breach, each with severity, root cause, impact, a concrete remediation, an owner, and a target date.

  • Classification

    Overall Control Environment Rating

    A single verdict on the control environment - effective, effective with minor deficiencies, significant deficiencies identified, material weakness identified, or needs manual review - weighting controls over high inherent risks most heavily.

  • Classification

    Metric Appetite Status

    A single verdict on where the business line sits against its risk appetite - within appetite, approaching tolerance, threshold breach detected, no metrics provided, or needs manual review.

  • Form

    Review Executive Summary

    The executive conclusion a risk committee or audit lead reads first - the control-environment and metric verdicts, effective vs. deficient control counts, significant deficiencies and breaches, coverage gaps, a three-lines accountability note, priority actions, and a two-paragraph narrative with cited examples.

Prerequisites

  • A control testing procedure defining the methodology and required control elements (What / Who / How / How Often)
  • A risk register / taxonomy to map controls against (controls can be inventoried without it, but risk coverage cannot be scored)
  • Defined KRI / KPI thresholds tied to the organization's risk appetite and tolerance (required to flag metric breaches)

Human review

A second-line risk/compliance reviewer or third-line internal auditor reviews the control inventory, the risk-to-control mapping, the design and operating conclusions, the metric breaches, and the cited findings before the review is trusted and findings are routed to owners for remediation.

Where it fits

Enterprise risk management - control assurance and risk/metric monitoring

Risk and control identification - the risk register / RCSA, control inventory, control testing procedure, business process maps, and KRI/KPI dashboards are maintained and queued for a periodic controls & metric review

This step

Controls & metric review (control design + operating effectiveness assessment and metric-vs-threshold review)

After

Issue / finding remediation and control build-out
Risk committee and board risk reporting
Internal audit and examination readiness (control-effectiveness evidence)
RCSA refresh and residual-risk re-rating

Who uses it

Risk ManagerOperational Risk AnalystCompliance OfficerInternal AuditorGRC / Controls AnalystChief Risk Officer

Grounded in

  • COSO, Internal Control-Integrated Framework (2013)verified as of 2026-07-22
  • COSO, Enterprise Risk Management-Integrating with Strategy and Performance (2017)verified as of 2026-07-22
  • The Institute of Internal Auditors (IIA), The Three Lines Model (2020 update of the Three Lines of Defense)verified as of 2026-07-22
  • PCAOB Auditing Standard AS 2201 (An Audit of Internal Control Over Financial Reporting Integrated with an Audit of Financial Statements) - control-deficiency severity taxonomyverified as of 2026-07-22
  • Risk appetite, risk tolerance, and Key Risk Indicator (KRI) threshold practice (COSO ERM 2017; common industry / IIA practice)verified as of 2026-07-22

Related agents

Browse all agents →

See ERM Controls & Metric Review on your documents

We'll run it against a file of yours and walk through every cited field.