Controls testing

A control test needs a third state: cannot verify.

Definite maps a control population and its supporting evidence into a finance ontology. Configured checks issue the result, incomplete evidence stays unresolved, and people review it with its source context attached.

Bring one control
Illustrative test run

The evidence can change. The configured check stays the same.

The example below shows the same vendor-master control before and after an approval record is added to the evidence set.

Illustrative · Vendor master change approval · Q2 FY2026 · sample 10 of 214Run conclusionCANNOT_VERIFY · 2 FAILURES + 1 REVIEW ITEM
ChangeAttributeFindingResult
VM-1042Approval timingApproval recorded before the vendor record was updatedPASS
VM-1087Approval timingApproval recorded after bank details were updatedFAIL
VM-1114Separation of dutiesRequestor and approver resolve to the same userFAIL
VM-1140Approval evidenceNo approval record is present in the evidence setCANNOT_VERIFY
6 remainingAll attributesThe retained evidence supports every configured testPASS

The missing approval record cannot be treated as a pass or a fail. Definite keeps it in CANNOT_VERIFY until a reviewer supplies evidence or records that it is unavailable.

Unchanged
Configured checks and mapped population
Changed
Approval record added to the evidence set
Result
CANNOT_VERIFY becomes FAIL

Fictional records, sample sizes, and results shown only to explain the review logic.

Control definition

Define the control before running it.

Definite is configured around how the team defines and performs the control today, including what belongs in the population and what evidence is required.

  1. 01

    Control narrative

    The process and control objective the team performs today.

  2. 02

    Population definition

    The records in scope, source counts, exclusions, and unresolved gaps.

  3. 03

    Configured checks

    The repeatable rules, thresholds, and conditions applied to each item.

  4. 04

    Required evidence

    The records and support needed for the check to reach a conclusion.

Re-performance

Keep the basis for every run inspectable.

Inputs, mappings, rules, parameters, evidence changes, and review decisions remain attached so the same run can be re-performed.

  1. 01

    Source evidence

    Record and field lineage stays attached.

  2. 02

    Mapped population

    Identities, dates, approvals, and evidence are related.

  3. 03

    Rules & parameters

    The configured basis for each result is retained.

  4. 04

    Run result

    PASS, FAIL, and CANNOT_VERIFY remain explicit.

  5. 05

    Review decision

    Added evidence and reviewer decisions stay with the run.

Preparer

Assembles the mapped population and required evidence.

Approver

Reviews exceptions and incomplete evidence as a separate role in the data layer.

Bring one control that is painful to test.

We map its population, required evidence, repeatable checks, and review path before configuring the workflow.

Show us the control