Finds the controls that exist on paper and nowhere else
Compliance programmes accumulate controls. Each was created for a real reason, written into a policy, assigned an owner and a frequency, and then left. Nobody removes one, because removing a control means explaining why it is unnecessary — harder than leaving it. The register grows every year and the capacity to perform them does not.
What follows is predictable. Controls owned by people who left. Controls performed but never evidenced, which is indistinguishable from not performed when an auditor asks. Quarterly controls performed twice a year. Controls requiring an independent reviewer where the reviewer is the person who did the work — the segregation failure that turns a control into paperwork. And attestations signed in bulk on a deadline, which is a signature rather than a check.
The dangerous version is the documented control nobody performs, because the organisation believes a risk is covered when it is not. An undocumented gap is at least known.
This agent reads the register against what was actually done and reports which risks are covered only on paper. It never asserts that a control was effective — that judgement requires evidence and accountability belonging to a person who signs their name to it.
Rather than which ones have a policy about them.
And a register you can defend.
The ones nobody performs and nobody misses.
The dangerous kind. The organisation believes a risk is covered when it is not, and an undocumented gap is at least known.
A control performed and never evidenced is indistinguishable from one never performed, when asked.
An independent check performed by the person who did the work. The control exists and does nothing.
Forty sign-offs in one minute on a deadline is a signature, not a check.
Owned by someone who left. Nobody notices, because a control with no owner produces no complaints.
Whether a control worked is a judgement someone signs their name to. It reports what was done.
Why Compliance & Risk in particular. A documented control nobody performs is worse than no control, because the organisation believes a risk is covered. An undocumented gap is at least known.
Runs unattended
Started by you or by an event, and it finishes on its own. Nothing waits for someone to be at a desk.
The same standard every time
The two-hundredth item is held to the bar the first one was. Consistency is the part people cannot sustain.
It cannot act on its own
Control Attestation Agent has no path to sending, spending or committing. That limit is why its output is safe to act on.
This agent runs server-side through the PROMIVO runtime. Each run is logged step by step and every tool call is permission-checked before it executes.
Read-only by design. This agent has no path to sending, spending, publishing or committing anything. Where that limit is the product, removing it would remove the reason to trust the output.
Demo dataIllustrative sample output, abridged.
{
"period": "H1 2026",
"controls": []
}{
"escalate": true,
"disclaimer": "A review of the control register against performance records. Nothing has been signed, attested, approved or performed; no control is stated to be effective; no compliance determination is made; and no individual is assessed.",
"onPaperOnly": [
{
"control": "CTL-118 — Quarterly review of privileged access",
"riskRating": "High",
"riskAddressed": "Unauthorised access to production systems"
}
],
"bulkAttestation": [
"41 attestations were signed within 90 seconds on the final day of the quarter. That is a signature rather than a check, and it is a process finding rather than one about anybody."
],
"escalationReason": "A control mapped to a High risk has no performance record, a control requiring independence was self-reviewed six times, and three controls are owned by people who have left.",
"orphanedControls": [
"Three controls are owned by two people who left in March. Nobody noticed, because a control with no owner produces no complaints."
],
"candidatesForReview": [
"CTL-402 has been performed 24 times over three years and raised no finding. Worth asking whether it addresses a live risk — a design question, not a recommendation to remove it."
],
"frequencyShortfalls": [
{
"control": "CTL-090 — Quarterly reconciliation review",
"required": 2,
"performed": 1
}
],
"independenceFailures": [
"CTL-311 requires review by someone other than the preparer. All 6 performances were prepared and reviewed by the same person. The control exists and does nothing."
],
"performedNotEvidenced": [
"CTL-204 was performed 6 times with no evidence attached to any. To an auditor that is identical to never having been performed."
],
"risksCoveredOnlyOnPaper": [
"Unauthorised access to production systems is rated High and its only control has no performance record this period. The organisation believes this is covered."
]
}No integrations required.
What was performed, evidenced and by whom.
The gaps a reviewer would open with.
Which controls lost their owner in the move.
Which controls earn their place.
$349/month
Billed monthly through your PROMIVO subscription. Cancel at any time.
Runs consume your plan allowance for agent executions and tokens. See plan limits.
No. Effectiveness is a judgement with accountability attached to whoever signs it. This reports whether a control was performed, evidenced, and by someone independent — the facts that judgement needs.
Never. It signs nothing, attests to nothing and closes nothing. A control signed by an agent is not a control.
No. It reports control-level findings. Where a pattern involves one owner it reports it as a capacity or design question, because a person owning forty controls is a register problem, not a personal one.
No reviews yet. Reviews open once customers have run this agent.
Tell us what to change and our team will scope a customised version for your business.
Customize this agent