Client Stories
Testimonials and longer accounts from application audits of risk control monitoring applications.
Voices from recent work
“They spent three days with our second-line operators before writing a word. The report named the exact alert thresholds that were masking overdue control attestations.”
Keiko M., Head of Operational Risk — regional bank, Tokyo
“Useful, though denser than our board pack usually allows. We asked them to add a one-page summary for the committee, which they did without softening the findings.”
Daniel R., Internal Audit Director — logistics group
“The mapping review caught forty-two controls in the application that no longer matched any live process. Fixing that was tedious, but better than discovering it in a regulatory interview.”
Aya S., Control Inventory Lead — manufacturer, Kansai
“I expected more discussion of industry frameworks. Instead they stayed inside our monitoring application and exception queues. That focus was right for us, even if our framework team wanted broader commentary.”
Marcus L., Risk Governance Manager
Extended story: exception queues that never aged out
A Tokyo headquarters asked Reason Space to examine two risk control monitoring applications used by branch operations. Scoping locked six control families and a ninety-day sample window.
Fieldwork showed that escalation rules existed on paper inside the application, yet operators cleared aged items by rewriting due dates rather than closing root causes. Alert emails routed to a shared inbox that three teams claimed and none owned. The findings register ranked residual exposure by branch volume, not by how dramatic the screenshots looked.
Remediation began with ownership of the shared inbox and a freeze on due-date edits without second-line approval. A follow-up Remediation Readiness Review six weeks later confirmed the queue age had fallen for four of six families; two remained open pending staffing decisions the audit could not invent.
Extended story: mapping before a committee deadline
Ahead of an audit committee, a corporate second line requested a Control Mapping Review rather than a full application audit. In three weeks we reconciled the monitoring application export against the approved inventory and found silent orphans — monitored items with no control owner — and inventory rows with no monitoring path.
The committee received a gap list and a short memo, not a multi-chapter report. The client later commissioned a Full Application Control Audit once access and ownership questions were settled.