Skip to main content

Assessments

Written by Hyperproof Support

Hyperproof supports control, requirement, and risk assessments.
​

Assessments help you review, evaluate, and improve controls, risks, or requirements across your organization. Some common compliance frameworks that encourage control-based assessments are NIST and SOC 2.
​

Controls, requirements, and risks can be audited for attributes including design, language, effectiveness, and reliability. When your organization’s controls, requirements, and risks are sufficient, internal audits based on a Document Request List (DRL) run much more smoothly because the bulk of the work is already done.
​

Many organizations perform assessments for the following reasons:

  1. Early detection - Routinely checking your controls, requirements, and risks for exceptions helps you find them more quickly.

  2. Continuous improvement - Looking critically at your controls, requirements, and risks is the best way to ensure you’re not wasting resources.

  3. Minimize risks - Quickly find exceptions and non-functional controls, requirements, and risks to minimize risk exposure.

  4. Audit preparation - If you find and fix issues with your controls, requirements, or risks, there will be fewer for your auditor to report.

Assessment Process

A typical process that an organization might use to perform an assessment could include:

  1. Choosing objectives

  2. Selecting controls, requirements, or risks to evaluate

  3. Deciding how to evaluate those controls, requirements, or risks

    1. Writing tests for operational effectiveness

    2. Selecting a framework to evaluate the design

  4. Managing the project

    1. Assigning work

    2. Collaboration

    3. Following up

  5. Tracking and remediating issues

Did this answer your question?