Skip to main content

Assessments

Written by Hyperproof Support
Updated this week

Hyperproof supports control, requirement, and risk assessments.

Assessments help you review, evaluate, and improve controls, risks, or requirements across your organization. Some common compliance frameworks that encourage control-based assessments are NIST and SOC 2.

Controls, requirements, and risks can be audited for attributes including design, language, effectiveness, and reliability. When your organization’s controls, requirements, and risks are sufficient, internal audits based on a Document Request List (DRL) run much more smoothly because the bulk of the work is already done.

Many organizations perform assessments for the following reasons:

  1. Early detection - Routinely checking your controls, requirements, and risks for exceptions helps you find them more quickly.

  2. Continuous improvement - Looking critically at your controls, requirements, and risks is the best way to ensure you’re not wasting resources.

  3. Minimize risks - Quickly find exceptions and non-functional controls, requirements, and risks to minimize risk exposure.

  4. Audit preparation - If you find and fix issues with your controls, requirements, or risks, there will be fewer for your auditor to report.

Assessment Process

A typical process that an organization might use to perform an assessment could include:

  1. Choosing objectives

  2. Selecting controls, requirements, or risks to evaluate

  3. Deciding how to evaluate those controls, requirements, or risks

    1. Writing tests for operational effectiveness

    2. Selecting a framework to evaluate the design

  4. Managing the project

    1. Assigning work

    2. Collaboration

    3. Following up

  5. Tracking and remediating issues

Did this answer your question?