What does continuous control testing actually mean?
Testing at the control’s own frequency rather than at review time. Every control is legally required to carry an owner, a timing and a frequency; each control’s test schedule is one automation running at that frequency, so a weekly control is tested weekly and the result is the evidence. The reframe underneath it came from the bank: all a control does is generate a signal about whether the right thing is being done.
Does this replace Line 2 challenge or Line 3 internal audit?
No, and it does not claim to. Line 2 gains a sampling surface — a monthly challenge pack generated from completed control tests, with a recorded opinion per sample. Line 3 gains a queryable system of record: run history, playbook definitions and evidence provenance, instead of binders. The judgment stays with the people whose job it is.
Why two instances instead of one?
Because they compute different things from different data. The regulatory instance works only on public material and computes what must be true. The bank instance holds internal control and evidence data under the full Australian sensitive-data posture and computes what is true. An org-private seam carries approved obligations and deltas between them; raw provenance never crosses. It also mirrors the real organisational boundary, and it limits blast radius.
Does anything reach APRA automatically?
No. Incident notification drafts are prepared with the relevant clock attached and the evidence bundle assembled, and they stop at a hard approval gate. Nothing regulator-bound leaves without a named person releasing it.
Does the bank have to replace its GRC system?
No. ServiceNow GRC remains the system of record and is unchanged. The loop sits above it. What it adds is the layer the system of record never held — the reasoning between a regulatory change and a control signal, kept with its provenance.
How does this help an accountable person under FAR?
What protects an accountable person is demonstrable reasonable steps — evidence with provenance and timestamps. The accountability view assembles, per accountable person, the obligations they hold, the controls mapped to them, the current signal state of those controls, and the evidence trail behind it.
Is the risk score a black box?
No — it renders its own formula. Five weighted signal classes: failed tests at 40 and recency-decayed, missed cadence or overdue evidence at 20, unowned controls and design gaps at 15, remediations past due at 15, and unassessed regulatory deltas at 10, on a 28-day half-life with bands at 25 and 55. The weights live in register data rather than in code, precisely so the second and third lines can challenge them.
What is deliberately not in this build?
Live probes into production bank systems — verifying TLS posture or key management directly — which need bank access decisions that have not been made. Also: no replacement of Line 2 or Line 3 judgment, and no new engineering. The loop composes primitives that already existed.