Compliance

Control Testing Frequency Planner

Derive a testing frequency for each control from its risk and operating cadence, allocate the sample across the period, and produce a dated test calendar for the year.

Last reviewed by the Radiatus Cloud team

The plan appears here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

Testing frequency should follow the control, not the calendar

Most programmes test everything annually because the audit is annual. That allocates the same effort to a control that runs once a year and to one that runs a thousand times a day, and it means a failure in a high-frequency control can persist for eleven months before anyone looks. Deriving the frequency from the control's own risk and cadence produces a schedule where the effort lands where a failure would matter, which is the only defensible basis for the allocation.

A sample drawn from one month covers one month

Statistical sampling assumes the sample is drawn from the whole population under test. Pulling all forty items from December and concluding something about the year is a common and serious error: it supports a conclusion about December. Spreading the sample across the testing periods costs nothing extra and is the difference between a conclusion that holds and one that does not, which is why this planner allocates the sample across periods rather than reporting a single number.

Continuous controls need continuous evidence

An automated control that runs on every transaction cannot meaningfully be tested by sampling twenty-five transactions once a year. Either the control's own logging is the evidence, in which case the test is of the logging, or the control is tested by reperformance against a population, which is a different exercise. Treating an automated control like a manual one produces a test that passes while telling you nothing.

Related tools

Frequently Asked Questions

How is the frequency derived?

From the control risk and how often the control operates. A high-risk control operating daily is tested quarterly or more often; a low-risk annual control is tested once. The point is that effort lands where a failure would matter.

Why spread the sample across periods?

Because a sample drawn entirely from one month supports a conclusion about that month. Spreading it costs nothing and is the difference between a conclusion that holds and one that does not.

How should automated controls be tested?

Not by sampling a handful of transactions annually. Either the control’s own logging is the evidence, in which case you are testing the logging, or you reperform against a population. Treating an automated control like a manual one produces a test that passes while telling you nothing.

Does more frequent testing mean a larger total sample?

Not necessarily. The total is driven by the conclusion you need to reach; frequency decides how that total is distributed and how quickly a failure would be found.

Is this an audit standard?

No. It applies a transparent rule you can see and adjust. Your methodology or your auditor may require something different, and where they do, theirs governs.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your controls with their risk and operating frequency.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.