AUTOMATED CONTROLS EFFICACY TESTING

Continuous Controls
Intelligence With ACET™

VALIDATE • VERIFY • ASSURE • TRACK

Your controls are only as good as the evidence behind them.

ACET™ receives control evidence, testing results, findings, and assurance data through A.D.A.M.™ — Mercury’s ingestion layer — and transforms that prepared information into a current, evidence-based view of controls efficacy.

CONTINUOUS CONTROLS INTELLIGENCE MULTI-FRAMEWORK VISIBILITY EVIDENCE-BASED ASSURANCE SOURCE DATA INGESTED THROUGH A.D.A.M.

The Controls Testing Gap
Most Programs Miss

Traditional controls testing is often periodic, labor-intensive, and disconnected from changing risk conditions. ACET receives control-relevant evidence through A.D.A.M. and brings that evidence together with control performance so assurance can become more continuous, current, and actionable.

Periodic Testing

Point-in-time assessments can become stale long before the next formal testing cycle.

Scattered Evidence

Control evidence lives across risk, audit, compliance, security, and operational systems.

Heavy Manual Effort

Teams spend significant time gathering, reconciling, documenting, and re-testing information.

Disconnected From Risk

Control performance is often reviewed separately from the risk it is intended to reduce.

The ACET™ Controls Intelligence Pipeline

1

Receive Evidence from A.D.A.M.™

ACET receives control-relevant evidence, testing results, findings, exceptions, and assurance data from A.D.A.M. A.D.A.M. handles source-data ingestion through direct integrations or decoupled file-based ingestion, so ACET does not need to connect directly to customer source applications.

Control EvidenceAssessment ResultsAudit FindingsTesting OutputsAssurance Data
2

Validate Evidence

ACET evaluates the evidence received through A.D.A.M. for completeness, relevance, and alignment to the control being assessed, while preserving exceptions and conflicting results for review.

3

Verify Control Performance

ACET evaluates control testing results and supporting evidence against expected performance to identify weakness, degradation, exceptions, gaps, and ineffective controls.

4

Assure & Track

Controls efficacy becomes visible and traceable over time, strengthening assurance and making changes in control performance easier to monitor.

5

Pass Efficacy Intelligence to Aurora™

Validated controls efficacy is passed downstream to Aurora™ as an input to Mercury’s scoring, quantification, and residual risk analysis.

What ACET™ Delivers

Continuous Controls Intelligence

A more current view of control performance rather than reliance solely on periodic testing snapshots.

Multi-Framework Visibility

Consolidated control information across regulatory, security, privacy, risk, and compliance requirements.

Defensible Evidence

Control conclusions supported by traceable evidence and testing results from the systems where the work occurs.

Reduced Operational Burden

Less repetitive evidence collection, reconciliation, preparation, and manual review across assurance teams.

Flexible Source-System Access

Through A.D.A.M., source data can enter Mercury through direct APIs or decoupled file-based ingestion using scheduled exports, reports, structured datasets, or manually provided files — without requiring ACET to connect directly to production applications.

Continuous Readiness

More current controls information for audits, assessments, regulatory reviews, executive inquiries, and assurance activities.

Controls Intelligence Across the Enterprise

Internal Audit

Strengthen continuous assurance with more current control evidence and reduced repetitive testing effort.

Risk & GRC

Incorporate current controls efficacy into risk analysis, monitoring, and residual risk determination.

Compliance & Privacy

Maintain evidence visibility across multiple frameworks, obligations, assessments, and regulatory requirements.

Security

Understand whether security controls are performing as expected and where weaknesses could materially change risk.

Control Owners

See testing results, evidence, exceptions, and performance trends associated with the controls they operate.

Executives & Boards

Gain clearer assurance that reported risk levels reflect the effectiveness of the controls intended to manage those risks.

Controls Efficacy Is One Part of the Risk Picture

ACET is not an isolated controls-testing application. A.D.A.M. is Mercury’s ingestion layer that reads raw customer source data and prepares it for downstream use. ACET receives the relevant evidence and testing information from A.D.A.M., validates and verifies controls efficacy, and passes that intelligence to Aurora for scoring and quantification.

01

A.D.A.M.™

Aggregate • Discover • Analyze • Measure

02

ACET™

Validate • Verify • Assure • Track

03

Aurora™

Normalize • Score • Quantify • Optimize

04

Executive Dashboards

Visualize • Monitor • Prioritize • Decide