Monitoring & absence testing
Monitoring & testing is the second line's recurring testing program. You sample transactions, work a regulatory checklist, document exceptions with root cause, and route an examiner-proof workpaper to an independent reviewer for sign-off. Absence testing is its mirror image. It proves that things which should not have happened did not happen. This article covers both.
Activities, reviews and workpapers
Three words are used precisely across this area:
- An activity is the recurring test. It has an area, the regulation it covers, a risk rating, and a cadence.
- A review is one execution of that activity for one period.
- The workpaper is the documented evidence that review produced.
What is due and what is overdue is derived from the cadence, so the program tells you what is late rather than waiting for you to notice.
Running a review
Choose Start review on an activity, optionally starting from a checklist template. The template is snapshotted at that moment, so a later edit to the template cannot change what you actually tested.
- Set scope, population and sample method. Sample method is judgmental, random, statistical, or full population, and the method is recorded with its rationale. An examiner will ask how you chose.
- Add samples to the review, one masked item reference per line.
- Grade the result matrix. Every checklist step is graded against every sample as pass, fail, or not applicable. The matrix is the workpaper's core.
- Log an exception on a failed cell. High-severity exceptions require a root cause. An exception can be promoted to a finding in the shared Findings tracker.
- Submit for sign-off. An independent reviewer signs the workpaper through the approvals queue, with a decision of sign off, request changes, or reject.
- Export the workpaper as a PDF for your files or an examination.
Workpaper states run in progress, pending approval, signed off, and changes requested.
An exception promoted to a finding names that finding on the workpaper. The review's Links panel shows the records linked to it, such as controls, findings and citations, so the review sits in the same crosswalk as the rest of your program.
The submit gate
Submission is complete by construction. If anything is ungraded, unexplained or missing, the platform blocks the submission and names exactly what to resolve. It does not accept a partial workpaper and flag it later. The only thing that discharges an ungraded failing cell is an exception bound to that specific cell.
This is stricter than most spreadsheet-based monitoring programs, and deliberately so. A signed workpaper in Zovos means every step was reached and every failure was either explained or escalated.
Absence testing
Some obligations are prohibitions. The corpus is full of clauses that say a bank shall not do something, and a normal control test cannot evidence them. There is no artifact produced by not doing a thing.
Absence testing turns every prohibition into a deterministic search over your own records: complaints, findings, fair-lending reviews, document text, marketing review materials and control tests. No language model is involved. This is a search with a written protocol, because a probabilistic answer to "did this ever happen?" is worth nothing to an examiner.
The screen has two tabs. Coverage map shows which prohibitions can be tested at all, graded direct, signal only, or not tested. Prohibitions we cannot yet test are disclosed rather than hidden, because an honest map with holes in it is more useful than a complete-looking one.
Runs holds the executions. Each run returns one of four verdicts:
- Exceptions found. Records matched the prohibition and need disposition.
- Nothing found. The search ran over a sufficient population and matched nothing.
- Insufficient population. There were not enough records to say anything.
- Not testable. No data source can currently evidence this clause.
Every run records its search protocol in plain language: which population was searched, how many records it held, the query used, and how many matched. It then seals a manifest into the proof ledger, so the run can be verified later. Saying "nothing happened" is different from saying "we searched this population, this many records, this way, and found nothing". Only the second is negative assurance.
Dispositioning an exception
A matched record is an exception pending disposition rather than a violation. Each one requires a rationale. It then gets a disposition of false positive, explained, or confirmed, or it is promoted to a finding. Dispositioning is a two-step action rather than a single click, because recording a false positive should not be something you do by accident.
Notes and limits
Monitoring samples come from your own systems. Zovos does not connect to core banking or loan origination systems, so you enter each sample as a masked item reference, one per line, rather than pulling it through a live query.
Absence testing coverage grows as we extend what each prohibition can be searched against. The coverage map is the honest statement of where that stands in your workspace today. If a clause that matters to your program reads not tested, tell us and it goes on the list.