Dear Experts,
I need you expert opinion on the Testing of Design for a control.
I am in midst of an GRC Process control 10 implementation. I have a question for having multiple test plan for a control (i.e. one for test of design and one of test of effectiveness)
For a SOX control, testing is performed in two parts as follows:
- TOD: Test of Design (In here we assess the design of the control)
- TOE: Test of Effectiveness (In here we assess the effectiveness of the control)
So based on the above underlying testing methodology for a control, we require to have two test plans for one controls, since the testing steps for TOD and TOE are different.
I am aware of the control design assessment testing in the planner. However, in scheduling a control design assessment a survey template is required.
I am not sure how it would take care of the TOD for a control, as in TOD we need to perform some testing based on the manual test attached to a control.
What I require is to schedule TOD for testing a control similarly to scheduling for testing effectiveness.
Please advice on how to perform test of design of a control.
Look forward to hear from you.
Regards,
Sahil.