Atheris Control Solution
Every control tested.
Every exception closed.
Nothing lost in a spreadsheet.
SecondLine is the control testing and exception management platform for banks, mortgage banks, microfinance banks, and fintechs. Define your controls once, test them on a schedule, and chase every exception to verified closure.
Control testing is happening. Proving it is the hard part.
Most control functions already do the work. The problem is what happens around it.
Results live on one laptop
Test results sit in a workbook on one officer's laptop — invisible to everyone else who needs them.
Exceptions vanish in email
Exceptions get raised in an email thread and quietly forgotten. The owner says it's resolved, so it comes off the tracker — with no evidence, no verification, and no record of who decided.
The examiner's question
Then the examiner asks how many high-risk exceptions are still open and how old they are — and nobody can answer without three days of reconciliation.
Everything the control function runs on
From the control register to the board pack — one connected workflow, with an audit trail behind every step.
Control Library
Define once, version forever, approve before it goes live
Build a central register of every control in the institution — segregation of duties, access management, authorisation limits, reconciliations, dual control, cut-off procedures. Start from a pre-loaded library of standard banking controls or define your own. Every control carries an owner, a process, a unit, and a testing frequency. Every change is versioned, and no control goes live without maker–checker approval.
Risk-to-Control Mapping
See what's covered, and what isn't
Map controls to the risks they mitigate, straight from your risk and control self-assessment. See inherent risk before controls, residual risk after, and — most usefully — the gaps: risks carrying no control at all, and controls mapped to nothing.
Checklist-Driven Testing
Structure, not memory
Testers work a structured checklist, not their memory. Each check item is marked Pass, Fail, or Not Applicable, with a mandatory comment and evidence attached. Sampling basis is captured in full: population, sample size, method, items selected. Tests generate automatically on each control's frequency, so nothing falls off the calendar.
Design & Operating Effectiveness Ratings
Design and operating, rated separately
Rate every control on both dimensions that matter: is it designed well enough to work, and did it actually operate throughout the period? Ratings require documented rationale, go through control function approval, trend over time, and feed straight back into your residual risk position.
An Exception Tracker That Can't Be Self-Closed
Owners remediate. Only control closes.
Every failed check raises an exception automatically — no re-keying. Each one carries severity, owner, root cause, remediation plan, and a target date it's aged against. A control owner can mark an item remediated. Only the control function can close it, and only after recording how the remediation was verified and by whom.
That single rule is what turns a tracker into an assurance record.
Compensating Controls
Know what's holding the line, and until when
When a control fails and remediation will take time, register the compensating control that's holding the line. Capture whether it's temporary or permanent, what exposure it doesn't cover, and when it expires. Temporary controls expire on schedule and re-escalate the underlying exception if the primary control still isn't fixed.
Spot Checks
Unscheduled reviews, formal reports, your format
Run an unscheduled review of a branch, a process, or a control whenever you need to — announced or surprise. Capture findings inline with severity, evidence, and management response, and issue a formal report in your own house format. Findings flow into the same exception tracker as everything else.
Escalation That Creates Accountability
Overdue items find their way upstairs
Set escalation rules by severity. When an exception goes unassigned, passes its due date, or sits without activity, it escalates automatically — control owner, then line manager, then control function head, then executive management. Every escalation is logged. Owners get a weekly digest of what's open on their desk.
Reporting & Dashboard
Open, serious, owned, overdue
A dashboard that answers the four questions you're actually asked: what's open, how serious, who owns it, and how overdue. Exceptions by severity, ageing buckets, testing completion rate, effectiveness distribution — every tile drilling through to the underlying records. Export to Excel or PDF, or generate a board committee pack in one click.
Evidence Handling Built for NDPA
Retention, legal hold, dual-approval disposal
Testing evidence often contains customer data. SecondLine treats that as a first-class problem. Uploaders declare whether an item holds personal data, retention periods run per evidence class, legal hold suspends disposal for anything under investigation, deletion requires dual approval, and every view and download is logged.
Define a control once. Let audit rely on it.
SecondLine talks to ThirdLine Internal Audit over API. When your control officers define and approve a control, it flows straight into the audit universe — and test results, effectiveness ratings, and open exceptions flow with it. Controls can originate on either side, and you decide at setup which system is master.
Control testing & exceptions
over API
Internal audit
The result: internal audit places reliance on second-line testing already performed instead of repeating it, and the second and third lines stop arguing about whose control register is correct.
Where NexusRisk IRM is deployed, the risk register comes across too — so control effectiveness updates residual risk automatically.
One system, four audiences
Internal Control & Compliance
Run the testing calendar, verify closure, own the register.
Risk Management
See residual risk move as control effectiveness changes.
Internal Audit
Rely on second-line testing instead of duplicating it.
Executive Management & Board
One view of what's unresolved, how serious, and how old.
Built for the Nigerian and wider African financial services market — commercial banks, mortgage banks, microfinance banks, payment service providers, and fintechs.
Three lines of defence. One set of facts.
Atheris builds governance, risk, and compliance software for African financial institutions — ThirdLine for internal audit, NexusRisk IRM for enterprise risk, and SecondLine for control testing. The products share a data model and speak to each other, so the three lines of defence work from the same facts.
We build for the environment you actually operate in: CBN risk-based supervision, NDPA obligations on customer data, IIA standards, and the reality of a branch network. Deployment is available hosted or on-premises, with in-country data residency where you require it.
Explore Other Modules
Audit Management
From risk-based audit planning to CBN examination-ready reports — automates every step of the internal audit lifecycle.
Enterprise Risk Management
AI-powered RCSA, Monte Carlo simulation, and real-time dashboards aligned to CBN ORMS guidelines.
Compliance Management
Automated compliance tracking and gap analysis for CBN, BOFIA, NDPA, and AML/CFT.
See it against your own control register.
Bring three of your controls to a demo and we'll set them up live — the library entry, the test checklist, the exception, the escalation path, and the report your board would see.