New: AI-Powered Regulatory Change Monitor now live. Learn More →
Back to Platform
SL SecondLine

Atheris Control Solution

Every control tested.
Every exception closed.

Nothing lost in a spreadsheet.

SecondLine is the control testing and exception management platform for banks, mortgage banks, microfinance banks, and fintechs. Define your controls once, test them on a schedule, and chase every exception to verified closure.

The Problem

Control testing is happening. Proving it is the hard part.

Most control functions already do the work. The problem is what happens around it.

Results live on one laptop

Test results sit in a workbook on one officer's laptop — invisible to everyone else who needs them.

Exceptions vanish in email

Exceptions get raised in an email thread and quietly forgotten. The owner says it's resolved, so it comes off the tracker — with no evidence, no verification, and no record of who decided.

The examiner's question

Then the examiner asks how many high-risk exceptions are still open and how old they are — and nobody can answer without three days of reconciliation.

SecondLine replaces that with one system of record
Core Capabilities

Everything the control function runs on

From the control register to the board pack — one connected workflow, with an audit trail behind every step.

Control Library

Define once, version forever, approve before it goes live

Build a central register of every control in the institution — segregation of duties, access management, authorisation limits, reconciliations, dual control, cut-off procedures. Start from a pre-loaded library of standard banking controls or define your own. Every control carries an owner, a process, a unit, and a testing frequency. Every change is versioned, and no control goes live without maker–checker approval.

Risk-to-Control Mapping

See what's covered, and what isn't

Map controls to the risks they mitigate, straight from your risk and control self-assessment. See inherent risk before controls, residual risk after, and — most usefully — the gaps: risks carrying no control at all, and controls mapped to nothing.

Checklist-Driven Testing

Structure, not memory

Testers work a structured checklist, not their memory. Each check item is marked Pass, Fail, or Not Applicable, with a mandatory comment and evidence attached. Sampling basis is captured in full: population, sample size, method, items selected. Tests generate automatically on each control's frequency, so nothing falls off the calendar.

Design & Operating Effectiveness Ratings

Design and operating, rated separately

Rate every control on both dimensions that matter: is it designed well enough to work, and did it actually operate throughout the period? Ratings require documented rationale, go through control function approval, trend over time, and feed straight back into your residual risk position.

The rule that changes everything

An Exception Tracker That Can't Be Self-Closed

Owners remediate. Only control closes.

Every failed check raises an exception automatically — no re-keying. Each one carries severity, owner, root cause, remediation plan, and a target date it's aged against. A control owner can mark an item remediated. Only the control function can close it, and only after recording how the remediation was verified and by whom.

That single rule is what turns a tracker into an assurance record.

1 Failed check raises the exception automatically
2 Owner remediates and marks it remediated
3 Control function verifies — then, and only then, it closes

Compensating Controls

Know what's holding the line, and until when

When a control fails and remediation will take time, register the compensating control that's holding the line. Capture whether it's temporary or permanent, what exposure it doesn't cover, and when it expires. Temporary controls expire on schedule and re-escalate the underlying exception if the primary control still isn't fixed.

Spot Checks

Unscheduled reviews, formal reports, your format

Run an unscheduled review of a branch, a process, or a control whenever you need to — announced or surprise. Capture findings inline with severity, evidence, and management response, and issue a formal report in your own house format. Findings flow into the same exception tracker as everything else.

Escalation That Creates Accountability

Overdue items find their way upstairs

Set escalation rules by severity. When an exception goes unassigned, passes its due date, or sits without activity, it escalates automatically — control owner, then line manager, then control function head, then executive management. Every escalation is logged. Owners get a weekly digest of what's open on their desk.

Reporting & Dashboard

Open, serious, owned, overdue

A dashboard that answers the four questions you're actually asked: what's open, how serious, who owns it, and how overdue. Exceptions by severity, ageing buckets, testing completion rate, effectiveness distribution — every tile drilling through to the underlying records. Export to Excel or PDF, or generate a board committee pack in one click.

Evidence Handling Built for NDPA

Retention, legal hold, dual-approval disposal

Testing evidence often contains customer data. SecondLine treats that as a first-class problem. Uploaders declare whether an item holds personal data, retention periods run per evidence class, legal hold suspends disposal for anything under investigation, deletion requires dual approval, and every view and download is logged.

Works with ThirdLine

Define a control once. Let audit rely on it.

SecondLine talks to ThirdLine Internal Audit over API. When your control officers define and approve a control, it flows straight into the audit universe — and test results, effectiveness ratings, and open exceptions flow with it. Controls can originate on either side, and you decide at setup which system is master.

SecondLine
Second line of defence
Control testing & exceptions
One register
over API
ThirdLine
Third line of defence
Internal audit

The result: internal audit places reliance on second-line testing already performed instead of repeating it, and the second and third lines stop arguing about whose control register is correct.

Where NexusRisk IRM is deployed, the risk register comes across too — so control effectiveness updates residual risk automatically.

Who It's For

One system, four audiences

Internal Control & Compliance

Run the testing calendar, verify closure, own the register.

Risk Management

See residual risk move as control effectiveness changes.

Internal Audit

Rely on second-line testing instead of duplicating it.

Executive Management & Board

One view of what's unresolved, how serious, and how old.

Built for the Nigerian and wider African financial services market — commercial banks, mortgage banks, microfinance banks, payment service providers, and fintechs.

Why Atheris

Three lines of defence. One set of facts.

Atheris builds governance, risk, and compliance software for African financial institutions — ThirdLine for internal audit, NexusRisk IRM for enterprise risk, and SecondLine for control testing. The products share a data model and speak to each other, so the three lines of defence work from the same facts.

We build for the environment you actually operate in: CBN risk-based supervision, NDPA obligations on customer data, IIA standards, and the reality of a branch network. Deployment is available hosted or on-premises, with in-country data residency where you require it.

SL
SecondLine
Control testing & exception management — the second line
TL
ThirdLine
Intelligent internal audit — the third line
NR
NexusRisk IRM
Enterprise risk management — the risk register of record
SL SecondLine

See it against your own control register.

Bring three of your controls to a demo and we'll set them up live — the library entry, the test checklist, the exception, the escalation path, and the report your board would see.

We use cookies to improve your experience. By continuing, you agree to our Privacy Policy. Data is stored in Nigeria per NDPA 2023.