Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
Most risk platforms make you run two programs: one for your third parties and one for yourself, in different tools, with different evidence, different findings and different reporting. Coverbase runs both on the same objects. The third-party half is what Coverbase is best known for. This page is about the other half: evaluating the controls inside the applications you run, on the same control model, feeding the same findings, workflows, dashboards and audit trail.
Internal control monitoring is delivered by Coverbase Inspect and is enabled per organization. If you do not see Inspect in your navigation, ask your Coverbase team to switch it on.

Evidence read from the admin console

Traditional compliance evidence collection is a screenshot request. Someone is asked whether MFA is enforced, they open the admin console, they screenshot it, they paste it into a ticket, and a quarter later nobody knows whether it is still true. Inspect signs in to the application tenant with read-only credentials and reads the answer off the live admin console itself, then records what it saw with chain-of-custody metadata: the screenshot, the source URL, the timestamp, and the request context.

Read-only by construction

The inspection identity holds a read-only role inside each target application. Authentication and authorization are separate concerns: your identity provider authenticates the inspection identity, and the target application’s own read-only role is what bounds it.

Absent evidence is reported

An observation that could not be obtained still exists and still says why: unsupported, authentication required, forbidden, inconclusive, or failed. An application that does not sell a capability is not marked down for lacking it.

Per-control isolation

Each control gets its own run, so one control failing to collect evidence never stops the rest of the set.

Judgment is separate from collection

Explore establishes whether the evidence can be collected at all. Evaluate adjudicates it against the control expectation and your scale. Progress and outcome stay separate facts.

362 internal controls, ready to run

The Internal Controls Library ships 21 templates spanning 362 controls, so a program does not start from a blank control set. Each control states an expectation carrying its own threshold, names the admin surface that answers it plus the alternate labels different vendors use for the same screen, and defines what counts as incomplete. Fork a template and it becomes your control set, fully editable, exactly like a vendor framework.

Drift between runs

Point-in-time evidence decays the moment an administrator changes a setting. Inspect’s Drift mode compares a run against a compatible earlier one and reports what moved.
  • Outcome is exact, changed, or an explicit reason it could not be compared, never a silent pass.
  • Materiality is judged on a change: material, immaterial, or inconclusive, with a summary of what actually differs. A renamed label is not the same event as a disabled control.
  • Re-run on a cadence you choose, so “is MFA still enforced on the finance system” is a question your evidence answers this week rather than last audit.
Drift results are findings like any other: assigned to an owner, tracked to closure, escalated by workflow, and visible in the same dashboards as third-party findings.

One risk model, both sides

This is the part that matters for an enterprise risk view. Internal and third-party risk are not parallel systems in Coverbase; they are the same system pointed at two populations. The practical consequence: a single dashboard can show that your own privileged-access control is weak and that three critical vendors have the same gap, scored on the same scale, in the same risk domain. Answering that across two separate systems normally means exporting both into a spreadsheet.
Start with the applications that already carry your regulated data. Inspect the identity provider, the CRM, the HRIS and the finance system against the Identity & Authentication Baseline and Privileged & Administrative Access sets. Those four applications and two control sets usually surface more than the first year of a manual internal control program does.

Compliance evidence automation

Where an internal audit or a compliance program needs evidence on a schedule rather than a request:
1

Define the control set once

Fork the internal templates that match your framework, edit expectations to your thresholds, and attach them to the applications in scope.
2

Let Inspect collect

Evidence is gathered from the live console, with the screenshot, source and timestamp attached to each observation. Nobody is asked for a screenshot.
3

Adjudicate and route the exceptions

Evaluate produces the judgment against your scale. Anything that fails or is inconclusive becomes a finding with an owner, a due date and a workflow behind it.
4

Re-run and watch for drift

Subsequent runs compare against the baseline. A material change is a new finding; an immaterial one is noise that does not reach anyone’s queue.
5

Export the file

The same evidence packaging that produces a third-party due-diligence file produces the internal control evidence package, with the audit trail behind it.

Agentic Inspect

The inspection engine itself, and the vendor-facing half of it.

Control Set library

Every internal and vendor control set, with counts and sources.

Findings Manager

The shared findings and remediation surface.

Regulatory alignment

How both halves map to banking supervisory expectations.