A new category

ControlOps: where controls actually run.

The operating layer where control execution happens, gets proven, and produces audit-ready evidence from the work teams already do.

DevOps gave engineering teams a layer to release software safely. RevOps gave revenue teams a layer to coordinate go-to-market. ControlOps is the same idea for the controls underneath the numbers — continuous, cross-system, evidence-producing.

Why this layer has to exist

Six gaps every existing tool leaves open.

  1. 01
    Systems change independently.

    Workday, Salesforce, Xactly, ADP, and the rest each have their own update cadences, owners, and validation rules. There is no single referee.

  2. 02
    Org changes don’t reliably propagate.

    A promotion in HRIS does not always reach the comp plan, the territory map, the payroll file, and the benefits eligibility table on the same day — or in some cases, ever.

  3. 03
    Teams need evidence, not just alerts.

    A red light tells you something is wrong. An audit needs a signed record of what ran, when, against which population, with which result. Alerts decay. Evidence persists.

  4. 04
    Auditors trust records, not verbal explanations.

    Workpapers and Control Execution Records are the currency of attestation. The team that can produce signed evidence on demand finishes audits in days, not weeks.

  5. 05
    Existing systems don’t prove agreement.

    iPaaS proves the pipe ran. GRC proves a control was documented. Neither proves that two systems actually agreed at the moment the control was supposed to run.

  6. 06
    AI and automation accelerate drift, not eliminate it.

    Every new automation, AI agent, and integration is another moving part that depends on the data underneath staying consistent. When schemas change, when a vendor renames a field, when a model retrains on a different data shape, the automation runs cleanly but silently produces wrong output. ControlOps is the independent verification layer that catches it — without that layer, every AI win quietly accrues a drift debt no one is watching for.

ControlOps vs everything else

Where adjacent categories stop short.

GRC platforms (Optro, Workiva, Diligent)

Manage the framework around controls — policies, ownership, sign-off. Don’t read operational systems or produce independent evidence that two systems agreed. ControlOps feeds CERs into them.

Audit evidence repositories

Store evidence after the fact. Don’t generate it from continuous verification. ControlOps is upstream: it produces the evidence the repository stores.

Spreadsheet reconciliation

Runs on a cadence, inside one domain, ends in a findings list. ControlOps runs continuously across domains and produces signed evidence as a byproduct.

HRIS / HCM analytics (Visier, OneModel, Workday Prism)

Lives inside one system. Drift happens between systems. ControlOps is explicitly cross-system.

Integration platforms (Workato, MuleSoft, Boomi)

Confirm the pipe ran. Don’t confirm the destination accepted the change correctly. ControlOps is the independent observer above the pipes.

Workflow / case-management tools

Track who did what work. Don’t verify that the work changed the right state in every dependent system. ControlOps verifies; workflow routes the work.

For the named-artifact definitions used here (CER, ODI, IPE, RACM, etc.), see the glossary.

Introducing a new category

Control Operations. The layer that closes the loop.

DevOps gave IT a continuous, operational layer above infrastructure. RevOps gave sales a continuous, operational layer above the CRM. Control Operations does the same thing for your controls — a verification layer that never stops checking — it watches every system, executes controls as events happen, and produces audit-grade evidence as a byproduct.

There's no Control Operations practitioner role on most org charts today. There will be — and the Referee at the top of this page is what it looks like in practice.

OrgDrift is the first product built for this layer. Your existing stack has pieces of the solution — none of them close the loop.

Internal reconciliation
Manual · Your team, today
Finance · Payroll · Sales Comp · HR
What they do
Monthly and quarterly reconciliations across each domain — commission accruals, payroll-to-GL, roster-to-payroll, disbursement-to-bank. Manual investigation of discrepancies. Signed workpapers.
Why it's not enough
Each recon runs in its own silo, on its own cadence — no reviewer has all four system views at once. Cross-domain drift slips through every check, and findings still aren’t audit-grade evidence.
Integration platforms
Workato · MuleSoft · Boomi
What they do
Move data between systems. Build, schedule, and monitor pipelines.
Why it's not enough
They confirm the pipe ran, not that the destination accepted the change correctly. Clean pipes still produce silent drift.
GL & account reconciliation
Blackline · FloQast · ReconArt
What they do
Reconcile balances and totals within one ledger — sub-ledger to GL, bank to book, intercompany to consolidation. Workflow, sign-off, flux analysis.
Why it's not enough
They verify balances within one ledger. Drift lives between systems — a clean Blackline tie-out can sit on top of duplicate payroll in two countries and never see it.
GRC & audit platforms
Optro · Workiva · Diligent
What they do
Catalog risks and controls. Manage testing workflows, evidence collection, and attestation.
Why it's not enough
They manage the framework around controls — workflow, sign-off, documentation. They don't execute controls or produce independent cross-system evidence.
HCM & HRIS analytics
Visier · OneModel · Workday Prism
What they do
Analyze HR and workforce data in depth. Build dashboards, forecasts, and workforce insights.
Why it's not enough
They live inside one system. Drift happens between systems — you can’t catch a cross-system break by going deeper into one.
Big 4 advisory
Deloitte · KPMG · PwC · EY
What they do
Design your control framework. Execute annual SOX testing and issue management letters.
Why it's not enough
Testing is periodic. Drift is continuous. A quarterly sample misses eleven months of exposure — by the time it's caught, the dollars are gone.
Control Operations
OrgDriftOrgDrift
The continuous verification layer
What it does
Continuously verifies that every critical change in one system propagated correctly to every other system it should have reached. Read-only. Independent. Cross-domain, cross-country, cross-cycle. Every check produces a Control Execution Record — signed, hash-chained, linked to source.
What you get
Drift caught in hours, not quarters. An integrity score that trends like a FICO. Workpapers your external auditor can pull directly from the platform — no 45-sample pull, no supporting schedules to assemble. Faster audits. Lower audit fees. Controls that actually produce evidence instead of requiring it.
FAQ

Common questions.

What is ControlOps?+

ControlOps is the operating layer where control execution happens, gets proven, and produces audit-ready evidence from the work teams already do. It is the continuous verification layer underneath GRC and above the systems of record — analogous to how DevOps sits between application teams and infrastructure, or how RevOps sits between sales, marketing, and finance.

Why does ControlOps need to be a category?+

Because no existing category produces independent, continuous, cross-system evidence that controls actually ran correctly. GRC manages the framework, iPaaS moves data, HRIS analytics looks inside one system, audit repositories store evidence after the fact. None of them sit between the systems and prove agreement.

Is ControlOps a replacement for GRC?+

No. ControlOps is complementary. GRC is the system of record for controls themselves; ControlOps is the system of record for control execution and evidence. CERs flow from ControlOps into GRC.

Who owns ControlOps inside a company?+

Typically a partnership: internal audit and SOX define the controls and accept the evidence; RevOps, payroll, comp, and HRIS teams operate the systems being verified; controllership and finance leadership own the dollars at risk. ControlOps is the shared operating layer those teams meet on.

What is the artifact that ControlOps produces?+

The Control Execution Record (CER): a signed, timestamped, immutable record of each control run — populations, mappings, hashes, results, attestations. The intent is for CERs to drop into Big 4 workpaper templates and GRC platforms without re-documentation; the workpaper template is on the roadmap.

Run ControlOps in your own systems.