Skip to content

Nextera Guard

Internal Control over Financial Reporting, from the control library through to continuous monitoring.

Nextera Guard turns ICoFR from spreadsheet work into a living system — a central control library, structured assessment, evidence collection, remediation tracking, and continuous monitoring.

  • Internal control (ICoFR) teams accountable for the control framework
  • Risk and compliance functions that use it and challenge it
  • Finance leadership who have to sign a statement that the controls are working

ICoFR fails in predictable ways, and almost none of them are conceptual. The control library lives in a spreadsheet that three people each hold their own copy of. Evidence is an email attachment nobody can find at year-end close. A deficiency recorded in March is found again in November. Testing only gets done in the last two weeks of the cycle because nobody was watching coverage.

Guard treats each of these as a systems problem:

  • A control library that really is the only control library. Every control over financial reporting sits in one place, mapped to the risks and processes it covers — so “how many controls do we have over revenue?” has a single answer.
  • Structured assessment. Judge design effectiveness and operating effectiveness together, against the risk each control addresses.
  • Evidence attached to the control and its period. Not to an email inbox.
  • Testing planned across the cycle. The results feed into the assessment rather than sitting beside it.
  • Remediation with an owner and a date. Deficiencies are recorded and tracked to closure.
  • Continuous monitoring. Watch the key controls throughout the period, not only at the end of it, so problems surface while there is still time to fix them.

For the framework underneath all of this — the COSO components, design versus operating effectiveness, deficiency severity levels, and the three lines model — read Internal control concepts.

Results Nextera publishes for Guard, as customer outcomes rather than guarantees:

  • 1 central control library
  • Live control monitoring
  • Complete audit trail

The two sit next to each other and are often confused. Guard is management running its own controls (first line and second line). Trace is internal audit independently reviewing whether those controls work (third line). Both can look at the same control; only one owns it. See the three lines.

Nextera Guard is a hosted web application, normally at guard.nextera.id.