GRC and Data Analytics: Towards Data-Augmented Risk Governance

When GRC Meets Data Analytics

Internal audit, internal control, and risk management functions have considerably structured their practices over the past ten years. Risk maps, internal control programs, reporting to audit committees: GRC (Governance, Risk & Compliance) frameworks have laid solid foundations. The question today is not whether to challenge these foundations, but how to enrich them.

The declarative approaches that form the backbone of GRC have a structural limitation: they rely on what operational teams report, not on what transactions reveal. Self-assessment questionnaires, sample-based controls, risk assessments based on subjective knowledge of the perimeter. The result can appear green on the surface and turn red as soon as you dig deeper.

“In my previous life as an auditor, we called this the ‘watermelon’ point: a milestone validated in appearance (green), but whose content reveals undetected or unreported anomalies (red).”

— Franck-Yves Inglebert, CEO Eye2Scan

This paradox is a structural limitation of the qualitative approach — one that data analytics can precisely address.

The Limits of Traditional GRC: Why the Declarative Model Is No Longer Enough

A well-configured GRC tool provides an essential management framework: risk mapping, control plans, incident tracking, report generation. It organises governance, formalises responsibilities, and ensures reporting to senior management. This framework gives teams a common language and a structure that scales across the organisation.

But this tool is, by nature, “semi-blind” if it remains purely declarative. It relies on what stakeholders enter into forms and on risk assessments based on a subjective understanding of the perimeter. Without automated verification, the GRC tool structures thinking and oversight, but draws too little on real data.

Conversely, a data analytics solution without a GRC framework will generate alerts without necessarily linking them to the overall risk management strategy. This is precisely where the value of combining both lies. GRC provides structure and risk-based prioritisation. Data analytics provides factual evidence. Together, they enable the shift from a declarative risk assessment to a quantitative, continuous measurement.

Three limitations of the purely declarative approach:
  • Operational teams self-assess their own risk: declarative bias is structural.
  • Because the approach is time-consuming, controls are performed episodically: anomalies can persist between two audit cycles without ever being detected.
  • Risk mapping relies on the perception that managers have of their own exposure: it measures risk as it is declared, not as it manifests in transactions.

The Contribution of Data Analytics to Risk Management

Data analytics applied to ERP flows feeds the GRC with objective signals. This enables the analysis of 100% of flows (P2P, O2C, inventory, SoD) rather than simple samples.

An often underestimated contribution is the ability to link gross risk to net risk. GRC assesses risks by criticality and probability, then weights them by the assumed effectiveness of existing controls to arrive at a net risk. Data analytics tests this assumption in practice: if a control is supposed to cover a risk, continuous control results allow verification that it is actually working, and enable the net risk to be adjusted accordingly. This is the shift from a declarative assessment of net risk to an objective measurement.

The value of this approach also lies in unifying functions that often operate in silos. Internal audit, internal control, compliance, risk management, operational departments: Eye2Scan gives them a common language built around data, from which each function can work within its own framework while sharing a consistent information base.

This logic transforms the posture of teams. It is not a shift to a strictly preventive mode, but it considerably reduces detection time: where an anomaly could remain invisible for months, until the next audit mission or control campaign, continuous control surfaces it within days or weeks, as close as possible to the moment it occurred. We can therefore speak of continuous audit and automated continuous control.

“The ERP cannot be judge and jury. A reasonably savvy internal actor will always end up understanding the system’s blind spots, including the limits of segregation of duties. They can then siphon off small amounts for years without ever triggering a native alert. To guarantee genuine governance at Comex level, it is essential to have a system independent of the ERP that surfaces these inconsistencies objectively.”

Pascal Gadea, Commercial Director, CoAudit Group

Sentinelys-Screenshot-Carto_2026.04

Eye2Scan × Sentinelys: Risk-Based Management and Data-Augmented Governance

The complementarity between these two solutions rests on a clear division of roles for amplified effectiveness:

  • Sentinelys structures governance: CoAudit Group offers a true “no-code” cockpit; the solution aggregates signals to steer the organisation. It centralises risk mapping, orchestrates control campaigns, ensures rigorous tracking of recommendations, and automates reporting to management committees.
  • Eye2Scan powers the cockpit: the solution continuously executes accounting and operational controls directly on the ERP, in perfect alignment with the risk map. Every anomaly is surfaced with its full context (user, date, amount), without the auditor needing to connect to the ERP. This data then generates dynamic KRIs (Key Risk Indicators) that automatically recalibrate the risk map in Sentinelys.

The combination of both creates augmented governance: a GRC anchored in real transactions, and data analytics whose results feed directly into risk management.

A Structured Data Flow Built Around KRIs

In practice, the results produced by Eye2Scan flow into Sentinelys as KRIs (Key Risk Indicators) for each control / risk. These key risk indicators allow teams to manage their exposure in near real time, without waiting for a periodic report. A user who wants to understand a degraded KRI switches to Eye2Scan to access the transactional detail — without connecting to the ERP, without engaging an IT team.

Concrete Case: From Alert to Action

Risk management teams open Sentinelys and notice that a KRI has turned red on the procurement perimeter of the Spanish entity. They access the detail: 12 incidents flagged by Eye2Scan during P2P order validations. One click takes them into Eye2Scan to view the transactions in question; they identify a recurring pattern (orders validated and received by the same user in violation of SoD), and trigger an action plan directly from Sentinelys.

This journey delivers operational fluidity: a degraded KRI identified in Sentinelys, root cause analysed in depth in Eye2Scan, then the action plan generated and integrated into the final audit report via Sentinelys.

KRI-ENG-InventoryGAP

Audit and Internal Control: The Benefits of Data-Augmented Governance

For internal audit teams: agility and independence
  • Reduced mission preparation time and autonomy: no extraction requests or data connections needed — baseline controls have already run, significant anomalies are identified before fieldwork even begins.
  • Expanded coverage: where a classic mission relies on random samples, Eye2Scan analysis covers 100% of transactions within the audited perimeter. Audit becomes continuous rather than point-in-time.
  • Objectivity of findings: grounded in real data, findings are no longer open to interpretation and carry genuine credibility with operational teams.
  • Enriched reporting to audit committees: audit results feed directly into Sentinelys GRC dashboards, providing a consolidated view of recommendation progress at group level.
For internal control teams: compliance by design
  • Dynamic net risk calculation: continuous confrontation between the risk map and reality.
  • Decentralised remediation: through automated workflows, anomalies detected by Eye2Scan are transmitted directly to Process Owners. They justify or correct deviations autonomously, freeing control teams from time-consuming follow-up tasks.
  • “Compliance by design” culture: native and continuous control traceability radically simplifies regulatory compliance exercises (Sapin 2, SOX, AFA) by providing a robust, always up-to-date evidence file.
For finance leadership and risk management: peace of mind and ROI
  • The “Sleepwell” concept: the certainty that flows are monitored continuously and that significant incidents are identified before they become major crises.
  • Quantitative view of operational risk: the risk map is no longer a static document updated annually, but a management tool fed by quantitative, continuously updated risk indicators (KRIs).

Business Accessibility and Data Sovereignty: A Strategic Prerequisite

The Eye2Scan and Sentinelys alliance is distinguished by two fundamental pillars:

1 — Accessibility designed for risk professionals

Eye2Scan is built for audit and internal control teams, not for ERP specialists or data scientists. ERP connectivity is handled by the Eye2Scan team, controls are preconfigured and activable without development, and results are presented in an interface readable by an auditor or internal controller — not a technician.

Sentinelys takes the same approach on the GRC side: rapid onboarding, no-code configuration, and functional coverage spanning risk mapping to audit and internal control campaign management.

Both solutions share this conviction: technology must serve risk professionals, not constrain them.

2 — Data sovereignty and uncompromising security

Eye2Scan analyses particularly sensitive information extracted from the ERP: purchase prices, sales prices, inventory, production data. This is why every Eye2Scan client operates via on-premise deployment or private cloud: data never leaves the company’s perimeter.

Sentinelys relies for its SaaS component on Outscale, the sovereign cloud of Dassault Systèmes, whose infrastructure is certified and hosted in France.

Exchanges between the two platforms occur via secured API, and only aggregated data flows from Eye2Scan to Sentinelys: anomaly rates, KRIs, control statuses. Transactional detail remains within the Eye2Scan environment, inside the company’s perimeter. Access management is strictly controlled in both solutions, with rights configurable by profile, entity, and process, so that each user accesses only the data within their scope of responsibility.

An Alliance in Service of Sapin 2 Compliance

For internal audit and internal control leadership, the alliance between Eye2Scan and CoAudit Group — the publisher of Sentinelys — addresses the critical gap between the perception of risk and its transactional reality. Organisations can no longer rely solely on what their teams choose to report; they must draw on what their P2P, O2C, and inventory flows reveal on a daily basis.

Together, these solutions cover the pillars of a robust compliance framework, particularly in light of the requirements of the French Sapin 2 law. They enable the construction of an anti-corruption risk map fed by real data, ensure continuous monitoring of third-party processes, and guarantee the full traceability of alerts and action plans required by the AFA.

Whether you are starting your internal control programme or looking to augment an already structured GRC, this combination offers a concrete and pragmatically deployable path — without a complete overhaul of the existing framework. It is the shift from passive governance to data-augmented governance, in service of lasting business performance.

 

Want more fact-based, confident governance?

Contact our experts to discuss your business challenges and discover how the alliance between CoAudit Group with the Sentinelys platform and Eye2Scan can reconcile your risk map with your transactional reality.

Discover more from Sentinelys

Subscribe now to keep reading and get access to the full archive.

Continue reading