A fixed engagement

Control Proof

Ninety days to find out what your rule catches, what it costs you in false holds, and whether you could prove which rule ran.

90 daysstart to decision
1 workflownot a platform rollout
0 changesruns beside production
Fixed feequoted before it starts

You already have the rule. You do not have its cost.

Every institution can tell you what its controls are supposed to catch. Almost none can tell you how much legitimate business the same control holds, or reconstruct which version of a policy was applied to one decision two years ago. Attestation proves a control was designed. Sampling finds patterns. Neither answers a question about a specific case.

Control Proof answers both, on your data, without touching production.

What you get

Five things, and they are the same five every time.

  1. Your false-hold rate, on your own mix

    How much legitimate activity your rule holds for review. This is the number that decides whether it can be deployed, and it is almost never published by the vendor selling you the rule.

  2. Every decision bound to the rule version in force

    Decision, rule, rule version, source version, timestamp. The record a regulator or an internal auditor asks for when they want one case rather than a trend.

  3. An exception register with named reviewers

    What was held, who it went to, what they decided, and how long it sat. The operational cost of the control, measured rather than estimated.

  4. A sealed evidence pack you can check without us

    Exported and verifiable with a standalone tool that contains no EcoKure code and makes no call back to us, which is the only way a verification means anything.

  5. A go or no-go against criteria agreed before the start

    Written down in week one, so the result cannot be reinterpreted afterwards by either of us.

The method

Four stages. You can stop at the end of any of them.

  1. Weeks 1-2
    Frame

    One workflow, one rule, one owner. Your risk function sets the threshold, the window and the policy citations. We write down what would count as a failure.

    Your risk function owns the rule
  2. Weeks 3-4
    Wire

    The check runs beside your existing process, reading what it already produces. Nothing in production changes and no decision is actuated.

    Read-only, shadow mode
  3. Weeks 5-10
    Observe

    Six weeks of real traffic through the rule. Allowed, held, reported, with the exceptions routed to your named reviewer as they would be in production.

    Your data, your reviewers
  4. Weeks 11-13
    Decide

    The numbers, the evidence pack and the exception register, against the criteria set in week one. Then a go or no-go, and if it is no, you keep the findings.

    Your decision, our recommendation
What we need from you

Four things, and none of them is a project.

  • One workflow owner who can answer questions in the same week
  • The thresholds and policy citations your risk function already uses
  • Read access to a representative sample, or a synthetic set that matches its shape
  • A named reviewer for exceptions
Before this

Two stages that cost nothing.

Clone an open-source gate and run it on your own machine. Then a scoping conversation to agree the workflow and what would count as a failure. Only after both do we quote Control Proof.

Start with the demo, not the deck.

Thirty seconds on one worked example will tell you more about whether this applies to you than any document we could send.

What Control Proof is not. It is not a compliance certification, a legal opinion or a regulatory approval, and it does not make a suspicion determination or file anything. It does not replace transaction monitoring, model validation or your existing controls, and nothing it produces is advice. It changes nothing in production: every decision it makes is observed rather than actuated. EcoKure holds no AUSTRAC or APRA approval. The result belongs to you whichever way it goes, including when it says the rule is not deployable.

Next · See it work Eco Control Tower