Skip to main content

Implement Level 2 control in Tenacy

Learn how the recurring task approval mechanism natively provides Level 2 control in Tenacy, and how to go further if needed.

In highly regulated environments, particularly in banking, rigorous oversight of internal controls is essential. Tenacy natively includes an approval mechanism that is, on its own, a genuine Level 2 control: full traceability, an independent reviewer, and a direct impact on your monitoring indicators.

What is a Level 2 control in Tenacy?

A Level 2 control means having someone other than the person who performed a control (Level 1) verify that it was properly executed and documented. This is a core independence principle in internal audit and regulatory compliance.

In Tenacy, this principle is built directly into how control recurring tasks (RTs) work, through the approval mechanism. You don't need to build this control from scratch: you just need to activate and configure it correctly.

The approval mechanism: your native Level 2 control

When a control recurring task is configured with an approver, submitting it automatically triggers an independent validation flow:

  • The team member responsible submits their completion (Completed OK or Completed KO).

  • The submission moves to Pending approval status and can no longer be edited by the submitter.

  • The approver, designated in advance and distinct from the person who carried out the task, approves or rejects the submission.

  • A rejected submission must be resubmitted by the original submitter to return to pending approval: the validation flow is repeated until it is actually approved.

  • Each decision (approval or rejection) can include a comment, which is kept in the task's activity feed.

  • The date and name of the approver remain visible on every occurrence of the task, providing directly usable audit evidence.

⚠️ Only approved submissions are counted as "Done" when calculating your completion rate. A submission that is pending approval or has been rejected is not counted, so your score accurately reflects the actual state of your validated controls.

Going further: formalizing a dedicated second level

The approval mechanism alone is sufficient to ensure the independence of Level 2 oversight. However, some organizations—particularly in the banking sector—wish to make it more visible and integral to their oversight plan. In this case, you can create a dedicated recurring task whose sole purpose is to explicitly represent this second level and to serve as a reminder to approve the Level 1 task.

  • Create a new recurring task with a name that clearly identifies its supervisory role (e.g., "L2 Review – Access Control").

  • Assign the Level 1 approver as the responsible of this recurring task.

  • Offset its start date relative to the Level 1 recurring task, to allow time for the realization.

💡 This second recurring task is an organizational choice, not a technical requirement: it adds to the Level 2 control already provided by approval, to further formalize governance in the most demanding contexts.

Best practices

  • Always assign an approver distinct from the person carrying out the task on your sensitive control tasks: this is what activates Level 2 control.

  • Use the approval or rejection comment to document your reasoning; it remains available in the activity feed in case of an audit.

  • If you formalize a dedicated second level, name it clearly so it's identifiable in your dashboards.


Frequently asked questions

Does a rejected task count toward my completion rate?
No. Until it's approved, it is not counted as "Done" in your scores.

Can I see who approved or rejected a task, and when?
Yes, the date and name of the approver are visible on every occurrence of the recurring task.

Is the dedicated second level mandatory?
No. The approval mechanism already constitutes a full Level 2 control on its own. The dedicated recurring task is an option for organizations that wish to make this level 2 control more visible with an even more formalized governance.

Did this answer your question?