Find controls with the library filters, create your own, decide applicability, assign owners one at a time or in bulk, and move controls through their lifecycle from draft to retired.
The library holds every control your organisation operates: those that arrived with your standards, those you created or imported, and drafts the Controls Assistant prepared. Anyone with View controls can browse it. Creating, changing, assigning and retiring controls needs Manage controls. See find your way around Controls for permissions and plan limits.
A control in the library is a definition and a set of decisions about it. It starts operating once it has an owner and at least one implementation that says where, how and how often it runs; see define where and how a control operates.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
Open Controls from the module launcher, choose Controls then Library in the Quality Management sidebar, or choose Controls under Analysis in the Risk Management sidebar. The page is titled Controls.
The header offers New control, Import controls and Ask the assistant. See adopt control packs and import controls for importing, and define and review controls with AI for the assistant.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
Every filter searches the whole library, and the result is paged 50 rows at a time with Previous and Next.
Filter | What it does |
|---|---|
Search | Matches the code or name. Type part of either, such as "access". |
Owner: any | Choose a person to see their controls, or Owner: unassigned to find controls nobody owns yet. |
Standard: any | Shows the controls from one standard's packs, plus any control mapped to one of its clauses. The Pack list narrows to that standard's packs, and links to its Statement of Applicability and Framework coverage appear. |
Pack: any | Shows the controls that came from one control pack. |
Applicability: any | In scope, Not in scope or Partly applicable. |
Status: any | Draft, Active or Retired. Retired controls are hidden unless you choose Retired. |
The count beside the filters, such as "42 controls", is the total that match. Clear filters resets them.
To keep a combination you use often, choose Save this view, enter a name in Name this view (the suggestion is "My controls") and confirm. The view appears as a chip you can select later; its × removes it. Saved views are stored in your browser on this computer, so they are yours alone and do not follow you to another device.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
Column | What it shows |
|---|---|
Code | The control's code, which identifies it everywhere and never changes. |
Control | Its name, with the objective beneath. |
Applicability | In scope, Not in scope or Partly applicable. |
Owner | The owner's name, or Not assigned. |
Source | The pack it came from, or Your own. An edited badge means you changed a field the catalogue owns, so the control no longer takes catalogue updates. |
Covers | How many estate targets the control applies to. This is the denominator of its coverage. |
Satisfies | The clauses it is mapped to, shown as the standard and clause. A clause nobody here has confirmed yet is marked "not yet confirmed by anyone here". "no clauses" means none; "3 proposed" means ComplyTrain's catalogue proposes mappings you have not accepted. See map controls to requirements. |
Status | Draft, Active or Retired. |
Select a row to open the control.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
Create your own control when your organisation operates a measure that no adopted pack provides, such as a contractual commitment to a customer. Your plan must allow controls of your own and have room in its allowance.
Choose New control.
Enter the fields below.
Choose Create control.
Field | What to enter | Rules and default |
|---|---|---|
Code | A short, stable identifier, such as | Required. 2 to 100 characters, starting with a letter or digit, using only letters, digits, dot, underscore and hyphen. Must be unique in your organisation and cannot be changed later. |
Name | What people call the control. | Required, up to 300 characters. |
Objective | What the control is for, written so someone could test whether it holds. | Optional. |
When it acts | Preventive, Detective, Corrective or Directive. | Defaults to Preventive. |
How it is carried out | Manual, Automated or Hybrid. A general description; each implementation says how it is really done. | Defaults to Manual. |
What it reduces | Frequency (how often a loss event happens), Magnitude (how badly it lands) or Both. | Defaults to Frequency. It decides which part of a risk the control is credited against, so set it deliberately. |
The new control is Active, In scope and has no owner. It appears in the library with Your own as its source, and the Governance tab records version 1 as "Control created.". It counts towards your plan's included controls.
A code that already exists is refused with "A control with code "IT-AR-01" already exists". If your plan does not include controls of your own, or the allowance is full on a plan that does not bill extra controls, the message explains which and nothing is created.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control and choose Scope and handling.
Open the control and choose Scope and handling. Everything on this tab belongs to your organisation and survives every pack update.
Field | What it does |
|---|---|
Does this control apply to you? | In scope, Not in scope or Partly applicable. |
Why not, or only partly? | Appears when the control is not fully in scope, and is then required. It is reported word for word in your Statement of Applicability. |
Your overall approach | How your organisation performs the control, in prose. The steps a tester ticks off belong to each implementation. |
When a test of this control fails | Inherit from the pack, or one of the policies below. |
Policy | What a failed test produces |
|---|---|
Log only | Nothing beyond the test result. |
Open an exception | A deficiency in the register that someone must own, explain and close with a passing retest. |
Exception, then CAPA | A deficiency and a CAPA against it. |
CAPA directly | A CAPA and no register entry. |
Create an action item | A deficiency and a task on the owner's action list. |
Inherit from the pack follows the pack's setting, including if the pack later changes it. For a control you authored it uses the organisation default. An implementation can set its own policy, which then wins.
The Statement of Applicability needs a reason on every row, including controls that apply. It takes the reason from the control and carries it into each new version, so record why each control applies here as well as why others do not. See prepare, approve and sign a Statement of Applicability.
Choose Save. Saved. confirms it. Changing applicability, the reason, the approach or the failure policy records a new version on the Governance tab. If someone else saved the control while you were editing, your change is refused and the control reloads with their version; make your change again on top of it.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control and choose Ownership.
The owner is the person answerable for the control being carried out and for its periodic review.
Open the control and choose Ownership.
In Who owns this control, choose the person, or Not assigned to remove the owner.
The change saves as soon as you choose. It records a new version on the Governance tab, and the new owner receives a Control Assigned notification. The library's Owner column shows their name.
Each implementation can name its own owner. Implementations that do not inherit this one, so the owner also receives the control's generated work, except while a delegate is covering. The same tab sets who may test the control; see govern control definitions and versions.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
After adopting a standard you may have dozens of controls to assign. Select them in the library with the row checkboxes, or the header checkbox for the whole page, then choose Assign…. Assign across the selection opens: "Any field you do not set is left as it is."
Field | Choices |
|---|---|
Owner | Leave unchanged, No owner or a person. |
What happens when the control fails | Leave unchanged, Inherit from the pack or one of the five policies. |
Review every (days) | How often the control definition should be reviewed, from 1 to 3,650 days. Leave empty to keep each control's value. |
Applicability | Leave unchanged, In scope, Not in scope or Partly applicable. |
Why is it out of scope? | Appears when applicability is not In scope, and is required. Recorded in the Statement of Applicability for every selected control. |
Choose Apply. One action covers up to 500 controls. If any selected control would end up out of scope without a reason, nothing is changed and the message lists up to five of their codes.
Bulk change applied reports "12 of 12 controls updated." and lists any skipped rows: "no longer exists", or "retired — reinstate it first to change it". Each updated control records its own new version, "Changed as part of a bulk update.", and each new owner is notified. Choose Done.
Clear selection deselects everything. Accept 5 proposed accepts the catalogue's proposed mappings for the selected controls, and needs Manage Requirements; see map controls to requirements.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Choose Draft in the Status filter and open the draft.
A draft is a control that has been proposed but not yet accepted, usually by the Controls Assistant. It shows Draft in the library and counts towards your plan's included controls.
Open the draft and review the Definition tab. Change anything that is not right before you activate it; see govern control definitions and versions.
Set Scope and handling and the owner.
Use the action on the control to activate it.
The status changes to Active and a new version records the change. Nothing else about the control changes.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control; to find a retired control, choose Retired in the Status filter.
Retiring is the normal end of a control's life. Use it when your organisation stops operating a control, or when a standard update no longer carries it.
Open the control and use the action to retire it.
Enter why it is being retired. The reason is required and becomes part of the audit trail.
Confirm.
A retired control shows Retired, and the version history records "Retired:" followed by your reason. It keeps its tests, evidence, deficiencies and history. It stops:
counting towards your plan's included controls;
generating scheduled work from its implementations;
counting in framework coverage, the Controls overview and the evidence matrix;
appearing in new Statement of Applicability versions;
accepting bulk changes.
Risks linked to it still show the link, but the control no longer counts towards their aggregate effectiveness.
To bring it back, choose Retired in the Status filter, open the control and use the action to reinstate it. It returns to Active, counts towards the allowance again, and its implementations resume generating work. The history records "Reinstated from retirement.".
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control you created in error.
Delete is for a control your organisation created in error, such as a duplicate made during an import. Open the control and use the action to delete it, then confirm.
Only controls your organisation created can be deleted. A control from a pack is refused: "came from a control pack and cannot be deleted. Retire it instead".
A control that already has a recorded test cannot be deleted, because test results are permanent. Retire it instead.
Deleting removes the control permanently, together with its implementations, requirement mappings, risk and process links and version history. It cannot be undone.
Product location: /qms/controls. Choose Library under Controls in the sidebar.
Your organisation has adopted ISO/IEC 27001, and its control pack has brought in the Annex A controls with nobody assigned. The IT manager, Sam Patel, is to own the access controls, and internal audit will test them.
In the library, choose ISO/IEC 27001 in Standard and Owner: unassigned, then search for "access". The results include Access control, Access rights and Privileged access rights.
Select them and choose Assign…. Set Owner to Sam Patel, What happens when the control fails to Exception, then CAPA, and Review every (days) to 365. Choose Apply. The result reads "4 of 4 controls updated.", and Sam receives four Control Assigned notifications.
Choose Save this view and name it "IT access controls", so the IT team can return to the same list.
Open Access rights and choose Scope and handling. In Your overall approach, write: "Each quarter IT exports the user lists of the finance system, the CRM and Microsoft 365, and each system owner confirms or revokes every account. Revocations are made within five working days." Choose Save.
On Ownership, tick Whoever operates this control cannot test it, so Sam cannot record the test of a review Sam operates.
Your organisation does no outsourced development. Filter for the Outsourced development control, set Does this control apply to you? to Not in scope and Why not, or only partly? to "All software is developed by our own staff; no development is outsourced." Save.
Next, add a quarterly implementation to Access rights so the review lands in Sam's inbox on schedule; see define where and how a control operates.