Help center

Help center

All collectionsControlsControl libraryBuild and maintain your control library

Build and maintain your control library

Find controls with the library filters, create your own, decide applicability, assign owners one at a time or in bulk, and move controls through their lifecycle from draft to retired.

Find controls with the library filters, create your own, decide applicability, assign owners one at a time or in bulk, and move controls through their lifecycle from draft to retired.

The library holds every control your organisation operates: those that arrived with your standards, those you created or imported, and drafts the Controls Assistant prepared. Anyone with View controls can browse it. Creating, changing, assigning and retiring controls needs Manage controls. See find your way around Controls for permissions and plan limits.

A control in the library is a definition and a set of decisions about it. It starts operating once it has an owner and at least one implementation that says where, how and how often it runs; see define where and how a control operates.

Open the library

Product location: /qms/controls. Choose Library under Controls in the sidebar.

Open Controls from the module launcher, choose Controls then Library in the Quality Management sidebar, or choose Controls under Analysis in the Risk Management sidebar. The page is titled Controls.

The header offers New control, Import controls and Ask the assistant. See adopt control packs and import controls for importing, and define and review controls with AI for the assistant.

Find controls

Product location: /qms/controls. Choose Library under Controls in the sidebar.

Every filter searches the whole library, and the result is paged 50 rows at a time with Previous and Next.

Filter

What it does

Search

Matches the code or name. Type part of either, such as "access".

Owner: any

Choose a person to see their controls, or Owner: unassigned to find controls nobody owns yet.

Standard: any

Shows the controls from one standard's packs, plus any control mapped to one of its clauses. The Pack list narrows to that standard's packs, and links to its Statement of Applicability and Framework coverage appear.

Pack: any

Shows the controls that came from one control pack.

Applicability: any

In scope, Not in scope or Partly applicable.

Status: any

Draft, Active or Retired. Retired controls are hidden unless you choose Retired.

The count beside the filters, such as "42 controls", is the total that match. Clear filters resets them.

To keep a combination you use often, choose Save this view, enter a name in Name this view (the suggestion is "My controls") and confirm. The view appears as a chip you can select later; its × removes it. Saved views are stored in your browser on this computer, so they are yours alone and do not follow you to another device.

Read the library table

Product location: /qms/controls. Choose Library under Controls in the sidebar.

Column

What it shows

Code

The control's code, which identifies it everywhere and never changes.

Control

Its name, with the objective beneath.

Applicability

In scope, Not in scope or Partly applicable.

Owner

The owner's name, or Not assigned.

Source

The pack it came from, or Your own. An edited badge means you changed a field the catalogue owns, so the control no longer takes catalogue updates.

Covers

How many estate targets the control applies to. This is the denominator of its coverage.

Satisfies

The clauses it is mapped to, shown as the standard and clause. A clause nobody here has confirmed yet is marked "not yet confirmed by anyone here". "no clauses" means none; "3 proposed" means ComplyTrain's catalogue proposes mappings you have not accepted. See map controls to requirements.

Status

Draft, Active or Retired.

Select a row to open the control.

Create a control

Product location: /qms/controls. Choose Library under Controls in the sidebar.

Create your own control when your organisation operates a measure that no adopted pack provides, such as a contractual commitment to a customer. Your plan must allow controls of your own and have room in its allowance.

  1. Choose New control.

  2. Enter the fields below.

  3. Choose Create control.

Field

What to enter

Rules and default

Code

A short, stable identifier, such as IT-AR-01.

Required. 2 to 100 characters, starting with a letter or digit, using only letters, digits, dot, underscore and hyphen. Must be unique in your organisation and cannot be changed later.

Name

What people call the control.

Required, up to 300 characters.

Objective

What the control is for, written so someone could test whether it holds.

Optional.

When it acts

Preventive, Detective, Corrective or Directive.

Defaults to Preventive.

How it is carried out

Manual, Automated or Hybrid. A general description; each implementation says how it is really done.

Defaults to Manual.

What it reduces

Frequency (how often a loss event happens), Magnitude (how badly it lands) or Both.

Defaults to Frequency. It decides which part of a risk the control is credited against, so set it deliberately.

The new control is Active, In scope and has no owner. It appears in the library with Your own as its source, and the Governance tab records version 1 as "Control created.". It counts towards your plan's included controls.

A code that already exists is refused with "A control with code "IT-AR-01" already exists". If your plan does not include controls of your own, or the allowance is full on a plan that does not bill extra controls, the message explains which and nothing is created.

Decide scope and handling

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control and choose Scope and handling.

Open the control and choose Scope and handling. Everything on this tab belongs to your organisation and survives every pack update.

Field

What it does

Does this control apply to you?

In scope, Not in scope or Partly applicable.

Why not, or only partly?

Appears when the control is not fully in scope, and is then required. It is reported word for word in your Statement of Applicability.

Your overall approach

How your organisation performs the control, in prose. The steps a tester ticks off belong to each implementation.

When a test of this control fails

Inherit from the pack, or one of the policies below.

Policy

What a failed test produces

Log only

Nothing beyond the test result.

Open an exception

A deficiency in the register that someone must own, explain and close with a passing retest.

Exception, then CAPA

A deficiency and a CAPA against it.

CAPA directly

A CAPA and no register entry.

Create an action item

A deficiency and a task on the owner's action list.

Inherit from the pack follows the pack's setting, including if the pack later changes it. For a control you authored it uses the organisation default. An implementation can set its own policy, which then wins.

The Statement of Applicability needs a reason on every row, including controls that apply. It takes the reason from the control and carries it into each new version, so record why each control applies here as well as why others do not. See prepare, approve and sign a Statement of Applicability.

Choose Save. Saved. confirms it. Changing applicability, the reason, the approach or the failure policy records a new version on the Governance tab. If someone else saved the control while you were editing, your change is refused and the control reloads with their version; make your change again on top of it.

Assign an owner

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control and choose Ownership.

The owner is the person answerable for the control being carried out and for its periodic review.

  1. Open the control and choose Ownership.

  2. In Who owns this control, choose the person, or Not assigned to remove the owner.

The change saves as soon as you choose. It records a new version on the Governance tab, and the new owner receives a Control Assigned notification. The library's Owner column shows their name.

Each implementation can name its own owner. Implementations that do not inherit this one, so the owner also receives the control's generated work, except while a delegate is covering. The same tab sets who may test the control; see govern control definitions and versions.

Assign in bulk

Product location: /qms/controls. Choose Library under Controls in the sidebar.

After adopting a standard you may have dozens of controls to assign. Select them in the library with the row checkboxes, or the header checkbox for the whole page, then choose Assign…. Assign across the selection opens: "Any field you do not set is left as it is."

Field

Choices

Owner

Leave unchanged, No owner or a person.

What happens when the control fails

Leave unchanged, Inherit from the pack or one of the five policies.

Review every (days)

How often the control definition should be reviewed, from 1 to 3,650 days. Leave empty to keep each control's value.

Applicability

Leave unchanged, In scope, Not in scope or Partly applicable.

Why is it out of scope?

Appears when applicability is not In scope, and is required. Recorded in the Statement of Applicability for every selected control.

Choose Apply. One action covers up to 500 controls. If any selected control would end up out of scope without a reason, nothing is changed and the message lists up to five of their codes.

Bulk change applied reports "12 of 12 controls updated." and lists any skipped rows: "no longer exists", or "retired — reinstate it first to change it". Each updated control records its own new version, "Changed as part of a bulk update.", and each new owner is notified. Choose Done.

Clear selection deselects everything. Accept 5 proposed accepts the catalogue's proposed mappings for the selected controls, and needs Manage Requirements; see map controls to requirements.

Activate a draft

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Choose Draft in the Status filter and open the draft.

A draft is a control that has been proposed but not yet accepted, usually by the Controls Assistant. It shows Draft in the library and counts towards your plan's included controls.

  1. Open the draft and review the Definition tab. Change anything that is not right before you activate it; see govern control definitions and versions.

  2. Set Scope and handling and the owner.

  3. Use the action on the control to activate it.

The status changes to Active and a new version records the change. Nothing else about the control changes.

Retire or reinstate a control

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control; to find a retired control, choose Retired in the Status filter.

Retiring is the normal end of a control's life. Use it when your organisation stops operating a control, or when a standard update no longer carries it.

  1. Open the control and use the action to retire it.

  2. Enter why it is being retired. The reason is required and becomes part of the audit trail.

  3. Confirm.

A retired control shows Retired, and the version history records "Retired:" followed by your reason. It keeps its tests, evidence, deficiencies and history. It stops:

  • counting towards your plan's included controls;

  • generating scheduled work from its implementations;

  • counting in framework coverage, the Controls overview and the evidence matrix;

  • appearing in new Statement of Applicability versions;

  • accepting bulk changes.

Risks linked to it still show the link, but the control no longer counts towards their aggregate effectiveness.

To bring it back, choose Retired in the Status filter, open the control and use the action to reinstate it. It returns to Active, counts towards the allowance again, and its implementations resume generating work. The history records "Reinstated from retirement.".

Delete a control created by mistake

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control you created in error.

Delete is for a control your organisation created in error, such as a duplicate made during an import. Open the control and use the action to delete it, then confirm.

  • Only controls your organisation created can be deleted. A control from a pack is refused: "came from a control pack and cannot be deleted. Retire it instead".

  • A control that already has a recorded test cannot be deleted, because test results are permanent. Retire it instead.

Deleting removes the control permanently, together with its implementations, requirement mappings, risk and process links and version history. It cannot be undone.

Example: IT owns access controls

Product location: /qms/controls. Choose Library under Controls in the sidebar.

Your organisation has adopted ISO/IEC 27001, and its control pack has brought in the Annex A controls with nobody assigned. The IT manager, Sam Patel, is to own the access controls, and internal audit will test them.

  1. In the library, choose ISO/IEC 27001 in Standard and Owner: unassigned, then search for "access". The results include Access control, Access rights and Privileged access rights.

  2. Select them and choose Assign…. Set Owner to Sam Patel, What happens when the control fails to Exception, then CAPA, and Review every (days) to 365. Choose Apply. The result reads "4 of 4 controls updated.", and Sam receives four Control Assigned notifications.

  3. Choose Save this view and name it "IT access controls", so the IT team can return to the same list.

  4. Open Access rights and choose Scope and handling. In Your overall approach, write: "Each quarter IT exports the user lists of the finance system, the CRM and Microsoft 365, and each system owner confirms or revokes every account. Revocations are made within five working days." Choose Save.

  5. On Ownership, tick Whoever operates this control cannot test it, so Sam cannot record the test of a review Sam operates.

  6. Your organisation does no outsourced development. Filter for the Outsourced development control, set Does this control apply to you? to Not in scope and Why not, or only partly? to "All software is developed by our own staff; no development is outsourced." Save.

Next, add a quarterly implementation to Access rights so the review lands in Sam's inbox on schedule; see define where and how a control operates.

Did this answer your question?
😞
😐
😁