Help center

Help center

All collectionsControlsAssuranceDefine and review controls with AI

Define and review controls with AI

Use the Controls Assistant to draft controls, suggest requirement mappings, plan where controls run, read test evidence and explain residual risk, and review what it saved before anything counts.

Use the Controls Assistant to draft controls, suggest requirement mappings, plan where controls run, read test evidence and explain residual risk, and review what it saved before anything counts.

The Controls Assistant helps you turn an obligation or a risk into a control people can operate and test, and helps you read what a control's evidence and linked risks show. Everything it saves is a draft or a suggestion. It cannot activate a control, create or switch on an implementation, confirm a mapping or decide that a test passed; those decisions stay with people, through the same steps as any other change.

You can reach the assistant in two ways: a general conversation from the library, or a focused conversation on one tab of a control.

Who can use it

Product location: /qms/controls. Open Library in Controls.

Conversation or action

Permission

Draft a new control

Manage controls (controls:manage_controls)

Save, confirm or remove requirement mappings, including the assistant's suggestions

The QMS permission Manage Requirements (qms:manage_requirements)

Help me with this on Scope and handling, Requirements or Where it runs

Manage controls

Help me with this on Tests

View controls (controls:view_controls)

Help me with this on Risks

View controls and View Risks (rms:view_risks)

The assistant can only do what you could do yourself: it saves a mapping only for someone who holds Manage Requirements. Help me with this appears only when the Controls Assistant is available for your organisation and you hold the permission for that conversation.

Start a conversation

Product location: /tenant-context/chat/new. In the Library, choose Ask the assistant, then select Controls Assistant.

  1. Open Library in Controls.

  2. Choose Ask the assistant. A new conversation opens.

  3. Select Controls Assistant from the available agents. See using the assistant.

  4. Describe the obligation or risk, who is affected and what evidence you already have.

For example: "Help me define a control that stops new orders going to a critical supplier whose annual review is overdue. We review critical suppliers once a year. Ask me about ownership, the review evidence and where the control should apply before you create anything."

The assistant asks one question at a time. Ask it to check for an existing control before it creates another.

Draft a new control

Product location: /qms/controls. Open Library in Controls.

When you agree, the assistant creates the control as a Draft. It chooses a code, name, objective and description, when the control acts (preventive, detective, corrective or directive) and what it reduces: how often the event happens, how much it costs, or both. Check that last choice carefully, because it decides how the control affects your risk figures.

A control the assistant creates follows the same rules as one you create in the library: your plan must allow your own controls, the control counts toward your plan's control allowance, its code must be unique and valid, and it starts its version history like any other control.

Then, in the library:

  1. Filter Status to Draft and open the control.

  2. Review the definition, and set the owner, applicability, procedure and failure handling.

  3. Activate the draft when it is ready. See the control lifecycle.

A draft appears in the library and counts toward your allowance, but nothing is scheduled or tested until you activate it and add implementations.

Use Help me with this

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose the tab and choose Help me with this.

Each of five tabs on a control has its own conversation. Choose Help me with this on the tab; a panel opens and the assistant reads the control and speaks first.

Tab

Conversation

What it can save

Scope and handling

How do we carry this out?

Nothing. It drafts procedure wording for you to copy and save.

Requirements

Which clauses does this satisfy?

Suggested mappings that you agree to, each with its reason. They wait for a person to confirm them.

Where it runs

Where should this run?

Nothing. It proposes targets and implementations.

Tests

What does the evidence show?

Nothing. It reports what the evidence shows and does not cover.

Risks

What is this control holding down?

Nothing. It explains the gap between inherent and residual risk.

A notice at the top of the panel repeats what the assistant cannot do. Type in the box and press Enter to send, or Shift+Enter for a new line. Choose Skip this question to move on without answering. Each time you open the panel a new conversation starts, so it reads the control as it is now. When you close the panel, the tab reloads and shows anything that was saved.

Improve the procedure

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose Scope and handling and choose Help me with this.

On Scope and handling, open How do we carry this out?. The assistant reads the current procedure, says what is missing or too vague to tick off honestly, and asks how the work is actually done.

For example: "Rewrite this as steps a buyer can follow: where the supplier list comes from, what they check, what record they keep and what they do when a review is overdue."

Copy the wording you want into Your overall approach and choose Save. Check that each step names a real record someone can produce as evidence.

Plan where it runs

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose Where it runs and choose Help me with this.

On Where it runs, open Where should this run?. The assistant looks at what the control could apply to, such as processes, suppliers, reports or risks, and which applicable targets have nothing running on them. It prefers one target covering a set, for example "all critical suppliers", over a list of names that stops covering the next supplier you add.

It saves nothing. Create the targets, scope the control to them and add implementations yourself, deciding the cadence and who does the work. See where and how a control operates.

Review suggested mappings

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose Requirements and choose Help me with this.

On Requirements, open Which clauses does this satisfy?. The assistant summarises what the control already covers and where it sees gaps, then proposes clauses one at a time with a reason. When you agree, it saves the mapping as a suggestion.

A suggestion is not yet a mapping:

  • it shows on the Requirements tab with a Confirm button instead of Confirmed, and in the library as a clause marked "not yet confirmed by anyone here";

  • on Framework coverage it counts under Awaiting review, not as coverage;

  • it stays out of the Statement of Applicability until someone confirms it.

To accept it, set Coverage to Primary, Supporting or Partial, then choose Confirm. Choose Primary only where this control is the main way the clause is met. To reject it, choose Remove. See mapping controls to requirements.

Understand test evidence

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose Tests and choose Help me with this.

On Tests, open What does the evidence show?. The assistant reads the evidence behind the most recent test and reports what was examined, how much passed, what failed and what the evidence does not cover.

For example: "Does the sample cover every critical supplier? Which reviews in the evidence are missing a sign-off date?"

Use the answer when you record or approve a test. The verdict and sign-off remain yours; see testing a control.

Explain the linked risks

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control, choose Risks and choose Help me with this.

On Risks, open What is this control holding down?. The assistant starts with the linked risk that has most at stake and explains the gap between its inherent and residual score. It separates what cannot be checked, such as an untested control, from what the evidence contradicts. It cannot rescore a risk. See linking controls to risks.

Check what was saved

Product location: /qms/controls. Open Library in Controls.

After a conversation, open the records it touched:

The assistant said it

Check

Created a control

The library shows it with status Draft; review and activate it.

Mapped a clause

The Requirements tab shows it waiting for Confirm; set coverage and confirm or remove it.

Proposed targets or implementations

Nothing was saved; create what you agree with.

Drafted a procedure

Nothing was saved until you pasted it and chose Save.

For combining controls with forms, processes and documents, see connected workflows.

Did this answer your question?
😞
😐
😁