Declare the estate your controls run against, scope and relate controls, and add the implementations that put each control on a schedule and create its work.
A control states what your organisation commits to. The estate is the list of things those commitments apply to: cloud accounts, documented processes, suppliers, reports and so on. An implementation is how the control is carried out in one place, by one person, on one schedule. A control can have several implementations, and each runs on its own.
Product location: /qms/controls/targets. Open Estate in Controls.
Task | What you need |
|---|---|
See the estate, a control's scope and its implementations | View controls ( |
Add or edit targets, and declare dimensions | Manage the estate ( |
Scope a control, relate controls, add, pause, switch on or retire implementations, and activate pack recipes | Manage controls ( |
Admins can do all of these. Buttons you cannot use are not shown.
Product location: /qms/controls/targets. Open Estate in Controls.
Open Controls, then Estate. The Control estate table lists each target with its Code, Target, Kind, Dimensions, External reference and the number of Controls measured against it.
Choose Add target. The dialog is titled Add an environment.
Complete the fields below and choose Save.
Field | What to enter | Rules |
|---|---|---|
Code | A short, stable identifier, such as | Required. 2 to 100 characters: letters, digits, dot, colon, underscore or hyphen, starting with a letter or digit. Cannot be changed later. |
What is this target? | An environment (cloud account, datacentre, SaaS tenant), A documented process, A stakeholder from the register, A report you review, A risk from the register, A controlled document or Something outside ComplyTrain. | Required. Cannot be changed later. |
Kind | For an environment only: AWS, Azure, Google Cloud, On-premise, SaaS or Process. It decides which dimensions apply. | Required for environments. Cannot be changed later. |
How much of it? | For processes, stakeholders, reports, risks and controlled documents: One specific thing, All of them, or, for stakeholders, All of a certain type. | Required for those kinds. The dialog shows how many things the choice covers right now. |
Which one? / Which type? | The process, stakeholder, report, risk or document, or the stakeholder type. | Required for One specific thing and All of a certain type. |
Name | A name people recognise, such as "AWS production account". | Required. Up to 300 characters. |
Description | What the target is and why it is in scope. | Optional. |
External reference | The real system's identifier, such as an AWS account number. | Optional. |
Dimensions | Values for each dimension declared for the kind, such as account and region. | Required dimensions must be filled in. |
All of them and All of a certain type stay up to date by themselves: a supplier onboarded tomorrow is covered without anyone editing the target. An implementation on such a target falls due once for each thing it covers.
Your plan sets how many targets you can declare. Targets that no longer count toward coverage do not count toward the limit either. When the limit is reached, Add target explains why it is unavailable; take a target out of use, as described below, to free a place.
Product location: /qms/controls/targets. Open Estate in Controls.
Choose Edit on the target. You can change Name, Description, External reference and Dimensions, but not the code or kind.
To take a target out of use, set Counts toward coverage to No, it has been decommissioned and save. It stops counting toward every control's coverage and toward your plan's target limit, and the record that it once counted is kept. That is what explains a change in coverage between two audit periods.
Product location: /qms/controls/targets/dimensions. Open Estate in Controls and choose Manage dimensions.
Dimensions are the coordinates that identify an environment, such as account, region and environment name. External reporting systems use them to say what they examined. Choose Manage dimensions on the estate page to open Target dimensions, then Declare a dimension.
Field | What it does | Rules |
|---|---|---|
Applies to | The kind of environment, such as AWS. | Required. |
Key | The exact name a reporting system sends, such as | Lowercase letters, digits and underscores, starting with a letter; up to 40 characters. Cannot be changed. Up to 12 keys per kind. |
Label and Description | What people see, and what whoever configures a reporting system reads. | Label required, up to 200 characters. |
Required | Every environment of this kind must have a value. | Refused while any environment lacks a value: add the dimension as optional, fill it in, then make it required. |
Accepted values | A comma-separated list, or empty for Any value. | Up to 200 values of up to 200 characters. Narrowing the list is refused while an environment uses a value it would exclude. |
Choose Remove and confirm Remove dimension to delete one. Environments keep the values already recorded, but reporting systems can no longer name that key.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Links tab.
By default, a control's coverage is measured against the targets its implementations run on. To state its scope explicitly, open the control and select Links. What it covers lists the targets that make up the denominator of its coverage figure.
Use the action to add a target to the control's scope, and choose the target.
To record that the control deliberately does not apply to a target, mark it as not applicable and give a justification. The justification is required, and the target shows as excluded.
To take a target out of the control's scope altogether, remove it. Unlike an exclusion, removal leaves no record of a decision.
Once a control has at least one scoped target, only its scoped, applicable, active targets count. Scoping changes the control's Covers figure in the library, the coverage shown on its Tests tab and on the Due board, and its effectiveness.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Links tab.
Under Related controls on the Links tab, record how this control depends on others. Use the action to add a relationship, choose the other control and the type, and add a note explaining why.
Type | Meaning |
|---|---|
Compensates for | This control stands in for one that is not in place. "Not implemented, but compensated for" is a different answer to an auditor from "not applicable". |
Depends on | This control is ineffective unless the other one also operates. |
Supersedes | This control replaces the other. |
A control cannot be related to itself, and the same relationship is recorded only once. Removing a relationship does not change either control.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Where it runs tab.
Open the control and select Where it runs. The panel How this control is carried out lists its implementations with Where, How, How often, Next due and Status.
Choose Add. The dialog is titled Add an implementation.
Complete the fields below. Leave Start it running straight away off while you prepare it.
Choose Save. The implementation is listed as Not running, or Running if you switched it on.
Field | What it does | Rules and defaults |
|---|---|---|
What is done | Becomes the title of every task it creates, so write it as an instruction. | Required. Up to 300 characters. |
Runs on | A target from the estate, or Not tied to anything specific for an organisational control such as a board review. | Defaults to not tied. |
How it is carried out | The evaluator: see the table below. | Required. |
Which process / Which form | The approved QMS process to run, or the form to fill in. | Required for those evaluators. |
How often | Not on a schedule, Every day, Every week, Every month, Every quarter, Every year, Every so many days or On set dates. | See the cadence table. |
Who does it | Whoever owns the control, or a named person. | A form-based implementation needs a person, either here or as the control owner. |
If a test of this fails | Whatever the control says, or one of Log only, Open an exception, Exception, then CAPA, CAPA directly or Create an action item. | Set it only when this place warrants a different consequence from the others. |
How to do it | The procedure the person follows. | Optional. |
Steps | Steps a tester ticks off one at a time. Use Add step and the arrows to order them. | Optional. Leave empty to record a single overall verdict. |
Start it running straight away | Puts the implementation on the clock as soon as it is saved. | Off by default. |
Your plan sets how many implementations a control can have, and how many can be reported by external systems. When a control has reached the limit, Add explains why it is unavailable. Retire an implementation to make room for another.
Evaluator | What happens when it falls due |
|---|---|
Someone confirms it was done | The person gets a task in My Tasks, completes it and gives the result, Pass or Fail. They are recorded as the tester, and the completed task is the evidence. |
A recurring task in QMS | On the first due date, a recurring task definition is created in QMS. From then on QMS generates each occurrence, with its own reminders. Each occurrence also appears on the Due board until its test is recorded. |
A form is filled in | A draft of the form is created for the person, with a task telling them. Submitting the form completes it. |
A process is run | A run of the approved process is created, ready to start, with a task asking the owner to cast and start it. |
Reported by an external system | Nothing is created for anyone. The due date expects a signed report from the reporting system bound to this implementation, and the report carries its own result. A schedule is required. See connect reporting systems. |
Completing a form, recurring task or process run links it as evidence and creates a test that waits for a tester's verdict. See work through due controls.
Cadence | Settings |
|---|---|
Every day | None. |
Every week | Which day: Monday to Sunday. |
Every month | Day of the month: 1 to 31. |
Every quarter | Which months (January, April, July and October by default) and Day of the month. |
Every year | Which month and Day of the month. |
Every so many days | Every how many days: 1 to 365, default 30. |
On set dates | One or more calendar dates. After the last date has passed, the implementation has no next due date. |
Not on a schedule | Nothing is generated. The implementation still counts for coverage and can be tested. |
For how month-end days are handled, see the schedule reference.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open an adopted control from the Library and select the Where it runs tab.
A control adopted from a pack can carry implementation recipes, such as "on an AWS account, review IAM users quarterly". Activating them creates one implementation for each matching target in your estate, instead of adding them one by one.
Preview the activation. It lists each recipe and target pairing with what would happen: create, refresh, or skip with a reason.
Activate. Every implementation created is Not running, so nobody is sent work until you switch it on.
Review the new implementations on each control's Where it runs tab, set owners if needed, and choose Switch on.
Activation can be repeated safely, for example after a pack update. It refreshes the recipe's own wording on existing implementations but never changes their owner, cadence or status, and it never brings back an implementation you retired.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Where it runs tab.
Action | Effect |
|---|---|
Switch on | Puts the implementation on the clock; its status becomes Running and its Next due date is set. |
Pause | Takes it off the clock without losing its setup; status Not running. |
Retire | Stops it permanently. Enter Why is it being retired?; the reason is kept. Its history stays as the record that the control was carried out. |
History | Lists each due date and What happened: Task created, Recurring task set up in QMS, Form ready to fill in, Process run created, or Nothing was created with the reason. |
Select Show retired implementations to see retired ones. For Reported by an external system, Review design opens the design review and passing thresholds. A retired implementation cannot be switched on again; add a new one instead.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Where it runs tab.
Your control AC-07 Quarterly access review must run on the production AWS account and on the HR system, and not on the sandbox account.
In Estate, add aws-prod and aws-sandbox (An environment, kind AWS, with account and region dimensions) and hr-saas (An environment, kind SaaS).
On AC-07's Links tab, scope it to both, and mark aws-sandbox as not applicable with the justification "No personal or customer data; rebuilt weekly from code".
On Where it runs, add "Review user access on the production AWS account": Runs on aws-prod, A recurring task in QMS, because the platform team manages its obligations in QMS; Every quarter on day 15 of January, April, July and October; Who does it the cloud platform lead; and three steps: export the user list, compare it with the leavers list, remove and record unneeded access.
Add "Review user access on the HR system": Runs on hr-saas, Someone confirms it was done, the same cadence, with the HR systems manager as owner.
Choose Switch on for both. Each shows Running with Next due 15 April.
On 15 April, the AWS implementation sets up its recurring task in QMS and its History shows Recurring task set up in QMS; from then on its quarterly occurrences appear in QMS Recurring Tasks. The HR implementation's History shows Task created. Both reviews appear on the Due board until their tests are recorded.
AC-07's Covers figure is now 2. See work through due controls and record evidence for what happens next.