Where each Controls page is and how to reach it, which permissions and roles open each part, what your plan includes, and how controls connect to standards, risks, processes and everyday work.
Controls is where your organisation keeps its controls: the measures it operates to hold risks down and to meet the clauses of the standards it follows. Each control records what it is for, who owns it, whether it applies to you, where and how it runs, and how well it is working.
Quality Management and Risk Management share one control library. The quarterly access review that satisfies an ISO/IEC 27001 clause is the same record that lowers the residual score of your unauthorised-access risk.
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
Controls is part of every organisation that uses Quality Management (QMS), Risk Management (RMS) or both. There is no separate module to switch on, and it opens the same way whether or not your organisation uses Quality Management.
What you see and can change depends on your permissions, described below. How many controls, targets and implementations you can hold depends on your plan.
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
From | How |
|---|---|
The module launcher | Choose Controls, described as "The controls your organisation operates to hold risks down and satisfy the clauses of the standards you follow." |
Quality Management | In the sidebar, expand Controls and choose a page. |
Risk Management | In the sidebar, under Analysis, choose Controls. |
Every route opens the same library, with the full Controls navigation: organisations without Quality Management see the same Controls pages in the sidebar.
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
Sidebar entry | Page | What you do there |
|---|---|---|
Library | Controls | Find, create, import and bulk-assign controls. See build and maintain your control library. |
Overview | Controls overview | Overall effectiveness, tested coverage, open exceptions and tests due. See framework coverage and the Controls overview. |
Due board | Due board | Scheduled control work: what is due, what is late and who holds it. See due controls and evidence. |
Deficiencies | Deficiency register | Failed tests, their remediation and any accepted risk. See deficiencies, exceptions and risk acceptance. |
Awaiting my approval | Awaiting my approval | Test results recorded by other people that need your sign-off. See test a control and get it signed off. |
Estate | Control estate | The environments, processes, stakeholders and other targets your controls apply to. Manage dimensions opens Target dimensions. See where and how a control operates. |
Reporting systems | Reporting systems | External systems that check your environments and send in results. |
Reporting health | Reporting health | Which automated checks report normally, have never reported or have stopped. See external reporting. |
Adopted packs | Adopted control packs | The control packs your standards brought in, and pack updates. See adopt control packs and import controls. |
Governance | Segregation exceptions | Where someone may test a control they also operate, and why. See govern control definitions and versions. |
Import | Import controls | Bring controls in from a spreadsheet or from your risk register. |
Two pages belong to a single standard and have no sidebar entry: Statement of Applicability and Framework coverage. Open them from the standard, or choose the standard in the Library's Standard filter and use the Statement of Applicability or Framework coverage link that appears beside the filters.
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
Select a row in the Library to open the control. The All controls link at the top returns to the Library.
Tab | What it holds |
|---|---|
Definition | What the control is: When it acts, How it is carried out, What it reduces, Category, What it is and Guidance. |
Scope and handling | Whether the control applies to you and why, your overall approach, and what a failed test produces. |
Ownership | Who owns the control, whether its tester must be independent, and whether each result needs a second person's approval. |
Requirements | The clauses the control satisfies, how fully, and whether anyone has confirmed each mapping. |
Where it runs | Its implementations: where it runs, how, how often and who does it. |
Tests | Its effectiveness rating, every recorded test and the evidence behind it. |
Exceptions | Its deficiency history and the failure policy in force. |
Governance | Its configuration history, a comparison between two dates and an integrity check for each version. |
Risks | The risks it mitigates, and the processes that carry it out. |
Links | The targets it covers and its related controls. |
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
Controls has eight permissions. They appear in the role catalogue under Controls.
Permission | Code | What it allows |
|---|---|---|
View controls |
| Open Controls and read the library, each control, the estate, coverage and the Statement of Applicability. Changes nothing. |
Manage controls |
| Create, import, edit, activate, retire, reinstate and delete controls. Set owners, delegates, applicability, procedures, failure policies and thresholds. Add implementations, record tests and evidence, work deficiencies, and build and submit a Statement of Applicability. |
Manage the estate |
| Declare and edit estate targets and dimensions, register reporting systems, manage their signing keys and bindings, and ask a system to check now. |
Adopt control packs |
| Preview and apply updates to the control packs your standards carry. |
Accept control risk |
| Settle a deficiency by accepting the risk instead of fixing it. You are recorded as the approver. |
Approve control test results |
| Approve or reject a test somebody else recorded, where the control requires a second person's approval. |
Manage control governance |
| Require independent testing and four-eyes sign-off on a control, and record or withdraw segregation exceptions. You are recorded as the approver. |
Approve Statement of Applicability |
| Send a submitted Statement of Applicability back for changes, or approve and sign it. |
Organisation Admins pass every permission check. Buttons and actions appear only for people who can use them, so a reader without Manage controls sees the library without New control or Import controls.
Some Controls work also touches another module and needs that module's permission:
Creating, confirming or removing a mapping between a control and a requirement needs Manage Requirements (qms:manage_requirements). That includes accepting ComplyTrain's proposed mappings and the assistant's suggestions.
Seeing the risks a control mitigates, and linking controls to risks, need the matching Risk Management permissions. See link controls to risks.
The Carried out by section of the Risks tab lists Quality Management processes and needs View Processes (qms:view_processes).
Product location: /settings/roles. Open Settings, then Roles & Permissions, and open a role to see its Controls permissions.
In Quality Management, each Controls permission is given to the roles that already hold a matching Quality Management permission:
Controls permission | Given to roles that hold |
|---|---|
View controls | View Documents or Manage Documents |
Manage controls, Manage the estate | Manage Documents |
Adopt control packs, Accept control risk, Manage control governance, Approve Statement of Applicability | Manage Requirements |
Approve control test results | Approve Documents |
For the system roles this gives:
System role | Controls permissions |
|---|---|
Quality Manager, Quality Lead, Document Controller | All eight |
Process Owner | All except Approve control test results |
Quality Auditor, QMS Viewer, Form Filler | View controls |
RMS Administrator | View controls, Manage controls, Accept control risk |
Risk Manager | View controls, Manage controls |
Billing Manager | None |
An organisation without Quality Management therefore works in Controls through its Risk Management roles. To give other people access, or to narrow who can accept risk or approve the Statement of Applicability, create a custom role with the Controls permissions you intend and assign it. See create roles and choose their permissions and RMS roles and permissions.
Product location: /settings/billing/usage. Open Settings, then Billing & Payments, and select the Usage tab.
Plan limit | Team and Starter | Professional | Enterprise |
|---|---|---|---|
Controls included | 100 | 200 | 500 |
Controls beyond the included number | Not available | Billed | Billed |
Estate targets | 3 | 25 | 100 |
Implementations per control | 2 | 10 | 25 |
Implementations reported by an external system | None | 25 | 100 |
Controls of your own | Yes | Yes | Yes |
Residual risk derived from control effectiveness | No | Yes | Yes |
On the free plan, controls still arrive with your standards, but you cannot author your own, declare targets or add implementations. A negotiated allowance in your agreement replaces these figures.
Active and draft controls count towards the included controls; retired controls do not. Controls that arrive with a standard are always added in full, even beyond the allowance. On Team and Starter you then cannot add controls of your own until you retire or delete enough to fall below it: the refusal reads "Your plan includes 100 controls and you already have 100. Existing controls keep working — retire or delete one, or upgrade, to add another."
Targets marked as no longer counting towards coverage do not count towards the target limit. At the target limit, Add target is unavailable, with "Your plan allows 3 targets and you have declared them all. Deactivate one to declare another." At the implementation limit, Add on the Where it runs tab is unavailable, with "Your plan allows 2 implementations per control, and this one has them all. Retire one to add another." Both update as soon as you add, retire or deactivate one. See monitor usage and limits for billing figures.
Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.
Where | What happens |
|---|---|
Standards | Adopting a standard brings its control packs into the library and suggests which clause each control satisfies. The standard's scope list shows the controls mapped to each clause, and each standard has its own Statement of Applicability and framework coverage. See standards, requirements and controls. |
Requirements | A mapping links a control to an exact requirement, with its coverage and rationale. See map controls to requirements. |
Risks | A risk's Controls panel links the controls that mitigate it, with coverage and weight. Their tested effectiveness supports the residual score. See link controls to risks. |
Processes | A process's Controls panel records whether the process or a step Performs this control, Produces evidence for it or Depends on it. The control's Risks tab shows these under Carried out by. |
Tasks, forms, recurring tasks and process runs | Each implementation's schedule creates the work: a task in the owner's inbox, a recurring task in Quality Management, a form to fill in or a process run ready to start. Completing an attestation task records the completer's verdict with its evidence. Completing a form, recurring task or process run links its evidence to a test that waits for the tester's verdict. Work that is not done stays due and becomes Overdue until the control is tested. |
CAPA and action items | A failed test follows the control's failure policy: a deficiency in the register, a CAPA, or an item on the owner's action list. It is raised when the result is approved, or at once when the control needs no sign-off. |
Reporting | Every organisation using Controls, with or without Quality Management, finds six Controls reports in Reporting: Control Register, Control Effectiveness Over Time, Statement of Applicability, Control Exception Register, Control Evidence Pack and Automated Control Reporting Health. They need View controls. |
Controls also sends notifications: Control Assigned to a new owner, Control Deficiency Raised to the owner when a test fails, Control Test Awaiting Your Approval to approvers, Control Test Rejected at Sign-off to the tester, Control Test Overdue and Control Deficiency Overdue to the holder's manager, Risk Acceptance Expiring, Segregation Exception Expiring to its approver, and Control Pack Update Available when a pack you adopted is republished. Choose how you receive each in your notification preferences.