Help center

Help center

All collectionsControlsGetting set upFind your way around Controls

Find your way around Controls

Where each Controls page is and how to reach it, which permissions and roles open each part, what your plan includes, and how controls connect to standards, risks, processes and everyday work.

Where each Controls page is and how to reach it, which permissions and roles open each part, what your plan includes, and how controls connect to standards, risks, processes and everyday work.

Controls is where your organisation keeps its controls: the measures it operates to hold risks down and to meet the clauses of the standards it follows. Each control records what it is for, who owns it, whether it applies to you, where and how it runs, and how well it is working.

Quality Management and Risk Management share one control library. The quarterly access review that satisfies an ISO/IEC 27001 clause is the same record that lowers the residual score of your unauthorised-access risk.

Who can open Controls

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

Controls is part of every organisation that uses Quality Management (QMS), Risk Management (RMS) or both. There is no separate module to switch on, and it opens the same way whether or not your organisation uses Quality Management.

What you see and can change depends on your permissions, described below. How many controls, targets and implementations you can hold depends on your plan.

Open Controls

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

From

How

The module launcher

Choose Controls, described as "The controls your organisation operates to hold risks down and satisfy the clauses of the standards you follow."

Quality Management

In the sidebar, expand Controls and choose a page.

Risk Management

In the sidebar, under Analysis, choose Controls.

Every route opens the same library, with the full Controls navigation: organisations without Quality Management see the same Controls pages in the sidebar.

Pages in Controls

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

Sidebar entry

Page

What you do there

Library

Controls

Find, create, import and bulk-assign controls. See build and maintain your control library.

Overview

Controls overview

Overall effectiveness, tested coverage, open exceptions and tests due. See framework coverage and the Controls overview.

Due board

Due board

Scheduled control work: what is due, what is late and who holds it. See due controls and evidence.

Deficiencies

Deficiency register

Failed tests, their remediation and any accepted risk. See deficiencies, exceptions and risk acceptance.

Awaiting my approval

Awaiting my approval

Test results recorded by other people that need your sign-off. See test a control and get it signed off.

Estate

Control estate

The environments, processes, stakeholders and other targets your controls apply to. Manage dimensions opens Target dimensions. See where and how a control operates.

Reporting systems

Reporting systems

External systems that check your environments and send in results.

Reporting health

Reporting health

Which automated checks report normally, have never reported or have stopped. See external reporting.

Adopted packs

Adopted control packs

The control packs your standards brought in, and pack updates. See adopt control packs and import controls.

Governance

Segregation exceptions

Where someone may test a control they also operate, and why. See govern control definitions and versions.

Import

Import controls

Bring controls in from a spreadsheet or from your risk register.

Two pages belong to a single standard and have no sidebar entry: Statement of Applicability and Framework coverage. Open them from the standard, or choose the standard in the Library's Standard filter and use the Statement of Applicability or Framework coverage link that appears beside the filters.

Tabs on a control

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

Select a row in the Library to open the control. The All controls link at the top returns to the Library.

Tab

What it holds

Definition

What the control is: When it acts, How it is carried out, What it reduces, Category, What it is and Guidance.

Scope and handling

Whether the control applies to you and why, your overall approach, and what a failed test produces.

Ownership

Who owns the control, whether its tester must be independent, and whether each result needs a second person's approval.

Requirements

The clauses the control satisfies, how fully, and whether anyone has confirmed each mapping.

Where it runs

Its implementations: where it runs, how, how often and who does it.

Tests

Its effectiveness rating, every recorded test and the evidence behind it.

Exceptions

Its deficiency history and the failure policy in force.

Governance

Its configuration history, a comparison between two dates and an integrity check for each version.

Risks

The risks it mitigates, and the processes that carry it out.

Links

The targets it covers and its related controls.

Controls permissions

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

Controls has eight permissions. They appear in the role catalogue under Controls.

Permission

Code

What it allows

View controls

controls:view_controls

Open Controls and read the library, each control, the estate, coverage and the Statement of Applicability. Changes nothing.

Manage controls

controls:manage_controls

Create, import, edit, activate, retire, reinstate and delete controls. Set owners, delegates, applicability, procedures, failure policies and thresholds. Add implementations, record tests and evidence, work deficiencies, and build and submit a Statement of Applicability.

Manage the estate

controls:manage_control_targets

Declare and edit estate targets and dimensions, register reporting systems, manage their signing keys and bindings, and ask a system to check now.

Adopt control packs

controls:adopt_control_packs

Preview and apply updates to the control packs your standards carry.

Accept control risk

controls:accept_control_risk

Settle a deficiency by accepting the risk instead of fixing it. You are recorded as the approver.

Approve control test results

controls:approve_control_tests

Approve or reject a test somebody else recorded, where the control requires a second person's approval.

Manage control governance

controls:manage_control_governance

Require independent testing and four-eyes sign-off on a control, and record or withdraw segregation exceptions. You are recorded as the approver.

Approve Statement of Applicability

controls:approve_soa

Send a submitted Statement of Applicability back for changes, or approve and sign it.

Organisation Admins pass every permission check. Buttons and actions appear only for people who can use them, so a reader without Manage controls sees the library without New control or Import controls.

Some Controls work also touches another module and needs that module's permission:

  • Creating, confirming or removing a mapping between a control and a requirement needs Manage Requirements (qms:manage_requirements). That includes accepting ComplyTrain's proposed mappings and the assistant's suggestions.

  • Seeing the risks a control mitigates, and linking controls to risks, need the matching Risk Management permissions. See link controls to risks.

  • The Carried out by section of the Risks tab lists Quality Management processes and needs View Processes (qms:view_processes).

Controls permissions in each role

Product location: /settings/roles. Open Settings, then Roles & Permissions, and open a role to see its Controls permissions.

In Quality Management, each Controls permission is given to the roles that already hold a matching Quality Management permission:

Controls permission

Given to roles that hold

View controls

View Documents or Manage Documents

Manage controls, Manage the estate

Manage Documents

Adopt control packs, Accept control risk, Manage control governance, Approve Statement of Applicability

Manage Requirements

Approve control test results

Approve Documents

For the system roles this gives:

System role

Controls permissions

Quality Manager, Quality Lead, Document Controller

All eight

Process Owner

All except Approve control test results

Quality Auditor, QMS Viewer, Form Filler

View controls

RMS Administrator

View controls, Manage controls, Accept control risk

Risk Manager

View controls, Manage controls

Billing Manager

None

An organisation without Quality Management therefore works in Controls through its Risk Management roles. To give other people access, or to narrow who can accept risk or approve the Statement of Applicability, create a custom role with the Controls permissions you intend and assign it. See create roles and choose their permissions and RMS roles and permissions.

What your plan includes

Product location: /settings/billing/usage. Open Settings, then Billing & Payments, and select the Usage tab.

Plan limit

Team and Starter

Professional

Enterprise

Controls included

100

200

500

Controls beyond the included number

Not available

Billed

Billed

Estate targets

3

25

100

Implementations per control

2

10

25

Implementations reported by an external system

None

25

100

Controls of your own

Yes

Yes

Yes

Residual risk derived from control effectiveness

No

Yes

Yes

On the free plan, controls still arrive with your standards, but you cannot author your own, declare targets or add implementations. A negotiated allowance in your agreement replaces these figures.

Active and draft controls count towards the included controls; retired controls do not. Controls that arrive with a standard are always added in full, even beyond the allowance. On Team and Starter you then cannot add controls of your own until you retire or delete enough to fall below it: the refusal reads "Your plan includes 100 controls and you already have 100. Existing controls keep working — retire or delete one, or upgrade, to add another."

Targets marked as no longer counting towards coverage do not count towards the target limit. At the target limit, Add target is unavailable, with "Your plan allows 3 targets and you have declared them all. Deactivate one to declare another." At the implementation limit, Add on the Where it runs tab is unavailable, with "Your plan allows 2 implementations per control, and this one has them all. Retire one to add another." Both update as soon as you add, retire or deactivate one. See monitor usage and limits for billing figures.

How controls connect to other modules

Product location: /qms/controls. Open Controls from the module launcher, or choose Controls in the Quality Management or Risk Management sidebar.

Where

What happens

Standards

Adopting a standard brings its control packs into the library and suggests which clause each control satisfies. The standard's scope list shows the controls mapped to each clause, and each standard has its own Statement of Applicability and framework coverage. See standards, requirements and controls.

Requirements

A mapping links a control to an exact requirement, with its coverage and rationale. See map controls to requirements.

Risks

A risk's Controls panel links the controls that mitigate it, with coverage and weight. Their tested effectiveness supports the residual score. See link controls to risks.

Processes

A process's Controls panel records whether the process or a step Performs this control, Produces evidence for it or Depends on it. The control's Risks tab shows these under Carried out by.

Tasks, forms, recurring tasks and process runs

Each implementation's schedule creates the work: a task in the owner's inbox, a recurring task in Quality Management, a form to fill in or a process run ready to start. Completing an attestation task records the completer's verdict with its evidence. Completing a form, recurring task or process run links its evidence to a test that waits for the tester's verdict. Work that is not done stays due and becomes Overdue until the control is tested.

CAPA and action items

A failed test follows the control's failure policy: a deficiency in the register, a CAPA, or an item on the owner's action list. It is raised when the result is approved, or at once when the control needs no sign-off.

Reporting

Every organisation using Controls, with or without Quality Management, finds six Controls reports in Reporting: Control Register, Control Effectiveness Over Time, Statement of Applicability, Control Exception Register, Control Evidence Pack and Automated Control Reporting Health. They need View controls.

Controls also sends notifications: Control Assigned to a new owner, Control Deficiency Raised to the owner when a test fails, Control Test Awaiting Your Approval to approvers, Control Test Rejected at Sign-off to the tester, Control Test Overdue and Control Deficiency Overdue to the holder's manager, Risk Acceptance Expiring, Segregation Exception Expiring to its approver, and Control Pack Update Available when a pack you adopted is republished. Choose how you receive each in your notification preferences.

Did this answer your question?
😞
😐
😁