Help center

Help center

All collectionsControlsGetting set upAdopt control packs and import controls

Adopt control packs and import controls

See which control packs your standards brought in, preview and apply pack updates, and import controls from a spreadsheet or from the existing-control notes in your risk register.

See which control packs your standards brought in, preview and apply pack updates, and import controls from a spreadsheet or from the existing-control notes in your risk register.

Most controls reach your library in bulk. Control packs arrive with the standards you adopt in Quality Management, and Import controls brings in a control list you already keep in a spreadsheet or describe in your risk register.

Task

Permission

See Adopted control packs

View controls

Preview and apply a pack update

Adopt control packs

Import controls

Manage controls

Suggest controls from the risk register

Manage controls, plus the Risk Management permissions to read and link risks

How control packs arrive

Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.

A control pack is a set of controls that ComplyTrain's compliance team maintains for a standard, such as the Annex A controls of ISO/IEC 27001. When your organisation adopts a standard in Quality Management, each pack the standard carries is added to your library automatically; see complete setup for each QMS standard.

Each pack control arrives:

  • Active and In scope, with no owner;

  • with the pack's failure policy, and its default cadence and method for new implementations;

  • with independent testing or four-eyes sign-off switched on where the pack requires it;

  • with the catalogue's mappings to the standard's clauses added as suggestions, marked "not yet confirmed by anyone here" until someone confirms them.

A pack is always added in full, even if it takes you past the controls included in your plan. If you already created a control with the same code as a pack control, the pack's copy is not added; the preview shows it as Blocked.

The pack keeps the wording of each control up to date. Everything you decide about a control, such as its owner, applicability, reason, approach and failure policy, belongs to you and survives every update.

Read your adopted packs

Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.

Choose Adopted packs under Controls in the sidebar. Adopted control packs lists each pack:

Column

What it shows

Pack

The pack's code and name.

Adopted version

The version of the pack you hold.

Status

Active, or Superseded when the pack was withdrawn or detached from its standard. "Your controls stay — the evidence against them is yours."

In use

Controls from this pack that are not retired.

Total

All controls from this pack, including retired ones. A gap between the two is the record of controls you decided to retire.

Actions

Preview update.

When a new version of a pack you adopted is published, ComplyTrain sends a Control Pack Update Available notification. Nothing changes in your library until someone applies the update.

Preview a pack update

Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.

Choose Preview update on the pack's row. The preview covers every pack the same standard carries. What this would do opens, and "Nothing has been written yet. Close this and nothing changes."

The counts at the top summarise the outcome, such as "3 to create", "90 to refresh", "2 left alone" and "1 blocked". The table lists every control:

What happens

Meaning

Create

A control new to you will be added.

Refresh

You already hold it; its catalogue wording will be brought up to date, and a changed definition records a new version of the control. Your owner, applicability, reason, approach and cadence are not touched.

Leave alone

You changed its definition yourself, so the update skips it: "Controls you have edited yourself are left alone — a refresh never overwrites a deliberate local change."

Blocked

"You already have a control using the same code, so the version from the pack cannot be added. Rename yours first if you want both."

Defaults it will inherit shows what each control brings with it: On failure (its failure policy), Cadence (how often its implementations run by default) and Owning role (the role the pack suggests should own it). The owning role is guidance only; owners are always your decision.

Apply the update

Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.

  1. Read the preview, especially any Blocked rows.

  2. Choose Apply this. It is available when at least one control would be created or refreshed.

  3. Read Update applied and choose Done.

Result

Meaning

"3 controls created, 90 refreshed."

What was written.

"2 were left alone because you have edited them."

Controls whose definition you changed.

"2 controls are no longer carried by this standard:"

Controls you hold that the pack no longer contains, listed by code and name. "They have been left in place — you may hold evidence against them. Retire them yourself if they no longer apply."

The Adopted version updates. New controls appear in the library with no owner. Their catalogue mappings show as proposals in the Satisfies column, such as "2 proposed", for someone with Manage Requirements to accept; see map controls to requirements.

After an update, filter the library by the pack and Owner: unassigned to assign the new controls, and decide whether each applies to you; see build and maintain your control library. Retire any drifted control you no longer operate.

Import from a spreadsheet

Product location: /qms/controls/import. Choose Import controls in the Library, or Import under Controls in the sidebar.

Use this to bring in controls you already maintain elsewhere, such as an internal IT control list exported from another tool. Your plan must allow controls of your own.

  1. In the library, choose Import controls. Import controls opens at Choose a source.

  2. Under From a spreadsheet, choose Upload a CSV file, or paste the rows into Or paste the rows.

  3. Choose Check the rows. Nothing is created yet.

The first row must be headings. Only a name is required; a missing code is made from the name. Headings are matched without regard to capitals, spaces, hyphens or underscores, so "Control Code", "control_code" and "CONTROLCODE" are the same.

Field

Headings recognised

Code

code, control code, control id, ref, reference, clause, id, identifier

Name

name, control name, title, control, control title

Objective

objective, control objective, purpose, intent, goal

Description

description, detail, details, summary, text

When it acts

nature, control nature, type, control type

How it is carried out

automation, automation nature, automated, implementation

What it reduces

reduces, effect, barrier type, bowtie

Category

category, domain, group, theme, family

Applicability

applicability, applicability status, applicable, in scope, scope

Reason

justification, applicability justification, reason, exclusion reason

Your overall approach

procedure, how we perform, method, process, implementation detail

Common wordings are understood. A value that is not recognised takes the default instead.

Field

Values understood

Default

When it acts

Preventive, Preventative, Prevent; Detective, Detect, Monitoring; Corrective, Correct, Remediation; Directive, Direct, Policy, Administrative

Preventive

How it is carried out

Manual, Human; Automated, Automatic, System, Technical; Hybrid, Mixed, Semi-automated

Manual

What it reduces

Frequency, Likelihood, Probability; Magnitude, Impact, Severity, Consequence, Recovery; Both, All

Frequency

Applicability

In scope, Applicable, Yes, Y, True; Not in scope, Not applicable, N/A, No, N, False, Excluded; Partial, Partially, Partially applicable

In scope

Up to 2,000 rows are read at once. A longer file is cut off, and About this file says how many rows were read.

Review the rows

Product location: /qms/controls/import. Choose Check the rows on Import controls.

The Review step shows the counts, such as "60 rows", "57 ready to import", "2 need fixing" and "1 already exist", then every row with Row, Code, Control, Nature, Applicability and Notes. Row numbers count data rows, so row 1 is the first line under the headings.

Note

Meaning

"A control name is required"

The row has no name. It needs fixing.

"No code was supplied; "QUARTERLY-ACCESS-REVIEW" was derived from the name"

A code was made from the name. Check it is one you want to keep, because codes never change.

"is not a valid code"

The code must be 2 to 100 characters, start with a letter or digit, and use only letters, digits, dot, underscore and hyphen. It needs fixing.

"A justification is required when a control is not fully in scope"

The row is not fully in scope and has no reason. It needs fixing.

"appears more than once in this file"

Two rows share a code. It needs fixing.

"A control with this code already exists and this row will be skipped"

Nothing is changed for this row, so re-running an import that stopped part-way is safe.

"Rows that need fixing are shown with the reason and are left out of the import. Correct them in your spreadsheet and check again." Rows cannot be edited on this page.

Import the controls

Product location: /qms/controls/import. Review the rows on Import controls, then choose the import button.

Choose Import 57 controls. Every row is created exactly as a control created with New control would be, so the same rules and plan limits apply.

Import finished reports "57 of 58 controls created.", how many "were skipped because a control with the same code already exists", and each row that "could not be created" with its reason, such as a full allowance. Choose Go to the library or Import something else.

Imported controls are Active, have no owner, show Your own as their source, and each has version 1 on its Governance tab.

Suggest controls from the risk register

Product location: /qms/controls/import. On Import controls, choose Suggest controls from the risk register.

Many organisations already describe their controls as free text in each risk's Existing controls field. ComplyTrain can read those notes and suggest structured controls.

  1. Choose Import controls.

  2. Under From the risk register, choose Suggest controls from the risk register. "Reading the risk register…" shows while it works.

  3. Review the suggestions. Each row shows From the risk register: with the text it came from, and the note "Extracted by AI from existing-control text — confirm before importing."

  4. Choose Import 12 controls, with the number of suggestions you are keeping.

The suggestions come from an AI model, so read each one against its source text before you import it. The reading covers up to 200 risks at once; when there is more text than one reading can take, About this file says how many risks were left out.

Each imported suggestion is linked to the risk it came from, with the rationale "Extracted from this risk's legacy control notes and linked automatically.", and that risk's Existing controls text is cleared. The risk's Controls panel then shows the structured control in place of the note. See link controls to risks.

Example: import IT's control list

Product location: /qms/controls/import. Choose Import controls in the Library.

The IT team keeps 40 internal controls in a spreadsheet exported from its previous tool, with the headings Control ID, Control Title, Objective, Type, Automated, Scope and Exclusion reason.

  1. Save the sheet as CSV and upload it with Upload a CSV file, then choose Check the rows. Control ID becomes the code, Control Title the name, Type When it acts, Automated How it is carried out, Scope the applicability and Exclusion reason its reason.

  2. The review shows "40 rows", "38 ready to import" and "2 need fixing". One row has Scope "N/A" and no exclusion reason; another reuses the code IT-17.

  3. In the spreadsheet, add the reason "We have no on-premises servers." to the first and renumber the second IT-41. Upload the file again and choose Check the rows: "40 ready to import".

  4. Choose Import 40 controls. Import finished reports "40 of 40 controls created."

  5. In the library, filter Owner: unassigned, select the IT controls and use Assign… to make the IT manager their owner.

Did this answer your question?
😞
😐
😁