See which control packs your standards brought in, preview and apply pack updates, and import controls from a spreadsheet or from the existing-control notes in your risk register.
Most controls reach your library in bulk. Control packs arrive with the standards you adopt in Quality Management, and Import controls brings in a control list you already keep in a spreadsheet or describe in your risk register.
Task | Permission |
|---|---|
See Adopted control packs | View controls |
Preview and apply a pack update | Adopt control packs |
Import controls | Manage controls |
Suggest controls from the risk register | Manage controls, plus the Risk Management permissions to read and link risks |
Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.
A control pack is a set of controls that ComplyTrain's compliance team maintains for a standard, such as the Annex A controls of ISO/IEC 27001. When your organisation adopts a standard in Quality Management, each pack the standard carries is added to your library automatically; see complete setup for each QMS standard.
Each pack control arrives:
Active and In scope, with no owner;
with the pack's failure policy, and its default cadence and method for new implementations;
with independent testing or four-eyes sign-off switched on where the pack requires it;
with the catalogue's mappings to the standard's clauses added as suggestions, marked "not yet confirmed by anyone here" until someone confirms them.
A pack is always added in full, even if it takes you past the controls included in your plan. If you already created a control with the same code as a pack control, the pack's copy is not added; the preview shows it as Blocked.
The pack keeps the wording of each control up to date. Everything you decide about a control, such as its owner, applicability, reason, approach and failure policy, belongs to you and survives every update.
Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.
Choose Adopted packs under Controls in the sidebar. Adopted control packs lists each pack:
Column | What it shows |
|---|---|
Pack | The pack's code and name. |
Adopted version | The version of the pack you hold. |
Status | Active, or Superseded when the pack was withdrawn or detached from its standard. "Your controls stay — the evidence against them is yours." |
In use | Controls from this pack that are not retired. |
Total | All controls from this pack, including retired ones. A gap between the two is the record of controls you decided to retire. |
Actions | Preview update. |
When a new version of a pack you adopted is published, ComplyTrain sends a Control Pack Update Available notification. Nothing changes in your library until someone applies the update.
Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.
Choose Preview update on the pack's row. The preview covers every pack the same standard carries. What this would do opens, and "Nothing has been written yet. Close this and nothing changes."
The counts at the top summarise the outcome, such as "3 to create", "90 to refresh", "2 left alone" and "1 blocked". The table lists every control:
What happens | Meaning |
|---|---|
Create | A control new to you will be added. |
Refresh | You already hold it; its catalogue wording will be brought up to date, and a changed definition records a new version of the control. Your owner, applicability, reason, approach and cadence are not touched. |
Leave alone | You changed its definition yourself, so the update skips it: "Controls you have edited yourself are left alone — a refresh never overwrites a deliberate local change." |
Blocked | "You already have a control using the same code, so the version from the pack cannot be added. Rename yours first if you want both." |
Defaults it will inherit shows what each control brings with it: On failure (its failure policy), Cadence (how often its implementations run by default) and Owning role (the role the pack suggests should own it). The owning role is guidance only; owners are always your decision.
Product location: /qms/controls/adoptions. Choose Adopted packs under Controls in the sidebar.
Read the preview, especially any Blocked rows.
Choose Apply this. It is available when at least one control would be created or refreshed.
Read Update applied and choose Done.
Result | Meaning |
|---|---|
"3 controls created, 90 refreshed." | What was written. |
"2 were left alone because you have edited them." | Controls whose definition you changed. |
"2 controls are no longer carried by this standard:" | Controls you hold that the pack no longer contains, listed by code and name. "They have been left in place — you may hold evidence against them. Retire them yourself if they no longer apply." |
The Adopted version updates. New controls appear in the library with no owner. Their catalogue mappings show as proposals in the Satisfies column, such as "2 proposed", for someone with Manage Requirements to accept; see map controls to requirements.
After an update, filter the library by the pack and Owner: unassigned to assign the new controls, and decide whether each applies to you; see build and maintain your control library. Retire any drifted control you no longer operate.
Product location: /qms/controls/import. Choose Import controls in the Library, or Import under Controls in the sidebar.
Use this to bring in controls you already maintain elsewhere, such as an internal IT control list exported from another tool. Your plan must allow controls of your own.
In the library, choose Import controls. Import controls opens at Choose a source.
Under From a spreadsheet, choose Upload a CSV file, or paste the rows into Or paste the rows.
Choose Check the rows. Nothing is created yet.
The first row must be headings. Only a name is required; a missing code is made from the name. Headings are matched without regard to capitals, spaces, hyphens or underscores, so "Control Code", "control_code" and "CONTROLCODE" are the same.
Field | Headings recognised |
|---|---|
Code | code, control code, control id, ref, reference, clause, id, identifier |
Name | name, control name, title, control, control title |
Objective | objective, control objective, purpose, intent, goal |
Description | description, detail, details, summary, text |
When it acts | nature, control nature, type, control type |
How it is carried out | automation, automation nature, automated, implementation |
What it reduces | reduces, effect, barrier type, bowtie |
Category | category, domain, group, theme, family |
Applicability | applicability, applicability status, applicable, in scope, scope |
Reason | justification, applicability justification, reason, exclusion reason |
Your overall approach | procedure, how we perform, method, process, implementation detail |
Common wordings are understood. A value that is not recognised takes the default instead.
Field | Values understood | Default |
|---|---|---|
When it acts | Preventive, Preventative, Prevent; Detective, Detect, Monitoring; Corrective, Correct, Remediation; Directive, Direct, Policy, Administrative | Preventive |
How it is carried out | Manual, Human; Automated, Automatic, System, Technical; Hybrid, Mixed, Semi-automated | Manual |
What it reduces | Frequency, Likelihood, Probability; Magnitude, Impact, Severity, Consequence, Recovery; Both, All | Frequency |
Applicability | In scope, Applicable, Yes, Y, True; Not in scope, Not applicable, N/A, No, N, False, Excluded; Partial, Partially, Partially applicable | In scope |
Up to 2,000 rows are read at once. A longer file is cut off, and About this file says how many rows were read.
Product location: /qms/controls/import. Choose Check the rows on Import controls.
The Review step shows the counts, such as "60 rows", "57 ready to import", "2 need fixing" and "1 already exist", then every row with Row, Code, Control, Nature, Applicability and Notes. Row numbers count data rows, so row 1 is the first line under the headings.
Note | Meaning |
|---|---|
"A control name is required" | The row has no name. It needs fixing. |
"No code was supplied; "QUARTERLY-ACCESS-REVIEW" was derived from the name" | A code was made from the name. Check it is one you want to keep, because codes never change. |
"is not a valid code" | The code must be 2 to 100 characters, start with a letter or digit, and use only letters, digits, dot, underscore and hyphen. It needs fixing. |
"A justification is required when a control is not fully in scope" | The row is not fully in scope and has no reason. It needs fixing. |
"appears more than once in this file" | Two rows share a code. It needs fixing. |
"A control with this code already exists and this row will be skipped" | Nothing is changed for this row, so re-running an import that stopped part-way is safe. |
"Rows that need fixing are shown with the reason and are left out of the import. Correct them in your spreadsheet and check again." Rows cannot be edited on this page.
Product location: /qms/controls/import. Review the rows on Import controls, then choose the import button.
Choose Import 57 controls. Every row is created exactly as a control created with New control would be, so the same rules and plan limits apply.
Import finished reports "57 of 58 controls created.", how many "were skipped because a control with the same code already exists", and each row that "could not be created" with its reason, such as a full allowance. Choose Go to the library or Import something else.
Imported controls are Active, have no owner, show Your own as their source, and each has version 1 on its Governance tab.
Product location: /qms/controls/import. On Import controls, choose Suggest controls from the risk register.
Many organisations already describe their controls as free text in each risk's Existing controls field. ComplyTrain can read those notes and suggest structured controls.
Choose Import controls.
Under From the risk register, choose Suggest controls from the risk register. "Reading the risk register…" shows while it works.
Review the suggestions. Each row shows From the risk register: with the text it came from, and the note "Extracted by AI from existing-control text — confirm before importing."
Choose Import 12 controls, with the number of suggestions you are keeping.
The suggestions come from an AI model, so read each one against its source text before you import it. The reading covers up to 200 risks at once; when there is more text than one reading can take, About this file says how many risks were left out.
Each imported suggestion is linked to the risk it came from, with the rationale "Extracted from this risk's legacy control notes and linked automatically.", and that risk's Existing controls text is cleared. The risk's Controls panel then shows the structured control in place of the note. See link controls to risks.
Product location: /qms/controls/import. Choose Import controls in the Library.
The IT team keeps 40 internal controls in a spreadsheet exported from its previous tool, with the headings Control ID, Control Title, Objective, Type, Automated, Scope and Exclusion reason.
Save the sheet as CSV and upload it with Upload a CSV file, then choose Check the rows. Control ID becomes the code, Control Title the name, Type When it acts, Automated How it is carried out, Scope the applicability and Exclusion reason its reason.
The review shows "40 rows", "38 ready to import" and "2 need fixing". One row has Scope "N/A" and no exclusion reason; another reuses the code IT-17.
In the spreadsheet, add the reason "We have no on-premises servers." to the first and renumber the second IT-41. Upload the file again and choose Check the rows: "40 ready to import".
Choose Import 40 controls. Import finished reports "40 of 40 controls created."
In the library, filter Owner: unassigned, select the IT controls and use Assign… to make the IT manager their owner.