See what the organisation owes on the Due board, complete the tasks, forms, recurring tasks and process runs that controls create, and know what that completion records.
When an implementation that is switched on reaches its due date, ComplyTrain creates the work in the place that suits it: a task, a form, a recurring task in QMS or a process run. Completing that work links it to the control as evidence and records, or starts, the control's test for that due date. The Due board shows what the whole organisation owes and who holds it, and each piece of work stays there until its test is recorded.
Product location: /qms/controls/due. Open Due board in Controls.
Task | What you need |
|---|---|
Open the Due board | View controls ( |
Complete work assigned to you | Nothing extra for a task. For a form or process run, access to that part of QMS, as for any other form or run. |
Record a test yourself, or add evidence | Manage controls ( |
Work goes to the implementation's owner. If the implementation has no owner, it goes to the control's owner. While a control is delegated, new work goes to the delegate for the delegation period, and the Due board shows them as holding it; see govern control definitions and versions.
Product location: /qms/controls/due. Open Due board in Controls.
Open Controls, then Due board. Each piece of work that falls due appears here, whichever way the control is carried out, and stays until its test is recorded. The four figures at the top always describe the whole organisation, whatever filters you choose:
Figure | What it counts |
|---|---|
On a schedule | All the due work on the board. |
Overdue | Work whose due date has passed without its test being recorded. |
Due this week | Those due today or in the next seven days. |
Nobody holds | Those with no owner on either the implementation or the control. |
Filter the table with Any owner, Anywhere (a target), Any pack and Overdue only; Clear filters resets them. The table lists 50 rows at a time, earliest first:
Column | What it shows |
|---|---|
Due | The due date. An overdue row also shows how many days late it is, for example 12 days late. |
Control | The control code and the implementation's name. |
Where | The target, or Not tied to anything specific. |
Who holds it | The person holding the work, Nobody, or Covering while the owner is away for a delegate. |
Effectiveness | Working, Partly working, Not working or Not yet known. If lateness has lowered the rating, the row also says, for example, Was Working when last tested. |
Coverage | Targets tested out of targets in scope, or a dash when the control has no estate. |
Select a row to open the control. An empty board reads Nothing is on a schedule yet.; a control appears only once it has a running implementation with a cadence.
Product location: /qms/controls/due. Open Due board in Controls.
How it is carried out | What the holder receives | How they complete it | Evidence linked to the test |
|---|---|---|---|
Someone confirms it was done | A task in My Tasks on the Dashboard, titled with the implementation's What is done. | Mark complete in My Tasks, giving the result Pass or Fail. Choose Open to read the control first. | Completed task |
A recurring task in QMS | An occurrence in QMS Recurring Tasks, with the recurring task's reminders. | Complete the occurrence, with notes and supporting files. See complete recurring task instances. | Completed task |
A form is filled in | A draft of the form, and a task in My Tasks that opens Submissions. | Fill in and submit the form. The task cannot be ticked off in My Tasks; submitting the form completes it. | Completed form |
A process is run | A run of the process, ready to start, and a task in My Tasks that opens the run. | Cast the lanes and start the run, then complete it. The task closes when the run starts, or when it is cancelled. See start, cast and complete a process run. | Process run |
Reported by an external system | Nothing. The reporting system is expected to send a signed report. | The report arrives. See connect reporting systems. | The report |
Each due date produces its own piece of work, so the second quarter's task never replaces the first quarter's. Every piece of work is listed under History on the implementation.
Product location: /dashboard. Open Dashboard and find the task in My Tasks.
Open Dashboard and find the task in My Tasks. The due text shows, for example, Due in 3 days or Overdue by 2 days.
Choose Open to read the control and the implementation's procedure and steps.
Do the work.
For a Someone confirms it was done task, choose Mark complete and give the result: Pass or Fail. For other work, complete the form, recurring task occurrence or process run where it lives.
For a form or a process run, My Tasks offers only Open, because the work is finished in QMS.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and select the Tests tab.
Completing the work records a test for that due date against the implementation, or starts one, with the completed work linked as evidence:
How it is carried out | What completing records |
|---|---|
Someone confirms it was done | A test with the result the person gave, Pass or Fail. They are recorded as the tester. |
A recurring task in QMS, A form is filled in or A process is run | The completed work is attached as evidence, and a test is created for that due date that waits for a tester's verdict. A tester records the verdict on the control's Tests tab; see test a control and get it signed off. |
Reported by an external system | The report carries its own result. |
You can see each test on the control's Tests tab: the period, where it ran, and Evidence with the number of items linked. Select Evidence to see what is linked. The work leaves the Due board once its test is recorded.
If the control requires independent testing or a second approver, the result waits for sign-off in Awaiting my approval, and the rules on who may test the control apply as usual. The control's effectiveness and coverage are updated once the result counts. A failing result applies the control's failure policy when it counts: straight away, or when it is approved if the control needs sign-off. See manage deficiencies and risk acceptance.
When someone records a test on the control's Tests tab for work that has already fallen due, the open task for that due date is closed, so the work is not done twice.
To add further evidence, such as a link to an exported user list, open the test's Evidence and attach it. See test a control and get it signed off.
Product location: /qms/controls/due. Open Due board in Controls.
On the Due board: work whose due date has passed without a test is counted under Overdue and shows how many days late it is. It stays there until its test is recorded.
Effectiveness ages: a rating stays as tested for 14 days after a test was due. After that, Working reads as Partly working, and the row says what it was. After 180 days overdue, the rating becomes Not yet known. Ageing never makes a control read Not working; only a failed test does that.
The holder's manager is told: once the work is more than three days past its due date, the manager of the person holding the work receives Control Test Overdue. If that person has no manager recorded, nobody is escalated to. Managers are set on each person's user record; see link people to their managers.
Product location: /qms/controls/due. Open Due board in Controls.
Controls sends these notifications. Each person can choose how they receive them in their notification preferences, under Workflow; see read your notifications and choose how you get them.
Notification | Sent to | When |
|---|---|---|
Control Assigned | The new owner | A control is assigned to them. |
Control Test Awaiting Your Approval | People who approve control test results | A test that needs a second person's approval is recorded. |
Control Test Rejected at Sign-off | The tester | An approver rejects their test. |
Control Test Overdue | The holder's manager | Due work is more than three days past its due date without a test. |
Control Deficiency Raised | The deficiency owner | A failed test raises a deficiency. |
Control Deficiency Overdue | The owner's manager | An outstanding deficiency is more than three days past its due date. |
Risk Acceptance Expiring | The deficiency owner | A risk acceptance lapses within 14 days. |
Segregation Exception Expiring | The exception's approver | A segregation exception lapses within 30 days. |
Control Pack Update Available | People responsible for your adopted packs | A new version of a pack you have adopted is published. |
Product location: /qms/recurring-tasks/instances. Open Recurring Tasks in QMS to find the control's occurrence.
AC-07 Quarterly access review has two implementations, both due on 15 April:
"Review user access on the production AWS account", a recurring task in QMS held by the cloud platform lead.
"Review user access on the HR system", Someone confirms it was done, held by the HR systems manager.
On 15 April, the occurrence appears in QMS Recurring Tasks for the cloud platform lead. The HR systems manager sees "Review user access on the HR system" in My Tasks, marked Due today. Both reviews appear on the Due board.
The cloud platform lead exports the user list, compares it with the leavers list, removes two accounts and completes the occurrence with a note and the exported list attached. AC-07's Tests tab shows a test for aws-prod with Evidence (1), the completed task, waiting for a tester's verdict.
The HR systems manager chooses Open, follows the procedure, then chooses Mark complete and gives Pass. A test for hr-saas is recorded with them as the tester and the completed task as evidence. Because AC-07 requires a second approver, the result waits in Awaiting my approval.
The internal auditor reviews the exported list attached to the AWS test and records its verdict, and the quality manager approves both results. The 15 April work leaves the Due board, AC-07's coverage counts both targets as tested, and the next reviews fall due on 15 July.
Had the HR review still been open on 19 April, its row would have shown 4 days late, and the HR systems manager's manager would have received Control Test Overdue. For how a tester records a verdict and how the approver signs it off, see test a control and get it signed off.