Help center

Help center

All collectionsControlsAssuranceLink controls to risks

Link controls to risks

Link the controls that mitigate a risk, say how much of the risk each one covers and how much it counts, read the combined effectiveness, and check whether the recorded residual score is supported.

Link the controls that mitigate a risk, say how much of the risk each one covers and how much it counts, read the combined effectiveness, and check whether the recorded residual score is supported.

A risk in RMS says what could go wrong and how likely and severe it is. A control in Controls is something your organisation does to hold that risk down. Linking the two lets the risk show how well its controls are actually working, based on their test results, instead of a note someone typed once. It also lets ComplyTrain challenge a residual score that claims more protection than the controls can show.

Who can link controls to risks

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

Task

Permissions

See a risk's linked controls, or a control's linked risks

View controls (controls:view_controls) and View Risks (rms:view_risks)

Link, change or unlink a control on a risk

Manage controls (controls:manage_controls) and Edit Risks (rms:edit_risks)

Record that a challenged residual stands

View controls and Edit Risks

Organisation administrators can do all of these. Buttons for actions you cannot perform are not shown. See permission codes.

Where links are made

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

Links are made on the risk, where the person assessing it has the risk in front of them. Open the risk in Risk (RMS); the Controls panel is on its Overview tab. The control's Risks tab shows the same links from the other side, read-only.

Only controls that exist in your control library can be linked. To create controls from the notes in your risk register, see importing controls.

Link a control to a risk

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

  1. Open the risk and find the Controls panel.

  2. Choose Link a control. The dialog Link a control to this risk opens.

  3. Complete the fields below.

  4. Choose Save.

Field

What to enter

Limits and default

Control

The control, chosen from Choose a control.

Required. Controls already linked to this risk are not listed. A control can be linked to a risk only once.

How much of this risk does it address?

The share of the risk the control deals with, as a percentage. Set it lower when the control handles only part of the risk.

Whole number from 0 to 100. Default 100.

How much should it count?

The control's weight relative to this risk's other controls. Use 0 to record a control without letting it affect the figure.

0 to 100, in steps of 0.25. Default 1.

Why does this control mitigate this risk?

The reason for the link, for example "Quarterly access review removes dormant accounts, which is the main route in."

Optional, but it is what a reviewer reads when the link is questioned.

The link appears in the panel straight away, and on the control's Risks tab.

Read the Controls panel

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

The panel's headline gives the combined figure, for example Control effectiveness: Partly working. Beneath it, short lines explain the figure: how many linked controls count toward it and what share of the risk they cover, how many are untested, how many were tested and found Not working, how many are retired, and what share of the risk nothing claims to address.

Column

What it shows

Control

Code and name, the reason for the link, and Retired if the control has been retired.

Effectiveness

Working, Partly working, Not working or Not yet known. When overdue testing has lowered the rating, a line such as Was Working, now 21 days past its test date explains it.

Covers

The percentage you entered.

Weight

The weight you entered, or Not counted for a weight of 0.

How the combined figure works

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

  • Each counted control contributes its effectiveness score multiplied by the share of the risk it covers.

  • Weights decide how much each contribution counts against the others.

  • Controls with a weight of 0, and retired controls, are left out of the figure but stay listed.

  • If any counted control is Not yet known, the combined figure is Not yet known. An average of only the tested controls would claim more protection than the evidence shows.

  • When the covered percentages add up to less than 100, the panel says how much of the risk nothing claims to address. A control that works perfectly but covers 30% still leaves 70% uncovered.

Control ratings come from their test results and age when testing is overdue. See testing a control.

Change or unlink a control

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

To change the coverage, weight or reason, choose Edit on the row. Change this link opens with the same fields except the control; choose Save.

To remove the link, choose Unlink, read Unlink this control? and choose Unlink again. The control no longer counts toward the risk.

Unlink only when the control genuinely does not mitigate this risk. If your organisation has stopped operating the control, retire the control instead. A retired control stays linked, marked Retired, and visibly stops counting, which records what happened. See the control lifecycle.

See a control's risks

Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and choose the Risks tab.

Open the control and choose its Risks tab, Risks this control mitigates. The table lists Risk, Inherent, Residual, Covers and Weight, ordered by inherent score, so the risk with most at stake if the control fails comes first. Coverage and weight are set on the risk, not here. Help me with this on this tab opens the assistant to explain what the control is holding down; see working with AI.

Check the residual score

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

Below the Controls panel on the risk, Residual vs controls compares the residual score someone recorded with the residual the linked controls support.

Finding

Meaning

What to do

Supported

The recorded residual is within tolerance of what the controls support, or more cautious.

Nothing.

Not supported

The recorded residual claims more protection than the controls are proven to deliver.

Rescore the residual, improve or test the controls, or record why it stands.

Evidence has slipped

A control that justified the score has failed a test or gone overdue since the score was set.

Look at that control, then rescore or record why the residual stands.

Cannot be checked

No controls are linked, or the linked controls are not yet tested.

Link the real controls and test them.

The panel shows the tolerance, for example Differences up to 3.75 are treated as agreement — 15% of this methodology's 25-point scale. To keep a challenged residual, choose The recorded residual stands, explain in Why the recorded residual stands, for example "the exposure is transferred under the group insurance policy", and choose Record this. The acknowledgement covers the disagreement as it stood; if the scores or controls change, the challenge is raised again.

Residual challenges in RMS lists every risk whose residual is not supported. It is rebuilt by a nightly check, so open a risk to see its current position. If your risk methodology computes residual scores from control effectiveness, the platform maintains the residual and it cannot be edited by hand. See controls and residual challenges.

When a risk has a loss estimate, What the controls are worth shows the yearly loss the linked controls avoid, overall and per control. See the risk record.

Replace an earlier note

Product location: /qms/controls/import. Open Import in Controls and choose to suggest controls from the risk register.

Before controls could be linked, risks described their controls in a free-text note. While a risk still has one, it appears read-only under Earlier note about controls. Import controls from the risk register to turn those notes into real controls: each imported control is linked to its risk and the note is removed. See importing controls.

Example: dormant accounts

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.

The risk "Unauthorised access to customer data through dormant accounts" is scored on a 25-point scale. Its inherent score is 16 and its recorded residual is 2. The risk owner links two controls:

Control

How much of this risk does it address?

How much should it count?

Why does this control mitigate this risk?

AC-03 Quarterly access review

70

1

Removes dormant accounts, the main route in.

AC-07 Multi-factor authentication

100

2

Stops a stolen password alone from giving access.

AC-07 is Working, but AC-03 has never been tested, so the panel reads Control effectiveness: Not yet known and Residual vs controls shows Cannot be checked.

The control owner tests AC-03 and records that it ran, with gaps. When the risk owner reopens the risk, the panel reads Control effectiveness: Partly working. Residual vs controls now shows Not supported: the controls support a residual of about 6, and the recorded 2 claims more protection than that, beyond the tolerance of 3.75 points. The risk owner rescores the residual to 5, and the finding changes to Supported. The owner of AC-03 plans a fix for the gaps the test found.

Did this answer your question?
😞
😐
😁