Link the controls that mitigate a risk, say how much of the risk each one covers and how much it counts, read the combined effectiveness, and check whether the recorded residual score is supported.
A risk in RMS says what could go wrong and how likely and severe it is. A control in Controls is something your organisation does to hold that risk down. Linking the two lets the risk show how well its controls are actually working, based on their test results, instead of a note someone typed once. It also lets ComplyTrain challenge a residual score that claims more protection than the controls can show.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
Task | Permissions |
|---|---|
See a risk's linked controls, or a control's linked risks | View controls ( |
Link, change or unlink a control on a risk | Manage controls ( |
Record that a challenged residual stands | View controls and Edit Risks |
Organisation administrators can do all of these. Buttons for actions you cannot perform are not shown. See permission codes.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
Links are made on the risk, where the person assessing it has the risk in front of them. Open the risk in Risk (RMS); the Controls panel is on its Overview tab. The control's Risks tab shows the same links from the other side, read-only.
Only controls that exist in your control library can be linked. To create controls from the notes in your risk register, see importing controls.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
Open the risk and find the Controls panel.
Choose Link a control. The dialog Link a control to this risk opens.
Complete the fields below.
Choose Save.
Field | What to enter | Limits and default |
|---|---|---|
Control | The control, chosen from Choose a control. | Required. Controls already linked to this risk are not listed. A control can be linked to a risk only once. |
How much of this risk does it address? | The share of the risk the control deals with, as a percentage. Set it lower when the control handles only part of the risk. | Whole number from 0 to 100. Default 100. |
How much should it count? | The control's weight relative to this risk's other controls. Use 0 to record a control without letting it affect the figure. | 0 to 100, in steps of 0.25. Default 1. |
Why does this control mitigate this risk? | The reason for the link, for example "Quarterly access review removes dormant accounts, which is the main route in." | Optional, but it is what a reviewer reads when the link is questioned. |
The link appears in the panel straight away, and on the control's Risks tab.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
The panel's headline gives the combined figure, for example Control effectiveness: Partly working. Beneath it, short lines explain the figure: how many linked controls count toward it and what share of the risk they cover, how many are untested, how many were tested and found Not working, how many are retired, and what share of the risk nothing claims to address.
Column | What it shows |
|---|---|
Control | Code and name, the reason for the link, and Retired if the control has been retired. |
Effectiveness | Working, Partly working, Not working or Not yet known. When overdue testing has lowered the rating, a line such as Was Working, now 21 days past its test date explains it. |
Covers | The percentage you entered. |
Weight | The weight you entered, or Not counted for a weight of 0. |
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
Each counted control contributes its effectiveness score multiplied by the share of the risk it covers.
Weights decide how much each contribution counts against the others.
Controls with a weight of 0, and retired controls, are left out of the figure but stay listed.
If any counted control is Not yet known, the combined figure is Not yet known. An average of only the tested controls would claim more protection than the evidence shows.
When the covered percentages add up to less than 100, the panel says how much of the risk nothing claims to address. A control that works perfectly but covers 30% still leaves 70% uncovered.
Control ratings come from their test results and age when testing is overdue. See testing a control.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
To change the coverage, weight or reason, choose Edit on the row. Change this link opens with the same fields except the control; choose Save.
To remove the link, choose Unlink, read Unlink this control? and choose Unlink again. The control no longer counts toward the risk.
Unlink only when the control genuinely does not mitigate this risk. If your organisation has stopped operating the control, retire the control instead. A retired control stays linked, marked Retired, and visibly stops counting, which records what happened. See the control lifecycle.
Product location: /qms/controls/{controlId} (fallback: /qms/controls). Open the control from the Library and choose the Risks tab.
Open the control and choose its Risks tab, Risks this control mitigates. The table lists Risk, Inherent, Residual, Covers and Weight, ordered by inherent score, so the risk with most at stake if the control fails comes first. Coverage and weight are set on the risk, not here. Help me with this on this tab opens the assistant to explain what the control is holding down; see working with AI.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
Below the Controls panel on the risk, Residual vs controls compares the residual score someone recorded with the residual the linked controls support.
Finding | Meaning | What to do |
|---|---|---|
Supported | The recorded residual is within tolerance of what the controls support, or more cautious. | Nothing. |
Not supported | The recorded residual claims more protection than the controls are proven to deliver. | Rescore the residual, improve or test the controls, or record why it stands. |
Evidence has slipped | A control that justified the score has failed a test or gone overdue since the score was set. | Look at that control, then rescore or record why the residual stands. |
Cannot be checked | No controls are linked, or the linked controls are not yet tested. | Link the real controls and test them. |
The panel shows the tolerance, for example Differences up to 3.75 are treated as agreement — 15% of this methodology's 25-point scale. To keep a challenged residual, choose The recorded residual stands, explain in Why the recorded residual stands, for example "the exposure is transferred under the group insurance policy", and choose Record this. The acknowledgement covers the disagreement as it stood; if the scores or controls change, the challenge is raised again.
Residual challenges in RMS lists every risk whose residual is not supported. It is rebuilt by a nightly check, so open a risk to see its current position. If your risk methodology computes residual scores from control effectiveness, the platform maintains the residual and it cannot be edited by hand. See controls and residual challenges.
When a risk has a loss estimate, What the controls are worth shows the yearly loss the linked controls avoid, overall and per control. See the risk record.
Product location: /qms/controls/import. Open Import in Controls and choose to suggest controls from the risk register.
Before controls could be linked, risks described their controls in a free-text note. While a risk still has one, it appears read-only under Earlier note about controls. Import controls from the risk register to turn those notes into real controls: each imported control is linked to its risk and the note is removed. See importing controls.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the risk from the Risk Register; the Controls panel is on its Overview tab.
The risk "Unauthorised access to customer data through dormant accounts" is scored on a 25-point scale. Its inherent score is 16 and its recorded residual is 2. The risk owner links two controls:
Control | How much of this risk does it address? | How much should it count? | Why does this control mitigate this risk? |
|---|---|---|---|
AC-03 Quarterly access review | 70 | 1 | Removes dormant accounts, the main route in. |
AC-07 Multi-factor authentication | 100 | 2 | Stops a stolen password alone from giving access. |
AC-07 is Working, but AC-03 has never been tested, so the panel reads Control effectiveness: Not yet known and Residual vs controls shows Cannot be checked.
The control owner tests AC-03 and records that it ran, with gaps. When the risk owner reopens the risk, the panel reads Control effectiveness: Partly working. Residual vs controls now shows Not supported: the controls support a residual of about 6, and the recorded 2 claims more protection than that, beyond the tolerance of 3.75 points. The risk owner rescores the residual to 5, and the finding changes to Supported. The owner of AC-03 plans a fix for the gaps the test found.