The control library
The control library holds every safeguard your organisation relies on, defined once and reusable across any number of risks. Find it under Settings → Controls.
Creating a control
Select Create. The form is grouped into sections; the ones that matter most:
| Group | Contains |
|---|---|
| Identity | Name, description, control type (preventive, detective, corrective) and category. |
| Compliance mapping | Which framework clauses this control satisfies. Populated automatically for controls that arrive in a framework pack. |
| Effectiveness | How well the control works when operating as designed. |
| Governance | Owner, reviewer, and review cycle. Without these a control quietly rots. |
| Evidence | What proves the control operates, and where that proof lives. |
| Weight and cost | Relative importance and cost of operation, for prioritisation. |
| Implementation and scope | Current status and which parts of the organisation it covers. |
Viewing a control
The read view adds what the create form cannot: an effectiveness log, test history with pass and partial-pass results, downloadable evidence, restricted comments, and the linked risks list showing this control’s mitigation percentage on each one.
That linked-risks list is the most useful screen in the library. It answers the question an auditor always asks: if this control failed, what would be exposed?
Global versus per-risk properties
Everything on this page is the control’s global definition. When you attach a control to a risk it also gains local properties for that risk only — which dimension it reduces, by how much, and its local implementation status. See Attaching controls to a risk.
Review cycles
Set a review cycle on every control. The cycle drives the overdue indicators in the control health tile on each risk. A library where nothing is ever reviewed produces risk scores that look precise and are not.