The control library

The control library holds every safeguard your organisation relies on, defined once and reusable across any number of risks. Find it under Settings → Controls.

Creating a control

Select Create. The form is grouped into sections; the ones that matter most:

Group Contains
Identity Name, description, control type (preventive, detective, corrective) and category.
Compliance mapping Which framework clauses this control satisfies. Populated automatically for controls that arrive in a framework pack.
Effectiveness How well the control works when operating as designed.
Governance Owner, reviewer, and review cycle. Without these a control quietly rots.
Evidence What proves the control operates, and where that proof lives.
Weight and cost Relative importance and cost of operation, for prioritisation.
Implementation and scope Current status and which parts of the organisation it covers.

Viewing a control

The read view adds what the create form cannot: an effectiveness log, test history with pass and partial-pass results, downloadable evidence, restricted comments, and the linked risks list showing this control’s mitigation percentage on each one.

That linked-risks list is the most useful screen in the library. It answers the question an auditor always asks: if this control failed, what would be exposed?

Global versus per-risk properties

Everything on this page is the control’s global definition. When you attach a control to a risk it also gains local properties for that risk only — which dimension it reduces, by how much, and its local implementation status. See Attaching controls to a risk.

Review cycles

Set a review cycle on every control. The cycle drives the overdue indicators in the control health tile on each risk. A library where nothing is ever reviewed produces risk scores that look precise and are not.