Skip to main content
Version: 1.0.0

Control Playbooks

Use these playbooks when working with controls, control testing, linked risks, assessment responses, and audit findings.

Maintain a Control

  1. Open Controls.
  2. Search for the control by code, title, framework, or domain.
  3. Confirm owner, description, objective, and domain.
  4. Review linked frameworks and mappings.
  5. Review evidence and testing history.
  6. Review linked risks and whether the control is still effective.
  7. Review exceptions and change requests.
  8. Update owner, notes, or implementation details if allowed.
  9. Schedule the next review or test.

Respond to a Control in an Assessment

  1. Open the assessment.
  2. Open the Controls tab.
  3. Filter to My Controls.
  4. Open the assigned control.
  5. Select compliance status.
  6. Add findings and recommendations for gaps.
  7. Upload evidence.
  8. Save.

Handle an Audit Finding Against a Control

  1. Review the audit finding and linked assessment control.
  2. Confirm whether the finding is material.
  3. Link issue or risk if required.
  4. Complete remediation and upload evidence.
  5. Wait for auditor verification.
  6. Reassess the affected assessment control after the platform marks it for reassessment.
  7. Upload updated evidence.
  8. Confirm linked risk or issue can be updated.

FAQ

QuestionAnswer
Should every control have an owner?Yes. Ownerless controls create weak assessments and weak audit evidence.
What makes control evidence good?It should match the control, period, scope, and approved source.
When should a control be retested?After major change, failed assessment, audit finding, exception, incident, or scheduled review.
Can control reassessment be targeted?Yes. Verified audit findings can reopen only the affected assessment control.