Controls & Assurance
Know whether your controls are operating, not just whether a policy says they exist.
Connect control definitions to real implementations, tests, evidence and independent sign-off, from one library shared by quality and risk management.
See whether your controls are actually operating
A control library holds the definitions: what a control is for, who owns it, whether it is preventive or detective, and whether it runs by hand or automatically. Adopting a control pack gives you that starting point, and a starting point is all it is.
What makes a control real is its implementation: where it actually applies, when its evidence is due, who tested it and who signed the result off. Quality and risk management draw on the same library, so a control relied on to treat a risk is the same record the audit programme tests.
What it looks like

Keep control definitions in a shared library, used by both quality management and risk management.
Use cases
One control, two uses
A control relied on to treat a risk is the same definition the audit programme tests, so assurance and risk stop disagreeing about what exists.
Know what is overdue
The due board shows missing and stale evidence as missing and stale. Nothing counts as satisfied because nobody looked.
Follow a failure somewhere
A failed observation raises a deficiency, and the deficiency links to the corrective action or risk that carries the work.
From a definition to evidence it operates
One shared library
Control definitions used by both QMS and Risk Management, so a control is not maintained twice with two answers.
Implementations
Concrete target implementations and applicability, held separately from the definition that describes the intent.
Due board
What is due, what is missing and what has gone stale, without treating missing evidence as a pass.
Testing and sign-off
A completed test and an approved result are different states, and independent sign-off is recorded as its own act.
Deficiencies
A failed observation becomes a deficiency record with a route into corrective action or risk, not an automatic fix.
Coverage with rationale
Statement of Applicability, exclusions and framework coverage, with the reasoning kept attached.

Control definition
Separate the promise from its implementation
A control definition states its objective, its owner, its nature and how it operates. The definition above is exactly that: a description of what the control is meant to achieve, and it does not by itself establish that the control runs.
Implementations are where that gets settled. Each says where the control applies, what evidence is expected and when, and it is the test result and its independent sign-off that turn an intention into assurance. Segregation exceptions, where they are unavoidable, are recorded rather than quietly allowed.
- Objective, owner, nature and method of operation on the definition
- Applicability and expected evidence on the implementation
- Testing and approval recorded as separate states
- Recorded segregation exceptions where independence is not achievable
