Start a free trial
Menu

Controls & Assurance

Know whether your controls are operating, not just whether a policy says they exist.

Connect control definitions to real implementations, tests, evidence and independent sign-off, from one library shared by quality and risk management.

See whether your controls are actually operating

A control library holds the definitions: what a control is for, who owns it, whether it is preventive or detective, and whether it runs by hand or automatically. Adopting a control pack gives you that starting point, and a starting point is all it is.

What makes a control real is its implementation: where it actually applies, when its evidence is due, who tested it and who signed the result off. Quality and risk management draw on the same library, so a control relied on to treat a risk is the same record the audit programme tests.

What it looks like

  • Control library containing an independent calibration review control, with ownership and scope columns.
    Keep control definitions in a shared library, used by both quality management and risk management.

Use cases

  • One control, two uses

    A control relied on to treat a risk is the same definition the audit programme tests, so assurance and risk stop disagreeing about what exists.

  • Know what is overdue

    The due board shows missing and stale evidence as missing and stale. Nothing counts as satisfied because nobody looked.

  • Follow a failure somewhere

    A failed observation raises a deficiency, and the deficiency links to the corrective action or risk that carries the work.

From a definition to evidence it operates

  • One shared library

    Control definitions used by both QMS and Risk Management, so a control is not maintained twice with two answers.

  • Implementations

    Concrete target implementations and applicability, held separately from the definition that describes the intent.

  • Due board

    What is due, what is missing and what has gone stale, without treating missing evidence as a pass.

  • Testing and sign-off

    A completed test and an approved result are different states, and independent sign-off is recorded as its own act.

  • Deficiencies

    A failed observation becomes a deficiency record with a route into corrective action or risk, not an automatic fix.

  • Coverage with rationale

    Statement of Applicability, exclusions and framework coverage, with the reasoning kept attached.

Independent calibration review control definition with detective nature and manual operation.

Control definition

Separate the promise from its implementation

A control definition states its objective, its owner, its nature and how it operates. The definition above is exactly that: a description of what the control is meant to achieve, and it does not by itself establish that the control runs.

Implementations are where that gets settled. Each says where the control applies, what evidence is expected and when, and it is the test result and its independent sign-off that turn an intention into assurance. Segregation exceptions, where they are unavoidable, are recorded rather than quietly allowed.

  • Objective, owner, nature and method of operation on the definition
  • Applicability and expected evidence on the implementation
  • Testing and approval recorded as separate states
  • Recorded segregation exceptions where independence is not achievable

Run it on your own documents

Start a trial and use this module on real material, not a demo dataset. We set the workspace up for you, usually within one business day.