Skip to main content

Control Details

Manage individual control attributes, evidence sources, linked risks, assurance, and reviews.

Written by James Ross

Overview

The control detail page is where you manage an individual control — its attributes, evidence sources, linked risks, assurance records, and review cycle. This article covers all fields and actions available on a control.

Control Header

The top of the control detail page displays:

  • Title — click to edit via an inline modal. Changes save without a full page reload.

  • Description — click to edit via an inline modal

  • Status badge — colour-coded (Active, Inactive, Draft)

Control Attributes

Three attribute cards are displayed on the control detail page. Click each card to open a modal and select a value:

  • Category — options: Preventive, Detective, Corrective

  • Type — options: Manual, Automated, Hybrid

  • Effectiveness — effectiveness levels with colour badges (e.g. Effective = green)

Attribute values persist across page reloads and are displayed with their colours.

Linked Risks

The linked risks section shows risks connected to this control:

  • Each entry shows the risk title, inherent rating, residual rating, and status

  • Click Link Risks to open a modal showing available (unlinked) risks

  • Select a risk and save — the linked risk count increments

  • Click unlink on a risk to remove the link (the risk itself is not deleted)

Evidence Sources

Evidence sources document the proof that a control is operating effectively:

Quick Steps

  • Open a control detail page

  • Locate the Evidence Sources section

  • Click Add Evidence Source

  • Enter a title, description, and source type (e.g. "External URL", "Linked Activity")

  • Save — the new evidence source appears in the list

You can also:

  • Edit — click on an evidence source to open the modal pre-filled with existing data

  • Delete — click delete and confirm. The linked document or activity is not deleted.

  • Link an activity — select "Linked Activity" as the source type and search for a process activity

Assurance Recording

You can record assurance results to track whether a control is operating as intended:

  • Click Record Assurance

  • Enter a date, result (e.g. "Effective", "Ineffective"), and notes

  • Save — the assurance record appears in the history list

Assurance history is ordered by date descending — the most recent record is visually highlighted (bold, badge, or background colour).

Review Cycle

  • The review field shows the current review date and cycle

  • Click the review date field to open the review modal

  • Set a cycle (e.g. "Quarterly") and save

  • The next review date is auto-calculated

Sign-Off

When a review is due, a sign-off button appears:

  • Click sign-off to record the review

  • The next review date advances based on the cycle

  • The sign-off appears in the review history

Ineligible users will see the button disabled or hidden.

Activation

  • Activate — requires title, description, category, and type. Validation errors appear if required fields are missing.

  • Deactivate — changes status to Inactive. Control data is not deleted.

Current Task Card

The overview panel displays a current task card showing:

  • Task title, due date, assigned to, status chip, timing chip

  • A View task button to open the task sidebar

  • For Draft controls: "Scheduled after activation"

Further Information

For health indicators, see Control Health. For the control summary table, see Managing Controls. For linking risks, see also Risk Details.

Did this answer your question?