Appearance
Controls & Assurance
This domain covers what your organisation actually does about its obligations, and how you know it is working.
In the application it spans the Controls & Assurance navigation domain: Control Register, Control Crosswalk, Control Assessment, Evidence Register, Evidence Fabric and Continuous Assurance.
The shape of the domain
Controls
| Article | What it covers |
|---|---|
| Control Register | The canonical register: fields, statuses, ownership, lifecycle |
| Control Sources | Turning policy and procedure documents into candidate controls |
| Common Control Layer | Control elements: the individually mappable clauses inside a control |
| Control Assessment | Design assessment, operating effectiveness and control testing |
| Design Adequacy | Governed assessment of whether an approved mapping is adequate by design |
Crosswalk
| Article | What it covers |
|---|---|
| Crosswalk Overview | What a mapping record is and what it asserts |
| Relationship Types | The eight semantic relationships, with worked examples |
| Crosswalk Lifecycle | Propose, review, approve, adjust, retire, and versioning |
| Crosswalk Import | Importing external catalogues as governed proposals |
| AI Mapping Suggestions | Discovery and AI proposal, and their strict limits |
| Historical Crosswalk | Point-in-time reconstruction of the mapping estate |
Evidence
| Article | What it covers |
|---|---|
| Evidence Register | Manual evidence: upload, link, review |
| Evidence Fabric | The whole evidence graph and how its pieces relate |
| Evidence Connections | External source connections |
| Collectors | Automated collection definitions and runs |
| Evidence Assertions | The atomic observation record |
| Expected Evidence & Freshness | What should exist, by when, and what happens when it goes stale |
Assurance
| Article | What it covers |
|---|---|
| Continuous Assurance | The deterministic assurance layer as a whole |
| Indicators | Indicator definitions, rules, results and scheduling |
| Control Effectiveness | How effectiveness is derived, and mandatory failure gating |
Entitlements
| Capability | Entitlement |
|---|---|
| Control register, crosswalk, assessment, manual evidence | control_assurance |
| Evidence Fabric connections, collectors, indicators, automated assurance | continuous_assurance |
| AI proposals and AI-suggested expected evidence | ai_risk_intelligence |
Core GRC works without Continuous Assurance
With the Continuous Assurance entitlement off, the control register, crosswalk, manual evidence, evidence links and manual control assessments all continue to work in full. Continuous Assurance adds automated telemetry; it is not a prerequisite for governed compliance.
Who works in this domain
| Role | Typical work |
|---|---|
| Control owner (Line 1) | Maintaining controls, providing evidence, responding to indicator failures |
| Compliance Analyst | Proposing mappings, defining expected evidence, gathering evidence |
| Compliance Manager | Reviewing and approving mappings, reviewing assessments |
| Security or IT Operations | Configuring connections and collectors |
| Internal Auditor | Testing controls, reviewing assurance evidence |
Related domains
- Regulatory & Compliance — the obligations controls address
- Risk & Remediation — what happens when controls fail
- Audit & Oversight — independent testing of controls