Skip to content

Create and Manage Controls

This guide explains how to create and manage internal controls in the Control Register (/controls).


Creating a New Control

  1. Navigate to Controls & Assurance > Control Register (/controls).
  2. Click the + New Control button in the top-right corner.
  3. Complete the required fields:
    • Control Title: A concise, descriptive name (e.g., Multi-Factor Authentication on External Access).
    • Operational Description: Detailed steps describing how the control is performed.
    • Control Domain: E.g., Access Control, Data Protection, Network Security.
    • Control Type: Preventive, Detective, or Corrective.
    • Implementation: Automated, Semi-Automated, or Manual.
    • Control Owner: Assign the user or team responsible for maintaining the control.
  4. Click Create Control. The system automatically issues a unique business reference (e.g., CTL-2026-0014).

Managing Control Details & Mappings

  1. In the Control Register table, click on any control row to open its slide-over drawer.
  2. In the drawer:
    • Metadata Tab: Edit description, owner, domain, or operational status.
    • Mapped Obligations: View or add crosswalk links to regulatory requirements.
    • Evidence Tab: Inspect attached evidence artifacts and freshness status.
    • Testing & Assessments: Review design adequacy and operating effectiveness test records.
    • Audit Trail: View chronological history of updates and sign-offs.

OrviQ Enterprise Governance, Risk & Compliance Platform