Appearance
Create and Manage Controls
This guide explains how to create and manage internal controls in the Control Register (/controls).
Creating a New Control
- Navigate to Controls & Assurance > Control Register (
/controls). - Click the + New Control button in the top-right corner.
- Complete the required fields:
- Control Title: A concise, descriptive name (e.g., Multi-Factor Authentication on External Access).
- Operational Description: Detailed steps describing how the control is performed.
- Control Domain: E.g., Access Control, Data Protection, Network Security.
- Control Type: Preventive, Detective, or Corrective.
- Implementation: Automated, Semi-Automated, or Manual.
- Control Owner: Assign the user or team responsible for maintaining the control.
- Click Create Control. The system automatically issues a unique business reference (e.g.,
CTL-2026-0014).
Managing Control Details & Mappings
- In the Control Register table, click on any control row to open its slide-over drawer.
- In the drawer:
- Metadata Tab: Edit description, owner, domain, or operational status.
- Mapped Obligations: View or add crosswalk links to regulatory requirements.
- Evidence Tab: Inspect attached evidence artifacts and freshness status.
- Testing & Assessments: Review design adequacy and operating effectiveness test records.
- Audit Trail: View chronological history of updates and sign-offs.