Controls that stay current
Tenant-wide controls with effectiveness assessed across two dimensions, currency that flags itself when it lapses, evidence kept in order, and a clear line to the risks they mitigate.
Start free trialControls as first-class, tenant-wide objects
Controls live outside risk registers and can support many risks at once — a single control mitigating risks across different parts of the organisation. Each control is defined with a structured pattern, sits in a category, moves through a lifecycle, and has a scope. The result is a control library that is consistent, searchable, and defensible when someone asks how a risk is being managed.
Structured, consistent, defensible
Controls are described with discrete fields for who performs or owns the control, what it does, where and when it operates, and why it exists. Every field is optional — the structure is there to support clarity, not to gate the control behind mandatory data entry.
Each control carries a mandatory category drawn from your tenant-managed, hierarchical category structure, and a lifecycle state — draft, active, or retired. Edits happen in place and are audited. Retired controls stay on the record for history; they can't be quietly reactivated.

Two dimensions, two perspectives
Effectiveness is assessed across design and operating effectiveness, independently. For each, you can hold both a self-assessment and an independent assessment, using the same qualitative scale — not assessed, ineffective, partially effective, effective.
Where a self-assessment and an independent assessment disagree, both stand side by side. There is no forced reconciliation: the difference is the signal, and surfacing it honestly is more useful than papering over it. Every assessment records its value, date, who made it, and an optional comment.

Assessments that flag themselves when they lapse
Your framework sets acceptable assessment age thresholds — separately for self-assessed and independent assessments, and independently for design and operating effectiveness. When an assessment passes its threshold, it is flagged as overdue: clearly in the UI, and highlighted in reports and review contexts. An overdue assessment doesn't invalidate the control — it simply tells you, and the control owner, what needs attention. No chasing a spreadsheet to work out what has gone stale.
Supporting artefacts, kept in order
Attach supporting documents — policies, test results, reports — directly to a control. Evidence is optional by design, tagged from a controlled list defined at framework level, and displayed grouped by tag. Documents are never deleted: when something is no longer current you archive it, which keeps it fully retrievable and out of historical reports' way. Every upload and archive is an auditable event.
Controls in context
Risks
Link controls to the risks they mitigate, many-to-many. When a risk is reviewed, its owner sees current effectiveness, what has changed since last time, and any overdue assessments.
RisksObligations
Map controls to framework requirements with coverage — full, partial, or planned — so your compliance posture comes straight from the controls you already maintain.
ObligationsActions
Raise actions from a control to remediate a weakness or close an evidence gap, with owners and due dates that link back to the control.
ActionsOwned by roles, recorded in full
Controls are owned by roles, with users assigned to those roles — reassignment during staff changes is a role membership change, not a rebuild. Control permissions are independent of risk register permissions, so access to a control follows its category, not the registers it happens to touch. A user without category access sees the control name only.
Every control event is auditable — the record relies on that audit history rather than explicit versioning, a deliberate trade-off that keeps day-to-day editing friction-free while retaining a complete trail of every change.