Control Management guide

Assess, test and improve Controls

Maintain assurance using assessments, reusable tests, test runs, evidence, issues, verification and exceptions.

Control Owner / Assessor Ongoing control assurance Updated 9 September 2026

1. Assess the Control

Use a Control assessment when a formal judgement is needed about the Control's current effectiveness or coverage. Confirm whether the assessment is organisation-wide or tied to a specific Asset context.

2. Run Control tests

Define repeatable tests for the Control and record each execution as a test run. Keep the reusable test definition separate from individual run results so assurance can be compared over time.

  • Record the test purpose and expected result.
  • Run the test against the intended scope.
  • Capture completion status and the result.
  • Attach evidence to the run where it demonstrates what was tested.

3. Link evidence and governance documents to what they prove

Evidence is most useful when its relationship is explicit. Link the item to the organisation Control, assessment or test run it supports rather than relying on a description alone. Keep governance-document links and document expectations separate from evidence where the relationship is about required policy/procedure documentation rather than proof of a particular test or assessment.

Evidence is not a status. A document, screenshot or test artefact can support a judgement, but the Control assessment or test result records the assurance conclusion.

4. Manage Control issues and Risk relationships

Create issues when assurance identifies a gap. Record severity, owner, due date and status, then follow the issue through remediation and verification. Link the Control to relevant Risk Register records for traceability when the safeguard is intended to treat or monitor a Risk; the relationship does not silently rewrite the Risk assessment.

5. Use exceptions and compensating Controls

Where the intended Control cannot be implemented as designed, use the Control exception workflow and identify a compensating Control where appropriate. A Control exception is separate from a Risk exception, although it can be linked to Risk context.

6. Verify closure

Do not close an issue simply because remediation was reported complete. Use verification to confirm that the corrective action is operating and that the evidence supports closure.

  • Assessment scope is clear.
  • Test results are retained separately from the test definition.
  • Evidence is linked to the specific assurance activity it supports.
  • Issues have accountable owners and dates.
  • Exceptions and compensating Controls are documented where required.
  • Closure is supported by verification.

Common problems

Evidence exists but the Control still appears weak

Confirm that the evidence is linked to the correct Control, assessment or test run and that an assurance conclusion has actually been recorded.

An Asset status does not match the organisation status

This can be valid. Asset-level implementation and organisation-level implementation are separate views and should be reviewed in their own scope.

A gap needs Risk escalation

Link the Control issue or exception to the appropriate Risk workflow rather than changing the Control record to represent enterprise risk.