Featured guide
Create and assess a risk
Learn how to complete CIA and FAIR assessments, add controls, assign treatment actions and manage risk exceptions.
Read the guideMaintain assurance using assessments, reusable tests, test runs, evidence, issues, verification and exceptions.
Use a Control assessment when a formal judgement is needed about the Control's current effectiveness or coverage. Confirm whether the assessment is organisation-wide or tied to a specific Asset context.
Define repeatable tests for the Control and record each execution as a test run. Keep the reusable test definition separate from individual run results so assurance can be compared over time.
Evidence is most useful when its relationship is explicit. Link the item to the organisation Control, assessment or test run it supports rather than relying on a description alone. Keep governance-document links and document expectations separate from evidence where the relationship is about required policy/procedure documentation rather than proof of a particular test or assessment.
Create issues when assurance identifies a gap. Record severity, owner, due date and status, then follow the issue through remediation and verification. Link the Control to relevant Risk Register records for traceability when the safeguard is intended to treat or monitor a Risk; the relationship does not silently rewrite the Risk assessment.
Where the intended Control cannot be implemented as designed, use the Control exception workflow and identify a compensating Control where appropriate. A Control exception is separate from a Risk exception, although it can be linked to Risk context.
Do not close an issue simply because remediation was reported complete. Use verification to confirm that the corrective action is operating and that the evidence supports closure.
Confirm that the evidence is linked to the correct Control, assessment or test run and that an assurance conclusion has actually been recorded.
This can be valid. Asset-level implementation and organisation-level implementation are separate views and should be reviewed in their own scope.
Link the Control issue or exception to the appropriate Risk workflow rather than changing the Control record to represent enterprise risk.