The control detail page summarises evidence status, effectiveness, review state, and active frameworks at the top.
Category, requirement level, hierarchy level, renewal cadence, and deactivation rules sit below the description.
Status reflects whether evidence is current: Overdue / Due Soon / Incomplete / Complete / Deactivated.
Renewal frequency drives the schedule for keeping evidence up to date.
Tabs on each control cover its Records (evidence), consultations, risk scenarios, tasks, comments, and activity log.
Opening a control
From /app/controls, click any row (for example, GOV-14). The control detail page opens.
Top-level cards
A row of cards runs across the top of the control:
Evidence Status: a count of evidence items required versus in place, with the control's current status.
Effectiveness: the current effectiveness rating, with the last and next effectiveness review dates. This is set by a person through a Review, not calculated from evidence. See Control effectiveness.
Review: the current review state; use this to request sign-off. See Assigning and completing reviews.
Frameworks: which active frameworks this control satisfies.
Status vs effectiveness: two different things: Status answers "is the evidence present and current?" and is calculated automatically. Effectiveness answers "is this control actually working?" and is a human judgement recorded through a Review. A control can be Complete on status and still be rated Partially Effective, or even Not Assessed for effectiveness. Keep the two separate when you report on your program. See Control effectiveness.
Description and metadata
Below the cards, the Description explains the control and the evidence it expects. Beneath it, a set of fields summarise the control's metadata:
Field | Meaning |
Category | The control's category (for example, governance, job design, policies, training, environment) |
Requirement Level | Whether the control is mandatory or optional under its frameworks |
Hierarchy Level | Where the control sits on the Hierarchy of Controls (Elimination, Substitution, Engineering, Administrative, Personal) |
Renewal | How often evidence should be refreshed (for example, Yearly, Quarterly, Monthly, Ongoing) |
Deactivation | Whether the control can be deactivated, and under what conditions. Some controls are mandatory and can't be deactivated |
The control's owner is assigned from the detail page. Set an owner so responsibility for keeping the control evidenced and current is clear.
What each status means
The status badge reflects the control's current state:
Complete: all required evidence is in place and current.
Incomplete: required evidence is missing or still in draft. (The dashboard's "Next controls to address" list shows this same state as a Needs Evidence badge.)
Due Soon: evidence is approaching its expiration date (within about 30 days).
Overdue: evidence has passed its expiration date.
Deactivated: the control has been switched off and is no longer contributing to your completion.
Where several conditions apply, the most urgent status wins.
Renewal frequency
The renewal frequency drives the schedule for keeping evidence up to date. For a control set to Yearly renewal:
Evidence added today is valid for 12 months.
Status moves to Due Soon as the expiration date approaches.
Status moves to Overdue once the expiration date passes.
Set the renewal cadence to match how often the underlying activity should genuinely be reviewed in your organisation.
Evidence on the control detail page
The control's evidence is organised into three sections: Documents, Policies, and Tests. This is where you add and manage the records that prove the control is in place; see Adding evidence to a control (Records). The detail page also gathers the control's linked consultations, the risk scenarios it mitigates, its tasks, comments, and a time-stamped activity log.
