Skip to main content

Assigning and completing reviews

Reviews capture formal sign-off on the things you need someone to check and approve: controls, policies, documents, risk assessments, and tests. Each review is raised, assigned to a reviewer, and closed with a decision.

Written by Taylor Laing

Open Reviews from the admin sidebar → Reviews (/app/reviews).

Reviews are broader than controls: The Reviews page is not just for control effectiveness. Anything reviewable in ReFresh flows through here.

What can be reviewed

A review can apply to any of these:

  • Control

  • Policy

  • Document

  • Risk assessment

  • Test

Opening Reviews

Go to Reviews in the admin sidebar. The page has two tabs:

  • My Reviews: reviews assigned to you

  • All Reviews: every review in your organisation

What each review row shows

Column

Meaning

Title

The item being reviewed and a short note on why the review was raised

Type

Control, Policy, Document, Risk assessment, or Test

Requested

When the review was raised

Due date

When a decision is required by

Click any row to open the review.

Completing a review

Opening a review shows the item in a review view, with a banner at the top carrying the requestor's notes. A review moves through Pending → In Progress → Completed (or Cancelled).

Record your decision as one of the following outcomes:

  • Approved: the item meets requirements

  • Rejected: the item does not meet requirements

  • Approved with conditions: accepted, subject to the conditions you note

  • Changes requested: sent back with feedback for rework

How control effectiveness is re-rated

Control effectiveness is confirmed through Reviews rather than edited ad hoc. When a control's review comes due (or is triggered), completing that review is where its effectiveness is re-rated.

Effectiveness is not the same as status: A control's status (Overdue / Due Soon / Incomplete / Complete / Deactivated) tells you whether the required evidence is in place and current. Its effectiveness (Effective / Partially Effective / Ineffective / Not Assessed) tells you whether the control is actually working, and that judgement is made by a person, through a review.

When reviews are triggered

A review can be raised from several triggers:

  • Periodic: on the item's renewal or review cadence

  • Version change: when a new version of a policy or document is published

  • Incident: raised after an incident or investigation, for example to re-rate a control's effectiveness

  • Manual: raised by a user on demand

  • Initial setup: raised when an item is first set up and needs its first review

Did this answer your question?