For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Explain how a control operates for a specific record, link supporting evidence and distinguish implementation from verification.
Before you start
Identify the control, the asset/process or other entity where it operates, and the person responsible for the evidence. Check that the control already exists before creating another description of the same safeguard.
For example, “access is reviewed quarterly” needs evidence of the relevant review, not just a policy saying reviews should happen.
Record the implementation
- Open the entity where the control applies and its control relationship.
- Edit that relationship. Check whether it is the appropriate relationship type for this entity.
- Set Implementation status to the actual current state. Planned work is not implemented work.
- Record the Rationale and implementation Notes. Explain how the control operates here, the scope it covers and any known limitations.
- Save and reopen the relationship. Verify that you changed this entity's implementation, not merely the shared control's general description.
Add evidence and verify
- Open the control's Linked area. Search the supported evidence types, such as policies, assets, RoPAs, DPIAs and documents.
- Select the exact record or document supporting the claim. Inspect its date, version and access before linking it.
- Explain relevance where the linking controls allow it. A large number of attachments is not a substitute for a clear evidential chain.
- Where you have verification authority, open Verify control, select the supporting evidence and record useful notes.
- Select Verify with evidence, then read the resulting verification state. Where the control is subject to an entity-specific application review, complete that review with its own tested outcome and evidence.
Check it worked
Reopen the control and the entity relationship. Confirm implementation status, linked evidence and verification are all visible and refer to the intended scope. The overview's implementation summary may still show other entities as planned or needing verification.
If something goes wrong
| Problem | Next action |
|---|---|
| Evidence is absent from search | Check supported type, organisation and your access to the source |
| Control is implemented but needs verification | Arrange the required check; do not alter status just to remove the warning |
| One entity's evidence is being reused elsewhere | Check that the same evidence genuinely covers both implementations |
| Evidence becomes stale | Add current evidence and conduct a fresh review, preserving the earlier record |
Human judgement matters
A linked document can describe a control without proving it is operating. Verification must reflect what was checked and by whom.
What next?
For the wider context, see Manage policies, controls and frameworks.
Map the organisation control to the applicable framework requirement, keeping operational evidence separate from the framework's wording.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.