Assess a control
Record a control assessment — a dated, signed answer to five questions about a control — and review the assessments already on record. Assessments build the evidence trail that regulatory frameworks ask for: proof that controls are reviewed regularly.
An assessment is a text record only: it doesn't change the control's rating or any risk values. To review how a control actually remediates risk and adjust its rating, see Test control effectiveness.
Prerequisites
- The Control Assessment Tab Early Access feature, enabled by an administrator under Admin → Server Settings → Early Access.
- A PRC (Performance, Risk and Control) license.
- Item role permissions, configured under Admin → Security Roles → Item Roles: with View on the control you see the Assessment tab and the assessments you created yourself; View Control Assessments also shows you other users' assessments; Add Control Assessments lets you record new ones. View Control Assessments is off for all roles by default. (On upgrade to 19.19.0, roles that had Add Risk Data were granted Add Control Assessments automatically.)
Steps
Add an assessment
- Open a Control or Control Instance and select the Assessment tab.
- Select the + icon at the top of the Control assessments area.
- Answer the five Yes/No questions — all five are required:
- Is this control present and is the description an accurate representation of the control?
- Is this control appropriate for the risk?
- Is this control an effective mitigation for the risk?
- Can this control be proven to be effective?
- Can this control be optimized in any way?
- Optionally add a Reason for any answer.
- Click Save, or Cancel to discard the assessment.

Review assessments
Every assessment you have rights to see is listed on the same tab, collapsed by default — expand one, or use the expand-all icon next to the + icon to open them all. Each shows when it was completed and by whom; if the user is mapped to a resource, the resource's name is shown instead of the user's.
- Sort with the sort icon: Name (A - Z), Name (Z - A), Newest first, or Oldest first.
- Filter with the filter icon, by Assessor name or by year; the choices offered come from the assessments you can see.
To review assessments across the whole repository instead of one control at a time, a user with the Manage Control Configuration permission can download them as a spreadsheet — see Download an assessment report.

Limitations
- Assessments are a historical record: once saved, they can't be edited or deleted — in the product or through the API. To correct one, record a new assessment.
Related
- Test control effectiveness
- Risks and controls
- Residual risk calculation — how the control's rating (a separate setting) mitigates risk values
- Control and Control Instance configuration