Core workflows

Monitor control health and run control reviews

Know which controls are healthy, which need attention and which are overdue a review — with a scheduled cadence and an approval trail behind every verdict.

7 min read · updated July 2026

Step-by-step

  1. 1

    Open Control health

    From the sidebar choose Control health. The KPI strip shows how many controls are healthy, need attention, are failing or have never been assessed, plus an overall health score and the count of overdue reviews.

    Health states, review cadence and overdue reminders in one register.
    Health states, review cadence and overdue reminders in one register.
  2. 2

    Schedule a review cadence

    Click Schedule on any control and pick a frequency and next review date. Critical controls (access management, backups, logging) work well monthly or quarterly; documentation-style controls annually.

  3. 3

    Log a review

    Click Log review, choose the health verdict, add what you tested and what you found, and attach or reference the evidence you looked at. Admins can approve the review to lock it into the history.

  4. 4

    Work the reminders tab

    The Reminders tab lists everything overdue or due soon so a weekly 15-minute pass keeps the whole register current instead of a pre-audit scramble.

  5. 5

    Read the review history

    The Review history tab is the timeline of every verdict logged, by whom and when — this is the artefact that proves ongoing monitoring rather than a point-in-time snapshot.

  6. 6

    Export for the audit file

    Export gives you the full register as CSV with health, cadence, last and next review dates and owners.

What corporate buyers look for
  • "How do you monitor whether controls are operating effectively between audits?"
  • "What is your review cadence for critical controls?"
  • "Who signs off that a control is working, and where is that recorded?"

What this workflow produces: A control health register plus dated review records — the closest thing to continuous assurance you can show before a Type 2 report exists.

FAQ

What is the health score?

The percentage of applicable controls that have been assessed and are currently Healthy. It rises as you work through the register.

How often should I review controls?

Risk-based: monthly or quarterly for controls that protect your most sensitive data, annually for lower-impact ones. Certification auditors expect a defined, followed cadence.

Who can approve a review?

Owners and admins. Members can log a review; approval is the second pair of eyes auditors like to see.

Does this replace internal audit?

No. Control health is continuous monitoring; internal audit is a periodic independent check. ISO 27001 expects both.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation