Assess controls
Assessing is the core loop: for each control in an activated framework, you record a compliance status, attach the evidence behind it, and move on. The Assessments module is built around that loop, with AI assistance that suggests verdicts and a score that always shows its arithmetic.
Pick a framework
On the Assessments page, open the Assessments tab and its Controls sub-tab, then use the Select Framework dropdown. Only frameworks you have activated in the Frameworks module appear here. Once you choose one, the control worklist loads along with four stat cards: Total controls, Assessment coverage, Compliance rate, and Control-backed.

The worklist is grouped by framework section. Expand a section to see its control cards, use the search box and the status filter to narrow the list, or Expand All / Collapse All to move quickly.
Set each control's status
Every control card carries a status you set from a fixed vocabulary:
- Not Assessed — the starting state; nobody has looked yet.
- Not Applicable — the control does not apply to your organization.
- Not Compliant and Likely Not Compliant — the control fails, or the evidence points that way.
- Partially Compliant — some of the requirement is met.
- Likely Compliant and Compliant — the evidence supports the control, or confirms it outright.
Alongside the status you can add assessment notes. Every status change lands in an immutable assessment history that records who decided what, when, and by which method, so an auditor can replay how a verdict came to be.
When you set a control to a not-compliant status, SolveGRC automatically emits a signal to the Risk Register. The gap enters your risk workflow without a separate escalation step.
Link the evidence
A verdict without evidence is an opinion. There are three ways to attach proof to a control:
- Link evidence from the control card, which opens a dialog for picking existing evidence or uploading something new.
- Drag an item from the Evidence tab onto a control card. Hold Shift while dropping for an instant quick-link without the dialog.
- Drop a file straight onto a control card to upload, register, and link it in one step.
When newer evidence arrives after a verdict was recorded, that verdict is flagged stale so you know to re-check it rather than trusting an assessment the facts have moved past.
Let AI suggest a verdict
Click AI Analyze on a control and SolveGRC evaluates it against your evidence, then presents a suggested status with its reasoning. The suggestion is advisory: it is never applied automatically. You accept it in one click, or override it from the status dropdown, and if you override a differing AI suggestion you record a reason that goes into the same immutable history.
To score many controls at once, use Bulk Analyze or the Bulk Analysis tab, and track runs under Job History.

The analysis reasons from the evidence linked to your organization. On a control with nothing attached, the honest suggestion is usually that there is nothing to support compliance, so link the obvious evidence first and let the AI do the reading.