Skip to main content

Assess controls

Assessing is the core loop: for each control in an activated framework, you record a compliance status, attach the evidence behind it, and move on. The Assessments module is built around that loop, with AI assistance that suggests verdicts and a score that always shows its arithmetic.

Pick a framework

On the Assessments page, open the Assessments tab and its Controls sub-tab, then use the Select Framework dropdown. Only frameworks you have activated in the Frameworks module appear here. Once you choose one, the control worklist loads along with four stat cards: Total controls, Assessment coverage, Compliance rate, and Control-backed.

The Assessments Controls sub-tab with the Select Framework dropdown, four stat cards, and the sectioned control worklist
The Assessments Controls sub-tab: the Select Framework dropdown above the four stat cards (Total controls, Assessment coverage, Compliance rate, Control-backed), and the control worklist grouped by requirement section.

The worklist is grouped by framework section. Expand a section to see its control cards, use the search box and the status filter to narrow the list, or Expand All / Collapse All to move quickly.

Set each control's status

Every control card carries a status you set from a fixed vocabulary:

  • Not Assessed — the starting state; nobody has looked yet.
  • Not Applicable — the control does not apply to your organization.
  • Not Compliant and Likely Not Compliant — the control fails, or the evidence points that way.
  • Partially Compliant — some of the requirement is met.
  • Likely Compliant and Compliant — the evidence supports the control, or confirms it outright.

Alongside the status you can add assessment notes. Every status change lands in an immutable assessment history that records who decided what, when, and by which method, so an auditor can replay how a verdict came to be.

Gaps become risks on their own

When you set a control to a not-compliant status, SolveGRC automatically emits a signal to the Risk Register. The gap enters your risk workflow without a separate escalation step.

A verdict without evidence is an opinion. There are three ways to attach proof to a control:

  • Link evidence from the control card, which opens a dialog for picking existing evidence or uploading something new.
  • Drag an item from the Evidence tab onto a control card. Hold Shift while dropping for an instant quick-link without the dialog.
  • Drop a file straight onto a control card to upload, register, and link it in one step.

When newer evidence arrives after a verdict was recorded, that verdict is flagged stale so you know to re-check it rather than trusting an assessment the facts have moved past.

Let AI suggest a verdict

Click AI Analyze on a control and SolveGRC evaluates it against your evidence, then presents a suggested status with its reasoning. The suggestion is advisory: it is never applied automatically. You accept it in one click, or override it from the status dropdown, and if you override a differing AI suggestion you record a reason that goes into the same immutable history.

To score many controls at once, use Bulk Analyze or the Bulk Analysis tab, and track runs under Job History.

An expanded control card with its status dropdown, AI-analyze action, implementation guidance, linked evidence, and assessment notes
An expanded control card: the control text, the status dropdown you set (Not Assessed here), the AI-analyze action beside it, and sections for implementation guidance, linked evidence, and assessment notes.
Feed the AI before you ask it

The analysis reasons from the evidence linked to your organization. On a control with nothing attached, the honest suggestion is usually that there is nothing to support compliance, so link the obvious evidence first and let the AI do the reading.

How the compliance score reads

Back on the Frameworks page, each active framework shows a compliance score card built for full transparency. Reading top to bottom:

  • The headline is the percent of in-scope controls that are compliant. If the number is out of date, a Stale button appears next to it for recomputing on the spot.
  • The progress bar shows the same fraction visually, with the counts spelled out beneath it as "n of m in scope", plus how many controls were excluded.
  • The exclusion breakdown, behind the info popover, itemizes the scoring denominator: the total assessable controls, minus those marked not applicable, scoped out, or retired, with special dispositions (inherited, partially inherited, compensating) listed separately, and the date the snapshot was computed.
  • The exception burden badge summarizes open and expired exceptions weighing on the framework.
  • A crosswalk chip appears when controls are satisfied through cross-framework mappings — see Crosswalks.
  • A sparkline traces the score's recent trend.
An expanded framework's compliance score card above its Framework Controls tree
The compliance score card: the percent-compliant headline, the 'n of m in scope' progress bar, the 'satisfied via crosswalk / evidenced' chip, and the trend sparkline — above the Framework Controls tree that lists every requirement.

The point of all this disclosure is that the score is never a bare number. You can always answer "out of what?" and "what was left out, and why?"

The dashboards around the worklist

The Assessments page carries more than the worklist. The Compliance Hub tab gives the cross-framework overview, Coverage rolls up how much of each framework is assessed and compliant, Gap Intelligence surfaces your biggest gaps so you can prioritize, and Evidence is the explorer for everything linked to the selected framework's controls, with export.

Track what falls short

Marking a control non-compliant records a verdict. It doesn't record what's wrong, how bad it is, or who is fixing it — that's what the Findings tab on the Frameworks page is for.

A finding is a control deficiency, gap, or non-compliance observation, carrying:

  • a severity, so a missing log retention policy and an unencrypted database aren't treated as equals,
  • a lifecycle, so it moves from open through remediation to closed rather than living forever in someone's spreadsheet,
  • and links to the remediation work, so the fix is traceable to the gap.

The Findings Overview breaks the active set down by status and severity, which is the fastest read on whether your open gaps are getting older or getting handled.

A finding is a good sign, not a bad one

An auditor is far more reassured by "we found it, rated it, and here's the remediation" than by a control sheet with nothing on it. A program with zero findings is usually a program that isn't looking — a clean sheet and an unexamined one are indistinguishable from outside.


One control satisfied in one framework can count in others too. Continue to Crosswalks.