Controls
The Controls section shows all controls assigned to a third party and their current assessment status. Controls are used to evaluate whether the vendor meets your organization's security and compliance requirements.
Assign Controls
You can assign controls to a third party from the Control Library. You can choose from four different ways to assign controls:
1. AI Recommendation
Let Narad recommend applicable controls based on the third party's profile and details.
This helps you identify relevant controls without having to select them individually.
2. Control Groups
Select from predefined Control Groups that you have created in your Control Library.
This is useful when you regularly apply the same set of controls to a specific type of vendor or assessment.
3. Existing Third Party
Copy controls from another third party that has already been assessed.
This can be useful when two vendors have similar services, risk profiles, or assessment requirements.
4. Control Library
Browse the complete Control Library and manually select the controls you want to assign.
Once assigned, each control can be assessed using the available vendor documents and evidence.
Test Controls
Narad allows you to test selected controls in two ways:
With AI — Narad analyzes the available documents and evidence to determine whether the control requirements are met.
Manually — A user can manually assess the control and record the assessment outcome.
You can select one or multiple controls and choose the appropriate testing method.
Control Status
After testing, each control is assigned an assessment status, such as:
Meet — Available evidence indicates that the control requirement is satisfied.
Do Not Meet — The available evidence does not satisfy the requirement.
Exception — An exception has been raised for the control.
Control Test History
Each control maintains a Test History, allowing you to see how its assessment has changed over time.
The history can include:
Previous assessment results
Whether the assessment was performed manually or with AI
Who performed the assessment
Assessment date
Expiry date, where applicable
Business decision associated with an exception
Rationale for the assessment
Documents and page numbers used as supporting evidence
For AI-based testing, Narad also shows the source document and the relevant pages used to support the assessment.
Change Test Result
The Change Test Result option allows you to update the outcome of a control assessment when the current result needs to be changed or an exception needs to be recorded.
You can change the control status to: Meet, Do Not Meet or Exception
Creating an Exception
When Exception is selected, provide the following information:
Exception Expiry Date — The date when the exception will expire and require review.
Business Decision — Select the decision associated with the exception.
Notification Recipient — The configured user who will be notified about the exception.
Rationale — Explain why the exception was raised and provide relevant context.
Supporting Files — Optionally attach documents supporting the decision.
Why use an Exception?
An exception allows you to formally document a control gap while recording the business decision, rationale, supporting evidence, and review/expiry date.
This creates a clear record of what the gap is, why it was accepted or managed, who was notified, and when it needs to be reviewed again.
Retesting Controls
Controls can be tested again when new evidence becomes available, an existing document is updated, or the previous assessment expires.
This allows the third-party's control status to remain aligned with its latest available evidence.
Why Control Testing Matters
Control testing creates the connection between a vendor's requirements, evidence, and risk assessment.
Once controls have been tested, Narad can identify areas where sufficient evidence is already available and areas where additional information may be required. This information can then be used as part of the questionnaire workflow.
