Skip to main content

Assess controls

Assessing is the core loop: for each control in an activated framework, you record a compliance status, attach the evidence behind it, and move on. The Assessments module is built around that loop, with AI assistance that suggests verdicts and a score that always shows its arithmetic.

Pick a framework

On the Assessments page, open the Assessments tab and its Controls sub-tab, then use the Select Framework dropdown. Only frameworks you have activated in the Frameworks module appear here. Once you choose one, the control worklist loads along with four stat cards: Total controls, Assessment coverage, Compliance rate, and Control-backed.

ScreenshotThe Assessments Controls sub-tab: the Select Framework dropdown above the four stat cards (Total controls, Assessment coverage, Compliance rate, Control-backed) and the sectioned control worklist.

The worklist is grouped by framework section. Expand a section to see its control cards, use the search box and the status filter to narrow the list, or Expand All / Collapse All to move quickly.

Set each control's status

Every control card carries a status you set from a fixed vocabulary:

  • Not Assessed — the starting state; nobody has looked yet.
  • Not Applicable — the control does not apply to your organization.
  • Not Compliant and Likely Not Compliant — the control fails, or the evidence points that way.
  • Partially Compliant — some of the requirement is met.
  • Likely Compliant and Compliant — the evidence supports the control, or confirms it outright.

Alongside the status you can add assessment notes. Every status change lands in an immutable assessment history that records who decided what, when, and by which method, so an auditor can replay how a verdict came to be.

Gaps become risks on their own

When you set a control to a not-compliant status, SolveGRC automatically emits a signal to the Risk Register. The gap enters your risk workflow without a separate escalation step.

A verdict without evidence is an opinion. There are three ways to attach proof to a control:

  • Link evidence from the control card, which opens a dialog for picking existing evidence or uploading something new.
  • Drag an item from the Evidence tab onto a control card. Hold Shift while dropping for an instant quick-link without the dialog.
  • Drop a file straight onto a control card to upload, register, and link it in one step.

When newer evidence arrives after a verdict was recorded, that verdict is flagged stale so you know to re-check it rather than trusting an assessment the facts have moved past.

Let AI suggest a verdict

Click AI Analyze on a control and SolveGRC evaluates it against your evidence, then presents a suggested status with its reasoning. The suggestion is advisory: it is never applied automatically. You accept it in one click, or override it from the status dropdown, and if you override a differing AI suggestion you record a reason that goes into the same immutable history.

To score many controls at once, use Bulk Analyze or the Bulk Analysis tab, and track runs under Job History.

ScreenshotA control card after AI Analyze: the suggested status with its reasoning, the one-click accept, and the status dropdown for overriding.
Feed the AI before you ask it

The analysis reasons from the evidence linked to your organization. On a control with nothing attached, the honest suggestion is usually that there is nothing to support compliance, so link the obvious evidence first and let the AI do the reading.

How the compliance score reads

Back on the Frameworks page, each active framework shows a compliance score card built for full transparency. Reading top to bottom:

  • The headline is the percent of in-scope controls that are compliant. If the number is out of date, a Stale button appears next to it for recomputing on the spot.
  • The progress bar shows the same fraction visually, with the counts spelled out beneath it as "n of m in scope", plus how many controls were excluded.
  • The exclusion breakdown, behind the info popover, itemizes the scoring denominator: the total assessable controls, minus those marked not applicable, scoped out, or retired, with special dispositions (inherited, partially inherited, compensating) listed separately, and the date the snapshot was computed.
  • The exception burden badge summarizes open and expired exceptions weighing on the framework.
  • A crosswalk chip appears when controls are satisfied through cross-framework mappings — see Crosswalks.
  • A sparkline traces the score's recent trend.
ScreenshotThe compliance score card: percent-compliant headline, progress bar with the 'n of m in scope' count, exclusion popover open showing the denominator breakdown, the crosswalk-satisfied chip, and the trend sparkline.

The point of all this disclosure is that the score is never a bare number. You can always answer "out of what?" and "what was left out, and why?"

The dashboards around the worklist

The Assessments page carries more than the worklist. The Compliance Hub tab gives the cross-framework overview, Coverage rolls up how much of each framework is assessed and compliant, Gap Intelligence surfaces your biggest gaps so you can prioritize, and Evidence is the explorer for everything linked to the selected framework's controls, with export.


One control satisfied in one framework can count in others too. Continue to Crosswalks.