Assess controls
Assessing is the core loop: for each control in an activated framework, you record a compliance status, attach the evidence behind it, and move on. The Assessments module is built around that loop, with AI assistance that suggests verdicts and a score that always shows its arithmetic.
Pick a framework
On the Assessments page, open the Assessments tab and its Controls sub-tab, then use the Select Framework dropdown. Only frameworks you have activated in the Frameworks module appear here. Once you choose one, the control worklist loads along with four stat cards: Total controls, Assessment coverage, Compliance rate, and Control-backed.
The worklist is grouped by framework section. Expand a section to see its control cards, use the search box and the status filter to narrow the list, or Expand All / Collapse All to move quickly.
Set each control's status
Every control card carries a status you set from a fixed vocabulary:
- Not Assessed — the starting state; nobody has looked yet.
- Not Applicable — the control does not apply to your organization.
- Not Compliant and Likely Not Compliant — the control fails, or the evidence points that way.
- Partially Compliant — some of the requirement is met.
- Likely Compliant and Compliant — the evidence supports the control, or confirms it outright.
Alongside the status you can add assessment notes. Every status change lands in an immutable assessment history that records who decided what, when, and by which method, so an auditor can replay how a verdict came to be.
When you set a control to a not-compliant status, SolveGRC automatically emits a signal to the Risk Register. The gap enters your risk workflow without a separate escalation step.
Link the evidence
A verdict without evidence is an opinion. There are three ways to attach proof to a control:
- Link evidence from the control card, which opens a dialog for picking existing evidence or uploading something new.
- Drag an item from the Evidence tab onto a control card. Hold Shift while dropping for an instant quick-link without the dialog.
- Drop a file straight onto a control card to upload, register, and link it in one step.
When newer evidence arrives after a verdict was recorded, that verdict is flagged stale so you know to re-check it rather than trusting an assessment the facts have moved past.
Let AI suggest a verdict
Click AI Analyze on a control and SolveGRC evaluates it against your evidence, then presents a suggested status with its reasoning. The suggestion is advisory: it is never applied automatically. You accept it in one click, or override it from the status dropdown, and if you override a differing AI suggestion you record a reason that goes into the same immutable history.
To score many controls at once, use Bulk Analyze or the Bulk Analysis tab, and track runs under Job History.
The analysis reasons from the evidence linked to your organization. On a control with nothing attached, the honest suggestion is usually that there is nothing to support compliance, so link the obvious evidence first and let the AI do the reading.
How the compliance score reads
Back on the Frameworks page, each active framework shows a compliance score card built for full transparency. Reading top to bottom:
- The headline is the percent of in-scope controls that are compliant. If the number is out of date, a Stale button appears next to it for recomputing on the spot.
- The progress bar shows the same fraction visually, with the counts spelled out beneath it as "n of m in scope", plus how many controls were excluded.
- The exclusion breakdown, behind the info popover, itemizes the scoring denominator: the total assessable controls, minus those marked not applicable, scoped out, or retired, with special dispositions (inherited, partially inherited, compensating) listed separately, and the date the snapshot was computed.
- The exception burden badge summarizes open and expired exceptions weighing on the framework.
- A crosswalk chip appears when controls are satisfied through cross-framework mappings — see Crosswalks.
- A sparkline traces the score's recent trend.
The point of all this disclosure is that the score is never a bare number. You can always answer "out of what?" and "what was left out, and why?"
The dashboards around the worklist
The Assessments page carries more than the worklist. The Compliance Hub tab gives the cross-framework overview, Coverage rolls up how much of each framework is assessed and compliant, Gap Intelligence surfaces your biggest gaps so you can prioritize, and Evidence is the explorer for everything linked to the selected framework's controls, with export.
One control satisfied in one framework can count in others too. Continue to Crosswalks.