New: Norrsent Copilot for better risk identification and mitigation planning

Platform

Design, assign, and track controls across your risk programme

Norrsent's Controls module lets you build a reusable control library aligned to your policies, ISO standards, or regulatory requirements — and link those controls directly to the risks and mitigation strategies they govern.

How it works

01

Build your library

Create a reusable library of controls categorised by type, risk domain, and standard. Controls can be applied across multiple risks and business units without duplication.

02

Map to risks

Link controls to specific risks, obligations, and mitigation strategies. See at a glance which risks have adequate controls and which carry residual exposure.

03

Test and evidence

Schedule control testing, capture results, and store evidence with full timestamped audit trail. Automated reminders ensure nothing is left untested.

Key capabilities

Centralised control library

Build and maintain a reusable library of controls categorised by type, risk domain, and applicable standard. Controls are version-controlled and linkable across the entire risk programme.

Control-to-risk traceability

Link every control to the risks, obligations, and mitigation plans it governs. Full traceability means auditors can follow the line from regulatory requirement to evidence in seconds.

Effectiveness monitoring

Set review schedules, define effectiveness criteria, and capture test results for every control. Automated reminders ensure controls are tested on time and results recorded consistently.

Evidence management

Attach control evidence — documents, test results, sign-offs — directly to each control record. Evidence is versioned, timestamped, and tamper-proof.

Gap identification

Identify risks without adequate controls and obligations without coverage. Norrsent surfaces control gaps so your team can prioritise remediation before an audit or incident exposes the weakness.

Audit-ready at all times

Every control action — creation, update, test, sign-off — is logged with an immutable audit trail. Regulators and internal auditors have everything they need, on demand.

Get started

See how Controls works in Norrsent