Key takeaways
- Controls management is no longer just about having controls documented. Boards, regulators, auditors and customers increasingly expect organizations to prove that controls are owned, tested, evidenced, effective and connected to real risk.
- The problem is that many teams still manage controls through spreadsheets, duplicated testing, disconnected evidence and point-in-time reviews. That creates activity, but not always assurance.
- A value-based GRC approach changes the question from “have we completed the control activity?” to “does this control help us achieve the right outcome with confidence?”
- CoreStream GRC’s belief is that controls management should become a connected operating model. Risks, controls, evidence, ownership, remediation and reporting should sit together, so teams can prove what is working, identify what is not and focus effort where it protects business value.
- With SANNOS and the Secure Controls Framework, controls management can move further again: assess once, map across many frameworks, reduce duplicated testing and produce evidence-led outputs that teams can review, defend and act on.
Introduction: why controls management needs to move beyond activity
Most organizations have controls in place. That is not the hard part.
The harder question is whether those controls are effective, current, owned by the right people, supported by evidence and connected to the risks that matter most. This is the proof burden now sitting behind major regulations and frameworks, from ISO 27001 and SOC 2 to NIS2, DORA, GDPR Article 32 and the NIST Cybersecurity Framework. Each may use different language, but the direction is the same: organizations need to show that controls are designed, operating, evidenced and improving.
Traditional controls management often breaks down because it measures activity before value. Teams can spend huge amounts of time documenting, testing and reporting controls without being able to show whether those controls are improving confidence, reducing exposure or supporting strategic outcomes. A spreadsheet might show that a control exists. It does not always show who owns it, when it was last tested, what evidence supports it or whether remediation is moving.
That gap matters as compliance expectations keep rising. PwC’s Global Compliance Survey 2025 found that 85% of respondents said compliance requirements have become more complex in the last 3 years. For controls management, the message is clear: the issue is not a lack of controls. The issue is lack of connected proof.
What is controls management?
Controls management is the process of identifying, owning, testing, evidencing, monitoring and improving the controls an organization uses to manage risk, meet obligations and prove accountability. In practice, that means knowing which controls exist, what they are designed to prevent or detect, who owns them, how they are tested, what evidence supports them and what happens when they fail.
That proof burden now sits behind a growing list of regulations and frameworks. SOX Section 404 requires management to assess internal control over financial reporting. The UK Corporate Governance Code expects boards to monitor risk management and internal control systems. DORA and NIS2 raise expectations around ICT, cyber and operational resilience controls, while GDPR Article 32, ISO 27001, SOC 2 and PCI DSS all require organizations to show that appropriate controls are in place and operating effectively.
A strong controls management process usually includes:
- Process and risk mapping
- Control design and documentation
- Ownership and accountability
- Control testing and self-assessments
- Evidence collection
- Deficiency and remediation tracking
- Attestation and certification
- Reporting and continuous monitoring
But the value does not come from the list itself. The value comes from how well those activities help the business understand whether its controls are actually working. A control library may show what should happen. Strong controls management shows what is happening, where evidence sits, what has changed and where leadership needs to act.
That matters because controls can become difficult to manage quickly. When testing, evidence and remediation sit across spreadsheets, emails and separate systems, it becomes harder to prove control effectiveness with confidence.
This is where effective controls management software should support. It should not just store controls. It should help teams understand control health, effectiveness, ownership and business impact, while giving audit, risk, compliance and the board the connected proof they need.
Why does traditional controls management fall short?
Traditional controls management often creates a false sense of assurance.
A control can be documented but not used. It can be tested but not tied to risk. It can be owned on paper but ignored in practice. It can be reported to leadership without enough evidence to defend the conclusion. That is a problem when frameworks and regulations increasingly expect organizations to prove control design, control operation and control effectiveness. SOX Section 404 focuses on internal control over financial reporting. ISO 27001, SOC 2, PCI DSS, GDPR Article 32, NIS2 and DORA may all come from different regulatory or assurance contexts, but they create the same practical demand: show that controls exist, show that they work and show the evidence behind them.
The common pain points are familiar:
- Controls sit in spreadsheets and shared drives.
- Different teams interpret controls differently.
- Evidence is collected repeatedly.
- Testing cycles are manual and inconsistent.
- Control owners are chased through email.
- Remediation actions are not tracked to closure.
- Reporting is slow, stale or hard to explain.
The risk is that controls management becomes mechanical. Teams complete the task, update the tracker and move to the next review cycle, but no one has a clear view of whether the control environment is getting stronger.
As Nikki Absolom, Tax Technology and Transformation Lead at IVC Evidensia and former Head of Controls at Pets at Home, said in CoreStream GRC’s Spotlight on Women in GRC podcast:
“GRC is still quite siloed. Technology and automation can only help integrate GRC across businesses and make the enterprise risk management piece a whole lot easier.”
Nikki Absolom, Tax Technology and Transformation Lead, IVC Evidensia
That silo problem matters more as risk becomes more connected. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 65% of large companies by revenue cite third-party and supply chain vulnerabilities as their greatest cyber resilience concern. For controls teams, that means assurance cannot stop at a static control list. Leaders need to understand which controls matter, who owns them, what evidence supports them and where gaps could expose the business.
When controls are disconnected, leaders do not have assurance. They have fragments.
How does value-based GRC change the controls conversation?
Value-based GRC shifts the controls conversation from “what controls do we have?” to “what outcomes do these controls protect?”
That shift matters because controls are not valuable simply because they exist. They are valuable when they help an organization achieve objectives, address uncertainty and act with integrity. That reflects the wider definition of GRC set out by OCEG, which frames governance, risk and compliance around reliable performance, risk management and principled conduct.
In controls management, that means moving beyond control inventories and asking whether each control is helping the business make better decisions, reduce exposure and prove accountability. For frameworks such as ISO 27001, SOC 2, DORA, NIS2 and SOX Section 404, the real question is not just whether a control has been recorded. It is whether the organization can show why the control matters, how it operates, what evidence supports it and how gaps are managed.
A value-based controls program should ask:
- Which strategic objective does this control support?
- Which risk does it reduce?
- What evidence proves it is working?
- Who owns it?
- How often is it tested?
- What happens if it fails?
- How does leadership see the result?
In CoreStream GRC’s value-based GRC blog, Paul Cadwallader frames this around 3 areas: business outcomes, transparency and cost effectiveness. That is a useful test for controls management. A control should not only satisfy an audit request. It should help the business understand risk, build trust with stakeholders and use time and resources more effectively.
As Paul puts it,
“Value-based GRC empowers an organization to achieve the right objectives with confidence.”
Paul Cadwallader, GRC Strategy Director
That is where controls management becomes a business enabler. When control activity connects to risk reduction, decision confidence and business performance, teams can move beyond proving that work has been done. They can prove why that work matters.
What does good controls management look like in practice?
Good controls management gives teams a clear view of what exists, what is working, what needs attention and what has changed.
In practice, that means controls are not managed as isolated records. They are mapped to risks, policies, processes, frameworks, testing cycles, evidence and remediation activity. Owners can be assigned. Testing can be scheduled. Evidence can be collected. Deficiencies can be tracked. Dashboards can show control health in real time.
That matters because regulations and frameworks do not just ask organizations to say that controls exist. They increasingly expect organizations to prove that controls are operating effectively. ISO 27001 expects organizations to manage information security controls through an ISMS. SOC 2 reports on controls relevant to trust services criteria. SOX Section 404 requires management assessment of internal control over financial reporting. DORA, NIS2 and GDPR Article 32 all increase the pressure to show that cyber, resilience and security controls are not just written down, but owned, tested and evidenced.
CoreStream GRC helps bring that proof together. Controls can be connected to the risks they reduce, the policies they support, the evidence that proves they are working and the remediation actions needed when gaps appear. That turns controls management from a periodic admin exercise into an ongoing assurance process.
Great Western Railway described the difference clearly:
“The CoreStream system provides us with an amazing single source of truth, not only for what needs doing but also for what’s been done. It evidences it, which was always a problem in the past.”
Read the Great Western Railway case study to see how CoreStream GRC helped replace scattered processes with 1 centralized platform for obligations, evidence and reporting.
The strongest control environments are not necessarily the ones with the most controls. They are the ones with the clearest ownership, evidence and accountability.
Why does control effectiveness matter more than control volume?
More controls do not automatically mean more assurance.
In fact, too many poorly managed controls can create duplication, confusion and unnecessary cost. A large control library can look impressive, but if controls are not mapped to risk, tested consistently, supported by evidence and linked to remediation, the business may still be exposed. The goal is not to create the biggest control inventory. The goal is to understand which controls matter, whether they are designed properly and whether they operate effectively.
That is why control effectiveness matters. Frameworks such as ISO 27001, SOC 2, SOX Section 404, PCI DSS, NIS2 and DORA all push organizations toward the same practical requirement: prove that controls are not only documented, but operating in a way that reduces risk.
The risk landscape makes that distinction harder to ignore. The 2026 Verizon Data Breach Investigations Report shows how quickly threats are moving, while Verizon’s own 2026 DBIR coverage reports that breaches involving a third party now account for 48% of all breaches. Analysis of the same report also found that ransomware was involved in 48% of breaches, reinforcing the point that control environments need to be current, tested and defensible.
Control effectiveness is where value-based GRC becomes practical. It helps teams separate activity from assurance. Instead of asking whether a control exists somewhere in the system, leaders can ask whether it is working, whether it is reducing the right risk and whether the evidence is strong enough to stand up to audit, regulator or board scrutiny.
How can SCF support a stronger controls management model?
The Secure Controls Framework helps organizations manage overlapping requirements through a common controls architecture. Instead of treating every framework as a separate project, SCF gives teams a shared foundation for mapping controls across multiple laws, regulations and standards.
That matters because many frameworks ask for similar evidence in different language. A business may need to prove control coverage across ISO 27001, NIST CSF, DORA, NIS2, PCI DSS, SOC 2, GDPR and customer assurance requirements. If each framework is managed separately, the same control can be tested, evidenced and reported several times.
SCF supports a stronger model: assess once, then understand how that control maps across many obligations. As our GRC guide to SCF explains that SCF consolidates 200+ laws, regulations and frameworks into 1 control architecture, with 1,400+ controls across 33 domains.
Tom Cornelius, co-founder of the Secure Controls Framework, puts the value clearly:
“The SCF makes compliance a natural byproduct of secure and resilient practices. It is the world’s most comprehensive cybersecurity and data privacy metaframework.”
Tom Cornelius, Co-Founder, Secure Controls Framework
For controls management, that changes the operating model. SCF provides the control architecture, while CoreStream GRC helps operationalize that architecture through workflows, ownership, evidence, remediation and reporting. The result is not just better mapping. It is a clearer way to prove which controls support which obligations, where evidence can be reused and where real gaps remain.
To explore this in more detail, register for CoreStream GRC’s upcoming webinar, The Modern CISO’s Compliance Stack: Frameworks, Automation and AI, featuring CoreStream GRC, SANNOS and the Secure Controls Framework.
How does SANNOS AI strengthen controls assessment?
AI can strengthen controls management, but only if the output is explainable, reviewable and evidence-led. Speed alone is not enough. In controls assessment, teams still need to know what evidence was reviewed, how a conclusion was reached, who approved it and what remediation follows.
That is why AI should not replace human accountability in controls management. Its value is in removing the manual drag from evidence review, framework mapping and gap identification, so risk, compliance and audit teams can spend more time interpreting risk, prioritizing remediation and advising the business. That is the difference between automation for speed and automation for value.
Michael Rasmussen explains the shift clearly:
“AI value is not simply in improved efficiency, but in the broader impact on the effectiveness and agility of the GRC program.”
Michael Rasmussen, GRC Analyst & Pundit, GRC 2020
SANNOS is designed to read real evidence, including policies, contracts, SOC reports, ESG documentation and vendor documents, then map that evidence to frameworks, identify gaps and generate structured outputs with traceability back to the source material. That makes it different from generic AI summaries. Controls assessment outputs need to withstand audit, regulator, customer and board scrutiny, especially where organizations are working across frameworks such as ISO 27001, SOC 2, DORA, NIS2, PCI DSS and GDPR.
In controls management, that means teams can reduce manual evidence review, accelerate control assessments and focus human judgment where it adds the most value. This looks like 88% faster framework assessment completion and 95% acceleration in TPRM assessments. SANNOS helps assess evidence. CoreStream GRC turns the result into action through ownership, workflows, remediation and reporting.
What does “assess once, comply with many” mean for control owners?
For control owners, “assess once, comply with many” means less duplicated effort.
Instead of being asked for the same evidence again and again across different frameworks, teams can provide evidence once and have it mapped across multiple obligations. That reduces control owner fatigue, improves consistency and gives compliance teams a clearer view of where controls meet requirements, partially meet them or need remediation.
This is especially important for organizations managing overlapping cyber, privacy, operational resilience and third-party risk obligations. A single control may support requirements under ISO 27001, NIST CSF, DORA, NIS2, PCI DSS, SOC 2 and GDPR. Without a common controls model, the same work is often repeated in different language.
Paul Cadwallader, GRC Strategy Director at CoreStream GRC, captures the value simply
“Our solution enables you to control once and satisfy many.”
Paul Cadwallader, GRC Strategy Director
The benefit is not just faster assessment. It is stronger confidence across the control estate. Compliance leaders get a clearer view of framework coverage and control gaps. Business control owners spend less time responding to repeated requests. Boards, auditors and regulators get stronger evidence of how controls are operating across the organization.
How can controls management prove business value?
Controls management proves business value when it helps leaders make better decisions faster.
The value is not just cost reduction. It is the ability to move faster with confidence, because the organization can see which controls matter, whether they are working and where action is needed. That is the core idea behind value-based GRC: GRC should not only protect against downside risk. It should help the business achieve the right objectives with stronger confidence, transparency and accountability.
In practical terms, stronger controls management can support:
- Faster audit preparation
- Fewer duplicated evidence requests
- Clearer control ownership
- Earlier identification of control failures
- Stronger remediation tracking
- Better reporting to boards and regulators
- Greater confidence in strategic objectives
- Reduced reliance on manual spreadsheets and consultancy-heavy reviews
That is where controls management becomes a business enabler. When risks, controls, evidence, owners and remediation sit together, teams can prove more than activity. They can show where the organization is protected, where exposure remains and what action is being taken.
With CoreStream GRC, SANNOS and SCF, controls management becomes a way to connect assurance work to real business outcomes. The organization can assess controls once, reuse evidence across frameworks and turn assessment findings into owned, tracked and reportable action.
How does CoreStream GRC support controls management?
CoreStream GRC supports controls management by bringing risks, controls, policies, testing, evidence, remediation and reporting into 1 connected platform. That matters because controls management is not just about maintaining a record of controls. It is about proving that controls are owned, operating effectively and connected to the risks, obligations and outcomes the organization needs to manage.
With CoreStream GRC, teams can:
- Identify and document controls
- Assign ownership and accountability
- Map controls to risks, policies, processes and frameworks
- Automate testing and self-assessments
- Collect and review evidence
- Track issues, deficiencies and remediation
- Support attestations and certifications
- Report on control health and effectiveness
- Prepare for audits with cleaner, more reliable records
This creates a stronger foundation for frameworks and regulations that require control evidence, including ISO 27001, SOC 2, SOX Section 404, DORA, NIS2, GDPR Article 32 and PCI DSS. The language may differ, but the expectation is consistent: organizations need to show that controls are designed, tested, evidenced and improving.
That is where CoreStream GRC helps teams move from fragmented control activity to connected assurance. Risks, controls, evidence, owners and remediation sit together, so teams can see what has been done, what still needs attention and what can be reported with confidence.
Rob Kinson, IT Risk and Assurance Manager at Shell Energy, described the impact clearly:
“The platform has enabled a higher level of stakeholder buy-in due to its ease of use and reporting functionality.”
Rob Kinson, IT Risk and Assurance Manager, Shell Energy

The platform adapts to how the business works, rather than forcing teams into rigid processes. That flexibility matters because no 2 control environments are identical. A financial controls team, a cyber compliance team, an internal audit function and a third-party risk team may all need different workflows, but they still need 1 connected view of control effectiveness.
Conclusion: controls management should create confidence
It is no longer enough to prove that a control exists. Organizations need to prove that controls are relevant, owned, tested, evidenced, effective and connected to the outcomes the business is trying to achieve.
That is where value-based GRC matters.
When controls are connected to risks, evidence, frameworks, owners and remediation, teams can move beyond tick-box assurance. They can show where the organization is protected, where it is exposed and what needs to happen next.
With CoreStream GRC Controls Management, SANNOS AI and the Secure Controls Framework, controls management becomes more than a compliance process. It becomes a way to reduce duplication, strengthen assurance and prove value.
Ready to make controls management easier to prove?
Ready to make controls management easier to prove, easier to trust and easier to scale?
Book a CoreStream GRC workshop to explore how your controls, evidence and frameworks could work together in 1 connected platform.
Frequently asked questions for Controls Management
Controls management is the process of identifying, documenting, owning, testing, monitoring and improving the controls an organization uses to manage risk and meet compliance obligations.
Controls management is important because boards, regulators, auditors and customers need confidence that key risks are being managed effectively. Strong controls management helps organizations prove that controls are working, not just documented.
Controls management software helps organizations centralize controls, assign owners, automate testing, collect evidence, track remediation and report on control effectiveness from 1 platform.
Value-based GRC connects controls to strategic objectives, risks, evidence and outcomes. This helps teams show how controls protect business value, support decision-making and build stakeholder confidence.
AI can help review evidence, identify gaps, map controls to frameworks and accelerate assessment work. In GRC, AI outputs need to be explainable, evidence-backed and reviewable by humans.
It means assessing a control once, then mapping that assessment and evidence across multiple frameworks or regulatory requirements. This reduces duplicate testing and repeated evidence requests.
SCF provides the common controls foundation. SANNOS supports AI-powered evidence review and controls assessment. CoreStream GRC provides the platform layer for workflows, ownership, remediation, evidence and reporting.
CoreStream GRC helps teams connect controls to risks, policies, testing, evidence and remediation. Dashboards and reporting give teams visibility into control health, overdue actions and assurance status.



