The Control Library defines the standard control set used within AuditFlow OS.
It provides a reusable control baseline for audit planning, control testing, findings, evidence, actions, and reporting across cyber, AI, data, governance, third-party, and IS4-style reviews.
It helps users build audits around defined controls rather than broad themes alone.
Purpose
The purpose of the Control Library is to:
- Establish a consistent set of auditable controls.
- Define what each control is intended to achieve.
- Support control-based audit planning and testing.
- Standardise evidence expectations.
- Improve consistency of findings and reporting.
- Provide traceability from control to audit, evidence, finding, and action.
Principles
The Control Library should be:
- Control-based: linked to specific control objectives.
- Reusable: usable across multiple audits and domains.
- Testable: capable of evidence-based review.
- Traceable: linked to audits, evidence, findings, and actions.