Control Register Template
A control register is the single list that tells you what you have promised to control, who owns it, how it is tested, and when it last passed. This template gives you the columns, the conventions, and the review rhythm.
- Category
- Guides & templates
- Type
- Template
- Reading time
- 8 min read
- Format
- PDF · Column guide + worked example
- Template
The columns that matter
Registers fail by being either too thin to be useful or so wide that nobody maintains them. These columns are the working minimum.
- Control ID and short name — stable, referenced everywhere else.
- Source — the policy, standard, regulation, or framework objective it satisfies.
- Risk addressed — plain language, one sentence.
- Control type — preventive, detective, or corrective; manual, automated, or hybrid.
- Process and activity — where in the flow it actually applies.
- Owner and approver — named people, not teams.
- Test method and frequency — how you know it works and how often you check.
- Last tested, result, and evidence link.
- Status — effective, degraded, failed, or retired.
Conventions that keep it alive
A register only survives if the rules for filling it in are boring and consistent.
- One control, one row. If a row has 'and' in it twice, it is two controls.
- Never delete a retired control — mark it retired with a date and a reason.
- If a control cannot be tested, it is a policy statement; move it out of the register.
- Owners are individuals. A team cannot be called at 7am.
Linking the register to live data
The difference between a register that is read and one that is filed is whether the test column is automatic. Where a control maps to a governance rule over an event log, the last-tested date and result should be written by the platform, not by a person.
Manual tests still belong in the register — just mark them clearly so you can see what proportion of your control environment depends on someone remembering.
The review rhythm
Monthly: exceptions and failed tests only. Quarterly: ownership, thresholds, and anything degraded. Annually: full re-walk against the source policies, including retirement of controls that no longer address a live risk.
How you may use this material
Everything listed in the Knowledge Portal is published by Automated Governance Systems for public use. You may read, download, print and share it inside your organisation, and adapt it for your own governance work, at no cost and without registering.
- Attribution. Keep a visible credit to Automated Governance Systems when you reuse wording, tables or templates outside your own team.
- No resale. Do not sell this material, or republish it as a paid product or training course, without written permission.
- Guidance, not assurance. This material supports your own judgement. It does not certify that a process is compliant, lawful, secure or audited, and it is not legal, regulatory or audit advice.
- Human review. Have an accountable owner check any adaptation before it is relied on for a decision, approval or published record.
Need different terms, or a copy for commercial redistribution? Ask us.
Want this applied to your own processes?
See how the same governance material works inside APIP.