Controls and Evidence
Adopt security and privacy controls, assign owners, and prove them with evidence that stays current on a schedule — the foundation of a compliance program in Concord Trust.
Overview
A Trust Center starts as a place to answer buyers' security questions. Controls turn it into a place to run your compliance program: you adopt a set of security and privacy controls, give each one an owner, and prove it with evidence that stays current on a schedule. When you later adopt a framework such as SOC 2 or ISO 27001, the controls you already maintain automatically show which requirements they cover.
Controls are available on the Premium and Enterprise Trust plans. If you don't see the Controls area yet, contact your Concord account team — access is being rolled out.
What a control is
A control is a named requirement you commit to and keep proving. Each control has:
- An owner — the person accountable for keeping it in good standing.
- One or more tests — each test is a single check, the specific thing being proved. A test carries a cadence, which is how fresh its evidence has to stay before the control asks for a refresh (cadences range from continuous through annual).
- Evidence — what shows a test is passing. You add evidence yourself today (upload a document or record an attestation); as you connect integrations, some tests will collect evidence automatically. Automated collection is rolling out.
- A status, computed from its tests. A control reads Passing when every required test has fresh, passing evidence, Needs review when evidence is missing or has gone stale, and Failing when a test fails.
Adopting controls
From the Controls area of Concord Trust, browse the curated library and adopt the controls that fit your program. Adopting a control brings its tests with it; you then assign an owner and start attaching evidence. You can run Controls on their own, before adopting any framework — they document your posture and can be published to your public Trust Center.
Adding evidence
Open a control to see its tests, and add evidence per test:
- Manually — upload a document or record an attestation that the test is met.
- Automatically — once the relevant integration is connected, eligible tests can collect evidence on their own. This is rolling out; where a test supports it, the option appears on the test.
Team members with a Limited role can add evidence to controls and comment on them, without being able to change the control itself. See User Roles & Permissions.
Recording an exception
When a control does not apply to you, or is handled somewhere outside Concord, record an exception with a short reason. The exception keeps the control from flagging for review while documenting, for your team and your auditor, why it is handled that way.
The controls dashboard
The Controls dashboard shows your program at a glance: each control's status and owner, and what currently needs review. Use it to see where evidence has gone stale before an auditor or a buyer does.
Publishing controls to your Trust Center
You can publish your controls to your public Trust Center so buyers can see the posture you maintain, not just the certifications you hold. Published controls appear in a dedicated section on your Trust Center page.
Next steps
- Adopting frameworks — map your controls to SOC 2, ISO 27001, and other frameworks, and see requirement coverage.
- Auditor access — give an auditor scoped, time-boxed access to review a framework.
RFP Automation Overview
Overview of RFP and RFX automation in Concord Trust: how to process incoming RFPs, generate AI-powered responses, and manage the review workflow.
Adopting Frameworks
Adopt a compliance framework to map your controls to its requirements, see coverage, and prepare for an audit — SOC 2, ISO 27001, and the other frameworks most teams need.