Skip to content

Control Assessment Agent

The Control Assessment Agent produces a structured readiness assessment for a Control, grounded in the Control definition and the Evidence linked to it. It helps teams run consistent readiness conversations without turning every review into a blank page.

What this is

When you run the agent, it generates:

  • a readiness score from 0 to 100
  • a short summary of what the current Evidence does and does not support
  • gaps with analysis and Evidence references
  • recommendations with Evidence references
  • a list of Evidence Sources used

Running the agent stores the assessment in one step: the result you see is already the assessment of record, replacing the previous one. Humans remain accountable for how the assessment is used: validate it against the Evidence, and re-run after you fix what it found.

Where in Modulos

You run the Control Assessment Agent from the Control detail view, or across a whole framework as a Job.

  • Project → Controls → select a control → Assessment → AI Agent to run the agent; the assessment is stored when the run completes
  • Project → Controls → Create Job to assess every non-archived Control under selected frameworks on a schedule or on demand
Control Assessment tab showing a readiness score, Evidence Sources, gaps, and the AI Agent action.
The Assessment tab shows the stored agent assessment: a structured readiness snapshot with gaps and recommendations. UI shown in dark mode.
  1. 1
    AI Agent
    Run the agent; the resulting assessment is stored and replaces the previous one.
  2. 2
    Readiness score and summary
    A structured snapshot of how well the Control is supported by current Evidence.
  3. 3
    Sources
    The Evidence items the agent used as inputs.
  4. 4
    Gaps
    Where Evidence is missing, insufficient, or misaligned, with references back to Sources.

Who can do what

Permissions

You need project permission to run the agent; running it stores the assessment.

  • Project owners and editors typically run the agent and act on its findings.
  • Viewers typically read stored assessments and follow Evidence references back to artifacts.

If you don’t see the AI Agent button or the Assessment tab, ask your project owner or organization admin.

How it works

When you run the agent, Modulos:

  1. takes the Control’s question, description, and guidance
  2. finds the Evidence linked to the Control
  3. searches within that Evidence for relevant passages
  4. generates a structured assessment in the project language

Evidence references in gaps and recommendations point back to the underlying artifacts, so reviewers can verify the basis.

How to use it

  1. Attach the most relevant Evidence to the Control.
  2. Open the Control’s Assessment tab and select AI Agent. The assessment is stored when the run completes.
  3. Read the summary, then review gaps and recommendations against the underlying Evidence.
  4. Update Evidence and Control report content as needed, then re-run the agent. Each run replaces the stored assessment.

To assess at scale, use Project → Controls → Create Job and select frameworks: the job runs the agent on every non-archived Control under them, on a schedule or on demand, and each run replaces the stored assessments.

Important considerations

  • The readiness score is not a certification. Use it to focus review effort, not as an approval decision by itself.
  • If Evidence is missing, the agent will correctly report gaps. Treat this as a checklist to collect the right artifacts.
  • Run assessments early and re-run when Evidence changes. Controls become harder to change once executed.
  • AI can make mistakes. Validate claims and references against the underlying Evidence.