# Control Narrative

> **Template — adapt before use.** One narrative per control. Auditors read narratives to understand how a control is designed and operated before they test it. Keep it factual and specific.

| | |
|---|---|
| **Control ID / name** | [e.g. AC-02 — Access Provisioning] |
| **Framework reference(s)** | [ISO A.5.16, PCI 8.1, SOC2 CC6.1] |
| **Owner** | [Name / Role] |
| **Last reviewed** | [YYYY-MM-DD] |

## 1. Control objective
[What risk does this control address? One or two sentences.]

## 2. Control description
[How the control works in practice: who does what, in which system, triggered by what, and how often. Be specific — name the tools and the steps.]

## 3. Frequency & type
- Frequency: [continuous / daily / quarterly / annual / event-driven]
- Type: [preventive / detective / corrective] · [automated / manual / hybrid]

## 4. Evidence
[What artifact proves this control operated? Where is it, and how often is it produced? Link to the Evidence Index entry.]

## 5. Responsible parties
- Operates the control: [role]
- Reviews / approves: [role]

## 6. Exceptions & compensating controls
[Any known gaps, approved exceptions with expiry, or compensating controls.]
