scf_create_compensating_control
Record a compensating control that offsets a vendor compliance gap, specifying the gap, the control, and effectiveness rating (full, partial, minimal).
Instructions
Record a compensating control for a vendor gap (write — editor role): what the gap is, what offsets it, and how effective that is (full, partial or minimal — default partial).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| org_id | Yes | Organization UUID — obtain from scf_list_organizations | |
| vendor_id | Yes | Vendor UUID — obtain from scf_list_vendors | |
| gap_description | Yes | The gap the control offsets | |
| compensating_control | Yes | The control that offsets the gap | |
| effectiveness_rating | No | Effectiveness (default partial) | |
| risk_reduction_notes | No | How much residual risk this removes |