Added

ControlMap API – Objective Assessments, Policy Sections & Risk Search


Summary

This release adds richer assessment details to objective responses, including sub-objectives, responsibility assignments, and associated action items. It also adds policy-section management and program-scoped objective unmapping for evidence records. The major version remains v1.


Changes

New endpoints

Policies

  • PUT /controlmap/v1/clients/{client_id}/policies/{policy_id}/sections
    • N/A → Available
    • Type: addition
    • Notes: Create or update an HTML policy section. Omit id to create a section, or provide id with title and/or description to update one.

Changed

Objectives and assessments

  • Objective detail responses
    • Assessment details expanded
    • Type: addition
    • Notes: Objective responses now include assessment sub-objectives with their answers, notes, RACI assignments, and associated action items.

Evidence mappings

  • POST /controlmap/v1/clients/{client_id}/evidences/{evidence_id}/mappings/bulk-delete
    • Tenant-wide objective codes → program-scoped objective codes supported
    • Type: addition
    • Notes: Unmapping requests can now identify objective codes together with their program_name, while existing control unmapping remains supported.

Dates

  • Effective: [2026-09-24]