Drag each risk into the correct control type: Preventive / Detective / Corrective. In Exam mode, drop everything first, then hit Check to get “why this is wrong” feedback.
Tip: Separate authorization, custody, record-keeping. Combining two → red flag.