---
title: "POST /subcontrols"
method: POST
path: "/subcontrols"
tags: ["subcontrols"]
---

# POST /subcontrols

`POST /subcontrols`

## Request body

- object
  - `controlId` number
  - `status` 'Waiting' | 'In progress' | 'Done'
  - `approver` string
  - `riskReview` 'Acceptable risk' | 'Residual risk' | 'Unacceptable risk'
  - `owner` string
  - `reviewer` string
  - `dueDate` string
  - `implementationDetails` string
  - `evidence` string
  - `attachment` string
  - `feedback` string

## Response `201`

new created sub control

## Other responses

- `500` — internal server error
- `503` — internal server error

## Changes

- **2025-01-22** `2d06a8c7f206` — 4 warning, 4 info
  - removed the request property `control_id`
  - removed the request property `due_date`
  - removed the request property `implementation_details`
  - removed the request property `risk_review`
  - …4 more
- **2025-01-22** `ed48b7196725` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/verifywise-ai/apis/verifywise-api/changes/subcontrols/post.md)

---

[API](https://skmtc.dev/verifywise-ai/apis/verifywise-api.md) · [All operations](https://skmtc.dev/verifywise-ai/apis/verifywise-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/verifywise-ai/verifywise-api/revisions/8f39d60f160a/schema)
