---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Review and evaluate control effectiveness

# Review and evaluate control effectiveness {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Review and evaluate the effectiveness of the controls through the execution of
control tests related to NIST-800.53.r4.

## Before you begin

Note:  
Starting with version 10.1.0, the NIST RMF Use Case Accelerator will be supported only for customers who currently use the product. New and existing customers should consider using the GRC: Continuous Authorization Monitoring application. For details, [Continuous Authorization and Monitoring](https://servicenow-prod.fluidtopics.net/h3gzNp_jxonigLFyLYLQCw "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.").

Role required: sn_irm_nist_rmf.security_accessor, sn_irm_nist_rmf.risk_executive, or sn_irm_nist_rmf.security_officer

## Procedure

1. Navigate to AllNIST RMFAssessControl Effectiveness.
2. Review each control test and their related security controls.
3. Review the control effectiveness results in the system.
4. Perform the control tests assigned to you following the standard approach outlined in the Audit Management application.
{#rmf-evaluate-control-effectiveness__steps_qxm_nsc_jhb}

*[\>]: and then


