---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Manage controls using the Compliance Workspace

# Manage controls using the Compliance Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Manage controls using the Compliance Workspace

This content guides ServiceNow customers on effectively managing controls within the Compliance Workspace.
Controls represent specific implementations of control objectives critical for risk mitigation and regulatory compliance.
The process emphasizes rationalizing, consolidating, and defining controls thoughtfully rather than bulk importing, to ensure controls align with business objectives and improve IT performance while minimizing overhead.
Show full answer Show less  

## Key Practices for Managing Controls

* **Rationalize Controls:** Evaluate each control's impact on business objectives, its effectiveness in risk prevention or detection, and opportunities to simplify or improve controls as business and IT environments evolve.
* **Consolidate Controls:** Identify redundant controls across multiple regulations (e.g., SOX, GLBA, AML) and cross-map them to create a unified control framework. This consolidation reduces duplication and facilitates audit readiness.
* **Define Controls and Business Rules:** Establish clear definitions of controls, assign owners, define test criteria and frequencies, assess risks, and prepare necessary attestations and evidence. Plan use cases detailing who interacts with GRC data and how.

## Entity Association and Data Accuracy

Controls must be associated with entities, which is mandatory on the Control form. Missing or disabled entities can cause inaccurate compliance calculations and should be addressed by adding entities or retiring affected controls.

## Entity Based Access (EBA)

EBA provides granular data access management tied to entities, enabling administrators to grant access to related records through user or group assignments. When EBA is enabled, new controls and related records automatically inherit entity-based access settings, streamlining access control and enhancing security without manual bulk updates.

## What Customers Can Expect

* Improved control management aligned with business goals and risk mitigation.
* Reduced control redundancy through consolidation and cross-mapping, simplifying compliance efforts.
* Accurate compliance calculations ensured by proper entity associations.
* Enhanced security and streamlined access control via Entity Based Access automation.  
Controls are specific implementations of a control objective. Retired controls do not appear in the list.
Before defining controls, take time to rationalize, consolidate, and define the important controls
in your organization.

## Rationalize your controls {#manage-controls-ws__section_ayx_vqv_lz}

If you upload all your controls in bulk, you are missing the opportunity to refine and streamline your controls set.

* How does this control affect my business objective?
* Is this control actually preventing or detecting risk?
* Is there a different control you can place that better protects your business?
* Is there a control you can put in place that reduces process overhead and improves IT performance while also mitigating risk?
* Can a complicated control be replaced with a simpler more effective control?
{#manage-controls-ws__ul_dbz_zqv_lz}  
As your business changes, and your IT data, processes, and technology improve, replace outdated controls and procedures.  
Note:  
When you define controls manually or when you import them from the Unified Compliance Framework (UCF), an entity is associated with the controls. It is a mandatory field on the Control form. If, however, you import controls from a source other than the UCF, you may encounter controls that do not have associated entities. It is important that you return to the Control form and [add an entity to
the control](https://servicenow-prod.fluidtopics.net/RM7OD42A3yZAUMPTtjV2lQ "Controls are automatically generated when you associate a policy with an entity type, or an entity type with a control objective, or when an entity is added to a control objective. A control is created for each entity listed in the entity type for the control objective. Controls can also be manually created using the Compliance Workspace."). Missing entities can cause unreliable results in calculations. Also, if you encounter a control with an entity that has been disabled, the control should be retired.

## Consolidate your controls {#manage-controls-ws__section_f4h_wqv_lz}

Look for opportunities to consolidate controls. Look for common, repeated controls across multiple regulatory authorities of frameworks (for example, SOX and GLBA and AML). Avoid operating a single control multiple times for
each regulation, by cross-mapping controls and eliminating the redundant ones. This process establishes a single consolidated set of controls = control framework, performing and preserving the cross mapping of controls is
critical for audits.

## Define controls and business rules {#manage-controls-ws__section_h4m_zgw_jz}

The business rules you define up front, establish the GRC configuration settings later. Be prepared to:

* Identify controls and control owners
* Define control tests and expected results
* Establish test and control frequencies
* Identify risks: impact and likelihood
* Prepare attestations, assessments, questionnaires, and required evidence
* Compose likely use-cases (who needs to interact with or view the contents of the GRC system and for what purposes)
* Map authoritative sources to policies, to procedures, to controls, and to risks
{#manage-controls-ws__ul_v1b_p35_5y}

## Entity Based Access (EBA) {#manage-controls-ws__section_ngx_vcj_cgc}

The Entity Based Access feature provides a framework for more granular approach to management of data access to objects associated with an entity. Administrators can grant access to an entity's related records by adding users or
user groups, or by using entity user fields for entity-based access configuration. For more information, see [Entity Based Access](https://servicenow-prod.fluidtopics.net/gkQW63YvjuDRnrNFxPdHmg "The Entity Based Access (EBA) application enables you to segregate data on the records that are based on entities. Entity-based access administrators can use this tool to set up secure, controlled access to various objects.").  
When a user is qualified based on these configurations and has the minimum required roles, they will have access to the following tables:

* Control
* Attestation
* Policy exception to control
{#manage-controls-ws__ul_ogx_vcj_cgc}

## Entity Based Access (EBA) rules {#manage-controls-ws__section_pgx_vcj_cgc}

When entity based record access rules are enabled on the Entity Based Access Configuration Properties page, any newly created controls, control attestations, indicators, and indicator tasks associated with
a configured entity will automatically inherit the entity-based access (EBA) value from that entity. Previously, users had to run bulk access updates to apply EBA restrictions whenever new objects were created.

For more information, see [Entity based record access rules to secure new records](https://servicenow-prod.fluidtopics.net/8OGh03Ts~V6uYqcrAtNMTQ "The entity-based record access rules let admins apply restrictions automatically to new and changed records. This configuration ensures that access settings stay enforced. No manual updates are needed when records are created, modified, or when users are added to user fields or user group fields.").

