---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add a control to a risk

# Add a control to a risk {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Controls are added to the risks for the on-going review of processes.

## Before you begin

Role required: sn_risk.manager and sn_compliance.manager

## About this task

## Procedure

1. Navigate to AllRiskRisk RegisterAll Risks
2. Open the risk record from the list.
3. Continue with one of the following options.

   | Option | Description |
   | Add an existing control | 1. In the Controls related list, select Add. 2. Select the controls that are associated with the risk profile. 3. Select Add relationship. {#t_AddControlToRisk__ol_kgk_sdz_pv} Note: The controls displayed after selecting the Add button are limited to controls where the entity of control matches the risk entity. If there are no eligible controls that can be related to the risk, the Add button isn't displayed on the Controls related list. |
   | Add a new control | 1. In the Controls related list, select New. 2. On the form, fill in the fields. For a description of the field values on the Control form, see [Create a control](https://servicenow-prod.fluidtopics.net/jbzCes4f6AkMQacFwUm6_A "Controls are automatically generated when you associate a policy with an entity type or an entity type with a control objective. A control is created for each entity listed in the entity type for the control objective. Controls can also be manually created."). 3. Select Submit. {#t_AddControlToRisk__ol_zqf_ydz_pv} |
   | Inherit common controls | 1. In the Controls related list, select Inherit common controls. 2. Select the controls. 3. Select Add. {#t_AddControlToRisk__ol_rx4_fd5_fwb} Note: The common controls displayed after selecting the Inherit common controls button are limited to controls where the reliant entity of control matches the risk entity. If there are no eligible controls that can be related to the risk, the Inherit common controls button isn't displayed on the Controls related list. |
   |-|-|

   {#t_AddControlToRisk__choicetable_y2l_kdz_pv}  
   * When a control objective and risk statement are associated and the control entity matches the risk entity, the risk-control association is created.
   * The risks and controls that are created after associating a control objective to the risk statement aren't associated with the risk statement immediately. They get associated when the GRC Profile Generation scheduled job runs.
   * If you manually delete a control from a risk, the control won't be re-created by the scheduled job. You must manually create it again if necessary.
   {#t_AddControlToRisk__ul_wmy_tzp_qqb}
{#t_AddControlToRisk__steps_qy3_nzy_pv}
**Related tasks**   

* [Associate a risk statement with a control objective in the Risk Workspace](https://servicenow-prod.fluidtopics.net/fvaX3w9IHsuJOKyN_EGP3A "Associate risk statements to control objectives in the Risk Workspace. This association helps you to manage your risks by ensuring that the risks have mitigating controls.")

*[\>]: and then


