---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add a control

# Manually add a control to a third party or engagement {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you're using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.

## Before you begin

Role required: sn_compliance.manager and sn_vdr_risk_asmt.vendor_risk_manager to associate controls in the Vendor Management Workspace.

## About this task

Controls and control objectives are created and managed in Policy and Compliance Management and can then be associated with third parties or engagements.

Controls are automatically generated when you associate a policy with an entity type or an entity type with a control objective. A control is created for each entity listed in the entity type for the control objective.
Controls can also be manually associated with a third party or engagement.

For more information on creating policies in Policy and Compliance Management, see [Create a policy](https://servicenow-prod.fluidtopics.net/unaAVs8Ggm0NGiF6I5N1fg "A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.").

To understand the difference between a control objective and a control, see [Structural overview of Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/fpMe_3JmkpZgylMb8Z_dhw "The structural overview of Policy and Compliance Management enables you to understand how the different modules that make up the Policy and Compliance Management application of ServiceNow integrate and interact with one another.").

## Procedure

1. Navigate to WorkspacesVendor Management Workspace.
2. Select the list icon ![]() and then navigate to Third partiesAll third parties or EngagementsAll engagements
3. Select the third party or engagement that you want.
4. Navigate to the Controls tab of the third party or engagement.
5. Assign a control to the engagement by selecting New.
6. On the form, fill in the fields.  
   For descriptions of all these fields, see [Create new control form](https://servicenow-prod.fluidtopics.net/UJuaBUrJL1j1Kf0rv3k33A "Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application.").
7. Select Submit.  
   For more information on managing controls, see [Manage controls](https://servicenow-prod.fluidtopics.net/tVIvJvJlit_ekax_HFXYEA "Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.").  
   The control is associated with the third party or engagement and all related lists are visible.
* **[Create new control form](https://servicenow-prod.fluidtopics.net/UJuaBUrJL1j1Kf0rv3k33A)**   
  Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application.

**Related concepts**   

* [Integrating Third-party Risk Management with GRC: Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/nX~deEfPOku6rS5ZGGLZoA "The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Compliance managers [sn_compliance.manager] can associate controls and control objectives with specific questions, third parties, and engagements used in Third-party Risk Management.")  
**Related tasks**   

* [Manually add a control objective to a question](https://servicenow-prod.fluidtopics.net/pbSyDzXFHcHlleEbOFu2LA "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.")  
**Related reference**   

* [Create new control form](https://servicenow-prod.fluidtopics.net/UJuaBUrJL1j1Kf0rv3k33A "Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application.")
* [Control objectives form](https://servicenow-prod.fluidtopics.net/aP~2QUBpT6pgCWxV18pViQ "Use the control objectives form to capture all the information that you need to associate a control objective with a question using the Third-party Risk Management application.")

*[\>]: and then


