---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add a control objective

# Manually add a control objective to a question {#ariaid-title1}

* Release version: Xanadu
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you're using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.

## Before you begin

Role required: sn_vdr_risk_asmt.vendor_risk_manager and sn_compliance.manager

## About this task

A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies.

For more information on creating policies in Policy and Compliance Management, see [Create a policy](https://www.servicenow.com/docs/t9VHs6HzpTp4cCyBcHsxFg "A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.").

To understand the difference between a control objective and a control, see [Structural overview of Policy and Compliance Management](https://www.servicenow.com/docs/_WSQOdBVpHjZPYmsqZZtKQ "The structural overview of Policy and Compliance Management enables you to understand how the different modules that make up the Policy and Compliance Management application of ServiceNow integrate and interact with one another.").  
Note:  
Although it is not possible to directly map control objectives to questions in SAE questionnaires, SAE provides the capability to flag controls as compliant or non-compliant through post-assessment actions.

## Procedure

1. Navigate to AllThird-party Risk ManagementAssessment SetupQuestionnaire Templates and select the questionnaire template you want.
2. Select the metric categories that you want from the related list and then select the question you want.
3. Navigate to the Control Objectives related list and then create a control objective by selecting New.
4. On the form, fill in the fields.  
   For descriptions of all these fields, see [Control objectives form](https://www.servicenow.com/docs/7juhHT1JpwyyXorUPkGPGQ "Use the control objectives form to capture all the information that you need to associate a control with a question using the Third-party Risk Management application. As a third-party risk admin, you can create a control objective.").
5. Select Submit.  
   For more information on managing controls, see [Manage controls](https://www.servicenow.com/docs/mZkUjfR5eG9gb9TxVvEEOA "Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.").  
   The control objective is created and all related lists are visible.
* **[Control objectives form](https://www.servicenow.com/docs/7juhHT1JpwyyXorUPkGPGQ)**   
  Use the control objectives form to capture all the information that you need to associate a control with a question using the Third-party Risk Management application. As a third-party risk admin, you can create a control objective.

**Related concepts**   

* [Integrating Third-party Risk Management with GRC: Policy and Compliance Management](https://www.servicenow.com/docs/Mz_aiWnxkOXb2j~f97JbDA "The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Third-party risk (TPR) managers with the Compliance Manager [sn_compliance.manager] role can associate controls with specific questions, third parties, and engagements.")  
**Related tasks**   

* [Manually add a control to a third party or engagement](https://www.servicenow.com/docs/uxe1Y8V11Urn7rm~4S7Ixg "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.")  
**Related reference**   

* [Control objectives form](https://www.servicenow.com/docs/7juhHT1JpwyyXorUPkGPGQ "Use the control objectives form to capture all the information that you need to associate a control with a question using the Third-party Risk Management application. As a third-party risk admin, you can create a control objective.")
* [Create new control form](https://www.servicenow.com/docs/6SFhw7Y342PN_95W4KBR4A "Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application. As a third-party risk admin, you can create a control.")

*[\>]: and then


