---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Add a control

# Manually add a control to a third party or engagement {#ariaid-title1}

* Release version: Yokohama
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

If you're using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.

## Before you begin

Role required: sn_vdr_risk_asmt.vendor_risk_manager and sn_compliance.manager

## About this task

Controls are automatically generated when you associate a policy with an entity type or an entity type with a control objective. A control is created for each entity listed in the entity type for the control objective.
Controls can also be manually created.

For more information on creating policies in Policy and Compliance Management, see [Create a policy](https://www.servicenow.com/docs/vqncqI2kfHgB2xPtK9_qFA "A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.").

To understand the difference between a control objective and a control, see [Structural overview of Policy and Compliance Management](https://www.servicenow.com/docs/puEABXwwoBi5byX0aHsgPw "The structural overview of Policy and Compliance Management enables you to understand how the different modules that make up the Policy and Compliance Management application of ServiceNow integrate and interact with one another.").

## Procedure

1. Navigate to WorkspacesVendor Management Workspace.
2. Select the list icon ![]() and then navigate to Third partiesAll third parties or EngagementsAll engagements
3. Select the third party or engagement that you want.
4. Navigate to the Controls tab of the third party or engagement.
5. Assign a control to the engagement by selecting New.
6. On the form, fill in the fields.  
   For descriptions of all these fields, see [Create new control form](https://www.servicenow.com/docs/bJWd2KcYt7eYtVGhgxTaMQ "Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application. As a third-party risk admin, you can create a control.").
7. Select Submit.  
   For more information on managing controls, see [Manage controls](https://www.servicenow.com/docs/T0XYlprgnuS5cq5EiMqz9w "Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.").  
   The control is created and all related lists are visible.
* **[Create new control form](https://www.servicenow.com/docs/bJWd2KcYt7eYtVGhgxTaMQ)**   
  Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application. As a third-party risk admin, you can create a control.

**Related concepts**   

* [Integrating Third-party Risk Management with GRC: Policy and Compliance Management](https://www.servicenow.com/docs/XyrRvnztGu7OR95ML95BWw "The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Third-party risk (TPR) managers with the Compliance Manager [sn_compliance.manager] role can associate controls with specific questions, third parties, and engagements.")  
**Related tasks**   

* [Manually add a control objective to a question](https://www.servicenow.com/docs/ztpYg~hTlzMy_VFwZPGosg "If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.")  
**Related reference**   

* [Create new control form](https://www.servicenow.com/docs/bJWd2KcYt7eYtVGhgxTaMQ "Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application. As a third-party risk admin, you can create a control.")
* [Control objectives form](https://www.servicenow.com/docs/cn2Ywz86XJbD46ZwEplKng "Use the control objectives form to capture all the information that you need to associate a control with a question using the Third-party Risk Management application. As a third-party risk admin, you can create a control objective.")

*[\>]: and then


