Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

3
  • Navigation
  • Understanding the Dashboard
  • Signing In

Governance

6
  • Exception
  • Process
  • Company Setup
  • Third-Party Inventory
  • Document Inventory
  • Policy Center

Risk

5
  • Threats
  • Assets
  • Vulnerabilities
  • Controls
  • Risk Register

Compliance

3
  • Audit Inventory
  • Cross Reference
  • Assessments

Administration

5
  • Roles and Permissions
  • Reports
  • Application Settings
  • Notifications
  • Users and Roles

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Risk
  • Controls

Controls

2 min read

App navigation: Risk → Control

The Control module maintains your organization’s catalog of security and compliance controls – the mitigations, safeguards, and procedures you have in place to manage risk. Controls are reusable and can be linked to multiple risks, policies, and authority document requirements.

Screen Layout #

Navigate to Risk → Control to open the Control Inventory screen. The Control Summary panel shows total controls by status and a review schedule overview.

[Screenshot: Control Inventory screen]

Control Lifecycle #

Controls follow the Draft → Under Review → Awaiting Approval → Active lifecycle. Once active, controls are tested on their configured Maintenance Frequency and results recorded.

Creating a Control #

Step 1 – Open the Creation Wizard #

  1. Select + on the toolbar and choose Create Manually or Upload from File.

Step 2 – Complete the Wizard #

  • Name and Description (required).
  • Control Type – Preventive, Detective, Corrective, or Compensating. Note: Compensating is a function type flag, not a separate category.
  • Maintenance Frequency – how often this control must be reviewed or tested (e.g., Monthly, Quarterly, Annually).
  • Assign Owner, Reviewer(s), and Approver(s).
  • Link to Risks, Assets, or Authority Document citations as needed.

[Screenshot: Control creation wizard]

Step 3 – Review and Approve #

  1. Submit the control for review. Reviewers evaluate and approve it.
  2. The control status moves to Active.

Testing a Control #

Controls must be tested on their configured Maintenance Frequency to confirm they remain effective.

Step 1 – Open the Control #

  1. Navigate to Risk → Control and open an existing control from the inventory.

Step 2 – Record the Test #

  1. Navigate to the Maintenance section within the control detail.
  2. Record the test outcome:
    • Effectiveness – select from the dropdown (e.g., Fully Effective, Partially Effective, Ineffective).
    • Comments – add supporting notes (max 100 characters).
  3. Upload any supporting evidence as an artifact.

[Screenshot: Control Maintenance section showing Effectiveness and Comments fields]

Note: Controls linked to Risk Register entries via ATVEC Mapping reduce the residual risk score of those risks. A single control can be linked to many risk records without re-entering the data.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
VulnerabilitiesRisk Register
Table of Contents
  • Screen Layout
  • Control Lifecycle
  • Creating a Control
    • Step 1 – Open the Creation Wizard
    • Step 2 – Complete the Wizard
    • Step 3 – Review and Approve
  • Testing a Control
    • Step 1 – Open the Control
    • Step 2 – Record the Test

© 2026 ClearGRC User Guide

  • Documentation