Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

4
  • Signing In
  • Understanding the Dashboard
  • Navigation
  • Roles and Permissions

Common Workflows

9
  • Create and Approve a Policy
  • Complete an Assessment
  • Upload Artifacts
  • Review AI Artifact Analysis
  • Record and Assess a Risk
  • Create a Risk Response
  • Test a Control
  • Import Vulnerabilities
  • Complete a Vendor Assessment

Governance

6
  • Policy Center
  • Document Inventory
  • Third-Party Inventory
  • Company Setup
  • Process
  • Exception

Risk

5
  • Risk Register
  • Controls
  • Vulnerabilities
  • Assets
  • Threats

Compliance

3
  • Assessments
  • Cross Reference
  • Audit Inventory

Administration

5
  • Reports
  • Users and Roles
  • Framework Configuration
  • Notifications
  • Application Settings

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Risk
  • Controls

Controls

1 min read

App navigation: Risk → Control

The Control module maintains your organization’s catalog of security and compliance controls – the mitigations, safeguards, and procedures you have in place to manage risk. Controls are reusable and can be linked to multiple risks, policies, and authority document requirements.

Screen Layout #

Navigate to Risk → Control to open the Control Inventory screen. The Control Summary panel shows total controls by status and a review schedule overview.

[Screenshot: Control Inventory screen]

Creating a Control #

  1. Select + on the toolbar and choose Create Manually or Upload from File.
  2. Complete the control wizard:
    • Name and Description (required).
    • Control Type – Preventive, Detective, Corrective, or Compensating. Note: Compensating is a function type flag, not a separate category.
    • Maintenance Frequency – how often this control must be reviewed or tested (e.g., Monthly, Quarterly, Annually).
    • Assign Owner, Reviewer(s), and Approver(s).
    • Link to Risks, Assets, or Authority Document citations.

[Screenshot: Control creation wizard]

Control Lifecycle #

Controls follow the Draft → Under Review → Awaiting Approval → Active lifecycle. Once active, controls are tested on their configured Maintenance Frequency and the results recorded in the Review Log.

Testing a Control #

See the Test a Control workflow for step-by-step instructions on recording test results and evidence.

Note: Controls that are linked to Risk Register entries via ATVEC Mapping reduce the residual risk score of those risks. Keeping controls up to date and tested is important for accurate risk reporting on the GRC Executive Dashboard.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Risk RegisterVulnerabilities
Table of Contents
  • Screen Layout
  • Creating a Control
  • Control Lifecycle
  • Testing a Control

© 2026 ClearGRC User Guide

  • Documentation