App navigation: Risk → Control
This workflow covers creating a control, assigning owners and reviewers, and recording a control test to verify its effectiveness.
Step 1 – Navigate to Controls #
- In the top navigation bar, select Risk → Control.
- ClearGRC opens the Control Inventory screen with the Control Summary panel and inventory grid.
Step 2 – Create a Control #
- Select + on the toolbar.
- Complete the control wizard:
- Name and Description (required).
- Control Type – Preventive, Detective, Corrective, or Compensating.
- Maintenance Frequency – how often this control must be reviewed/tested.
- Assign Owner, Reviewer(s), and Approver(s).
- Link the control to relevant Risks, Assets, or Authority Document citations as needed.
[Screenshot: Control creation wizard]
Step 3 – Test the Control #
- Open an existing control from the Control Inventory.
- Navigate to the Maintenance section within the control detail.
- Record the test outcome:
- Effectiveness – select from the dropdown (e.g., Fully Effective, Partially Effective, Ineffective).
- Comments – add supporting notes (max 100 characters).
- Upload any supporting evidence as an artifact.
[Screenshot: Control Maintenance section showing Effectiveness and Comments fields]
Step 4 – Review and Approve #
- Submit the control for review – assigned reviewers evaluate the control and its test results.
- Approvers provide final sign-off.
- The control status moves to Active.
Note: Controls are reusable across multiple risks. A single control can be linked to many risk records in the Risk Register via the ATVEC Mapping step.
