Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Control objectives form

Use the control objectives form to capture all the information that you need to associate a control objective with a question using the Third-party Risk Management application.

FieldDescription
NameName of the control objective.
SourceSource of the control objective. For example, if the control objective is from a third-party provider, indicate which one.
Source IDUnique identification number used by the source to catalog this control objective.
ReferenceUnique numerical identifier.
ParentControl objective that is not a child of the current control objective. This is to avoid cyclic parent – child relationship.
Compliance Score PercentageCompliance score percentage calculated for this control objective and its color code: - 80 and higher in green - 80 to 50 in yellow - below 50 in red
ActiveOption that indicates whether a control objective is active.
Creates controls automaticallyOption that indicates that controls are automatically created from the control objective. Note: Select this option if the control objective can also serve as the control.
CategoryList of options:- Acquisition or sale of facilities, technology, and services - Audits and risk management - Compliance and Governance Manual of Style - Human Resources management - Leadership and high-level objectives - Monitoring and measurement - Operational management - Physical and environmental protection - Privacy protection for information and data - Records management - System hardening through configuration management - Systems continuity - Systems design, build, and implementation - Technical security - Third Party and supply chain oversight - Root
ClassificationList of options:- Preventive - Corrective - Detective
TypeList of options:- Acquisition/Sale of Assets or Services - Actionable Reports or Measurements - Audits and Risk Management - Behavior - Business Processes - Communicate - Configuration - Data and Information Management - Duplicate - Establish Roles - Establish/Maintain Documentation - Human Resources Management - Investigate - IT Impact Zone - Log Management - Maintenance - Monitor and Evaluate Occurrences - Physical and Environmental Protection - Process or Activity - Records Management - Systems Continuity - Systems Design, Build, and Implementation - Technical Security - Testing - Training
AttestationList of options. - GRC Attestation is chosen by default - Note: If the user changes the control attestation, the related control objective attestation type is changed also.
Issue group ruleGroup rule assigned to this control objective.
DescriptionDescription of the control objective.
Functional domainFunctional domain for the control objective.

Parent Topic:Manually add a control objective to a question

Related topics

Manually add a control objective to a question