Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Policy and Compliance Management mandatory setup

After you have assigned roles to your users and set Policy and Compliance Management properties, proceed with the mandatory setup steps.

The flow of mandatory steps in the checklist are illustrated here.

Image omitted: mandatory-steps.png
Mandatory steps

When you have completed the mandatory steps outlined above, other optional setup procedures are available.

  • Create a policy
    A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.
  • Create a control objective
    A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies.
  • Relate a control objective to a policy
    Associate the control objective to a policy individually when the policy is in the review or draft state by clicking the edit button in the Control Objective related list.
  • Create a control attestation using the Attestation Designer
    Use the Attestation Designer to create and edit metric types. Use different metric types for different controls. Select multiple respondents for an attestation, as well as change scoring parameters.
  • Create a control indicator
    Indicator data for controls, risk, and audit evidence are measured differently depending on the GRC application.

Parent Topic:Implementing Policy and Compliance Management