Control Library
The Control Library is the foundation of TPRM program.
Controls define the security and compliance requirements used to assess your third parties, identify gaps, test evidence, and determine which questions need to be asked.
The better your Control Library is maintained, the more effectively Narad can support your vendor risk assessments.
Default Control Library
When you first log in to Narad, a set of controls is provided by default. These controls are initially in Draft status, allowing you to review and customize them before using them in your TPRM workflows. To use a default control, you must first publish it.
Creating and Managing Controls
You can manage your Control Library in several ways:
Edit Controls — Modify the description, requirements, or other details of a control while it is in Draft status.
Create Controls — Create a new control individually using the Create option.
Import Controls — Import your organization's own controls into Narad.
Export Controls — Export controls and make bulk changes, before importing them back into Narad.
Adding a Control to the Control Library
Use Create Control to add a new control to your organization's Control Library.
To create a control, provide the following information:
Domain — The security or compliance area the control belongs to, such as Access Control, Data Protection, or Compliance & Audit.
Control — The name of the control.
Description — Explain what the control requires or what security practice it addresses.
Passing Criteria — Define the specific condition or evidence that must be satisfied for the control to be considered Met.
Control Groups
Control Groups help you organize controls for different vendor types or assessment requirements.
For example, you could group controls applicable for:
Payment Vendors
Information Security
Joiner, Mover & Leaver
Basic Vendor Controls
Data Privacy
AI Security
Organizing controls into meaningful groups makes it easier to manage and apply them across your TPRM program.
Control Status
Controls can move through different stages during their lifecycle:
Draft — The control is being created or edited and is not yet available for use.
In Review / Needs Approval — The control has been submitted for review and is awaiting approval.
Published — The control has been approved and is available for use.
Rejected — The control was reviewed but not approved and may require changes before resubmission.
Retired — The control is no longer intended for use.
Admin vs. Manager Permissions
The control approval process depends on the user's role.
Admin - Admins can directly publish controls after creating or editing them.
Manager - Managers can create or modify controls and submit them for review. The control must be approved by an Admin before it becomes Published and available for use.
This review process helps organizations maintain governance over the controls used in their TPRM program.
Why is the Control Library important?
Controls are at the core of Narad's TPRM workflow. Vendor profiles, control applicability, evidence testing, exceptions, and questionnaire generation all depend on the controls configured in your organization.
Keeping your Control Library relevant, accurate, and up to date helps ensure that vendor assessments are aligned with your organization's security and compliance requirements.
