Why You May Need to Add Controls
Every organization is different — and while ComplyJet automatically configures a comprehensive standard control set for you, there are times when you may want to go beyond what’s provided.
For example:
You operate a physical office and need controls around visitor management or on-premise security
You maintain a self-hosted data center
You follow an industry-specific requirement that needs additional safeguards
You simply want to introduce more structure or documentation around your internal processes
In all such cases, ComplyJet allows you to easily add extra controls that match your unique environment while still keeping everything aligned with your compliance frameworks.
Where Controls Live Now
Controls aren't managed from one central library page anymore — they're scoped to each framework. Open any framework (Compliance → Frameworks → [a framework]) and you'll find three tabs: Requirements, Tests, and Controls.
The Controls tab lists every control linked to that framework, including deactivated ones, filterable by All / Passing / Failing / Excluded.
The Requirements tab is where you actually attach controls to a specific requirement — each requirement section has its own Map Controls button.
Mapping Controls to a Requirement
Click Map Controls on any requirement, and you'll see the set of controls available for that framework, with checkboxes for which ones are already mapped to this requirement. Search and select the ones that fit, then click Remap Controls to save.
For a standard framework (SOC 2, ISO 27001, HIPAA, and so on), this list is limited to that framework's own standard control set — you can't create a brand-new custom control and self-map it into a standard framework here. If none of the existing controls fit and you genuinely need a new one added to a standard framework, reach out to support:
For your Custom Framework, this same Map Controls flow draws from your organization's own custom control set (you'll see IDs like CTRL-1, CTRL-2, etc.) instead of a standard library, since a custom framework's requirements and controls are yours to define.
If You Need a Genuinely New Control
Beyond re-mapping what already exists, adding an entirely new control definition — one that doesn't yet exist anywhere in your environment — currently goes through support rather than a fully self-serve UI. Reach out via Contact Support with what the control should cover and which framework(s) it should apply to, and the ComplyJet team will get it added and mapped correctly on your behalf.

