✅ Feature availability: You can create custom controls on any current plan. Some controls features may require an upgrade or add-on to your plan—refer to Vanta Plans and Pricing for details. Importing custom controls with the Vanta Agent is a new feature being gradually rolled out in place of the bulk uploading experience—you can contact your Customer Success Manager to request access if you don’t see it in your account.
While Vanta offers a comprehensive set of prebuilt controls mapped to frameworks like SOC 2, ISO 27001, and HIPAA, your company might have unique workflows, tools, or regulatory obligations that require more tailored controls. Custom controls let you document security and compliance requirements that aren’t covered by one of Vanta's default controls, whether you already have them defined or you're creating them from scratch.
You can add custom controls with the Vanta Agent, in bulk, or one at a time. When you add a custom control, you’ll need to review and add the right framework, test, document, and policy mappings so you can track it as part of your program.
⚙️ User permissions: Admins, Editors, and Audit Limited Editors can manage custom controls. Learn more: User Permissions by Product Area
Importing custom controls with the Vanta Agent
If you have an existing compliance program to bring into Vanta, ask the Vanta Agent to help import your controls. Upload your files, and the agent reviews each one, creates custom controls, assigns owners, and suggests relevant mappings for you to review—all in the same guided conversation. If enabled on your plan, it can also create custom fields and custom frameworks.
To import your controls with the Vanta Agent:
Open the Vanta Agent.
Ask the agent to help import your controls. For example: “Help me import my custom controls.”
Upload your control files:
You can upload up to 30 files at once, with a 50 MB total limit per upload.
When uploading controls, CSV, XLS, or XLSX files work best, up to 10 MB each.
The agent classifies each file and asks you to confirm before continuing.
Review the control details for each control being imported, then confirm when you’re ready to create the custom controls:
The agent extracts control details for you to review in a user-friendly table view.
You can chat with the agent to update control details like the ID, name, description, domain, owner, and framework mappings before the controls are created.
If your plan has custom fields enabled, the agent can suggest creating custom fields for columns in your file that don’t fit an existing control field.
If your plan has custom frameworks enabled and your control file includes framework references that don’t match an enabled framework in your Vanta account, the agent can flag them and ask whether you’d like to create a new custom framework during the same import.
Review the suggested mappings, then accept or reject the suggestions.
Depending on what you’re uploading and what already exists in Vanta, the agent can suggest which frameworks, tests, documents, and policies each imported control can be mapped to.
The agent can only create new custom controls—it can’t update existing custom controls already added to Vanta.
💡 Tip: You can upload custom controls, custom frameworks, and custom policies in the same Vanta Agent conversation. The agent will classify the files, import them through the same guided flow, and suggest mappings for you to review. Just ask: “Help me import my compliance program.” Learn more: Vanta Agent Guided Flows
Bulk uploading custom controls
If you have several existing controls to bring in at once, you can upload a CSV or Excel file from the Controls page. You can create new controls or update existing ones, and map your file's columns to Vanta's fields.
To upload your controls in bulk:
From the Controls page, click Add control and select Via import (.csv, .xlsx).
Choose Create new controls or Update existing controls.
Download the CSV template to use as a starting point.
Upload your file.
Map your file's columns to Vanta's fields.
Review and fix any flagged rows.
Finish the import to create or update the controls.
ℹ️ Note: If your file includes custom fields, create those custom fields in Vanta before importing. Once created, each custom field appears as a column in the downloadable control import template.
Creating a custom control
If you're documenting a requirement from scratch, or only have one custom control to add, create a custom control directly from the Controls page.
To add a custom control manually:
From the Controls page, click Add control and select Add custom control.
In the New control modal, fill in the control details:
Required: Description, Domain, Control ID, Effective Date
Optional: Control Name, Framework Code
Select Add control.
From the Controls page, assign an Owner.
ℹ️ Note: Vanta may suggest a Domain based on the control description, and the Effective Date defaults to today. You can review and change either before saving. If the Control Name is left blank, Vanta uses the Control ID as the name. To add custom field values, create the control first, then open it from the Controls page and edit its available fields.
Supported control fields
This table lists supported control fields that can be populated when adding custom controls with the Vanta Agent or when bulk uploading:
If you’re using the Vanta Agent, your file doesn’t need to be perfectly formatted up front—the agent reviews your file, flags missing or unclear details, and asks you to confirm or correct the values before creating the controls.
If you’re bulk uploading controls, your file should meet these requirements to import successfully.
Field | Requirements |
Control ID | Required—a unique identifier for the control. Matching is exact and case-sensitive. |
Control Description | Required—details of what the control covers. |
Effective Date | Required—the date the control goes into effect. Defaults to the date the control is created or imported. |
Control Name | Optional—a short name for the control. If left blank, the Control ID is used as the name. |
Domain | Optional—the category used to organize the control. Must match one of Vanta's supported domain values. |
Owner | Optional—the person or team responsible for the control. Must match a user or team added to your Vanta workspace. |
Framework Code | Optional—a comma-delimited list of the framework sections or requirements the control maps to. Each one must match a framework enabled in your Vanta account and a valid section or requirement within that framework. Can be left empty and mapped later. |
💡 Tip: Controls also support custom fields for capturing information specific to your compliance program.
Managing custom controls
After you create a custom control, it's added to the Controls page where you can assign owners to controls, manage control mappings, and edit control details at any time.
Assigning owners
Assigning owners
To assign owners to controls:
From the Controls page, click directly into the Owner column for the control.
Search for and select the person or team you want to assign.
Mapping tests
Mapping tests
To map controls to tests:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Tests.
Select the + button to add a test, or use the remove action to remove an existing one.
Search the full list of tests, or turn on Suggest by Vanta AI to review AI-suggested tests.
Select the test you want to link, then click Add.
Mapping documents
Mapping documents
To map controls to documents:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Documents.
Select the + button to add a document, or use the remove action to remove an existing one.
Search the full list of documents, or turn on Suggest by Vanta AI to review AI-suggested documents.
Select the document you want to link, then click Add. You can also upload a new document by selecting New document.
Mapping policies
Mapping policies
Controls can be mapped to policies to show which policies support or document the control.
To map controls to policies:
From the Policies page, select the policy.
Click the Mapped elements tab.
Click Map control.
Search for the control, or review AI-suggested controls if available.
Select the control you want to link, then click Add.
Mapping frameworks
Mapping frameworks
The same control can be mapped to multiple frameworks and requirements.
To map controls to frameworks:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Frameworks.
Select the + button to add a framework mapping, or use the remove action to remove an existing one.
Select the framework using the dropdown, then use the search bar to find the requirement by code, name, or description.
Select the appropriate requirement, then click Add.
Mapping risk scenarios
Mapping risk scenarios
To map controls to risk scenarios:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Risk scenarios.
Select the + button to add a risk scenario, or use the remove action to remove an existing one.
Search the full list of risk scenarios.
Select the risk you want to link to, then click Add.
Linked issues
Linked issues
Issues linked to a control appear in the control’s Mapped elements tab, helping you see related gaps, remediation work, or audit findings. To link a control to an issue, open the issue and add the control from the issue’s mapped elements area.
Deactivating or deleting custom controls
Deactivating or deleting custom controls
⚠️ Note: Deactivating and deleting are different actions. Deactivating a control removes it from your security program and removes its framework and monitor mappings, but a deactivated control can be restored later. Deleting a custom control permanently removes it from your program and related frameworks, and this action can't be undone.
To deactivate: Open the control > click the ••• menu and select Deactivate > click Deactivate.
To delete: Open the control > click the ••• menu and select Delete > click Delete.
