✅ Feature availability: You can create custom controls on any current plan. Some controls features may require an upgrade or add-on to your plan—refer to Vanta Plans and Pricing for details. Importing custom controls with the Vanta Agent is a new feature being gradually rolled out in place of the bulk uploading experience—you can contact your Customer Success Manager to request access if you don’t see it in your account.
While Vanta offers a comprehensive set of prebuilt controls mapped to frameworks like SOC 2, ISO 27001, and HIPAA, your company might have unique workflows, tools, or regulatory obligations that require more tailored controls. Custom controls let you document security and compliance requirements that aren’t covered by one of Vanta's default controls, whether you already have them defined or you're creating them from scratch. When you add a custom control, you’ll need to review and add the right framework, test, and evidence mappings so you can track it as part of your program. You can add custom controls with the Vanta Agent, in bulk, or one at a time.
⚙️ User permissions: Admins, Editors, and Audit Limited Editors can manage custom controls. Learn more: User Permissions by Product Area
Importing custom controls with the Vanta Agent
If you have an existing compliance program to bring into Vanta, ask the Vanta Agent to help import your controls. Upload your files, and the agent reviews each one, creates custom controls, and suggests relevant evidence mappings (like tests and documents) for you to review—all in the same guided conversation.
To import your controls with the Vanta Agent:
Open the Vanta Agent.
Ask the agent to help import your policies. For example: “Help me import my custom controls.”
Upload your control files:
You can upload up to 30 files at once, with a 50 MB total limit per upload.
When uploading controls, CSV, XLS, or XLSX files work best, up to 10 MB each.
The agent classifies each file and asks you to confirm before continuing.
Review the control details for each control being imported, then confirm when you’re ready to create the custom controls:
The agent extracts control details for you to review in a user-friendly table view.
You can chat with the agent to update control details like the ID, name, description, domain, owner, and framework mappings before the controls are created.
The agent can only create new custom controls—it can’t update existing custom policies already added to Vanta.
Review the suggested mappings, then accept or reject the suggestions.
💡 Tip: You can upload custom policies and custom controls in the same Vanta Agent conversation. The agent will classify the files, import the policies and controls through the same guided flow, and suggest mappings between them for you to review. Just ask: “Help me import my compliance program.”
Bulk uploading custom controls
If you have several existing controls to bring in at once, you can upload a CSV or Excel file from the Controls page. You can create new controls or update existing ones, and map your file's columns to Vanta's fields.
To upload your controls in bulk:
From the Controls page, click Add control and select Via import (.csv, .xlsx).
Choose Create new controls or Update existing controls.
Download the CSV template to use as a starting point.
ID and Description are the only required fields.
Upload your file.
Map your file's columns to Vanta's fields.
Review and fix any flagged rows.
Finish the import to create or update the controls.
Creating a custom control
If you're documenting a requirement from scratch, or only have one custom control to add, create a custom control directly from the Controls page.
To add a custom control manually:
From the Controls page, click Add control and select Add custom control.
In the New control modal, fill in the control details:
Required: Description, Domain, Control ID, Effective date
Optional: Control name, Framework code
Select Add control.
ℹ️ Note: Vanta sets the Effective date to today by default, but you can change it if needed. If the Control name is left blank, Vanta uses the Control ID as the name.
Managing custom controls
After you create a custom control, it’s added to the Controls page. You can assign Control Owners, manage control mappings, and edit control details at any time.
💡 Tip: You can also use the Vanta Agent to manage your custom controls, which helps reduce the effort it takes to make bulk changes. The Vanta Agent can help you assign owners, as well as map tests, documents, and create custom frameworks.
Assigning owners
Assigning owners
To assign owners to controls:
From the Controls page, click directly into the Owner column for the control.
Search for and select the person or team you want to assign.
Mapping tests
Mapping tests
To map controls to tests:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Tests.
Select the + button to add a test, or use the remove action to remove an existing one.
Search the full list of tests, or turn on Suggest by Vanta AI to review AI-suggested tests.
Select the test you want to link, then click Add.
Mapping documents
Mapping documents
To map controls to documents:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Documents.
Select the + button to add a document, or use the remove action to remove an existing one.
Search the full list of documents, or turn on Suggest by Vanta AI to review AI-suggested documents.
Select the document you want to link, then click Add. You can also upload a new document by selecting New document.
Mapping policies
Mapping policies
Controls can be mapped to policies to show which policies support or document the control.
To map controls to policies:
From the Policies page, select the policy.
Click the Mapped elements tab.
Click Map control.
Search for the control, or review AI-suggested controls if available.
Select the control you want to link, then click Add.
Mapping frameworks
Mapping frameworks
The same control can be mapped to multiple frameworks and requirements.
To map controls to frameworks:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Frameworks.
Select the + button to add a framework mapping, or use the remove action to remove an existing one.
Select the framework using the dropdown, then use the search bar to find the requirement by code, name, or description.
Select the appropriate requirement, then click Add.
Mapping risk scenarios
Mapping risk scenarios
To map controls to risk scenarios:
From the Controls page, open the control.
In the Mapped elements tab, scroll to Risk scenarios.
Select the + button to add a risk scenario, or use the remove action to remove an existing one.
Search the full list of risk scenarios.
Select the risk you want to link to, then click Add.
Linked issues
Linked issues
Issues linked to a control appear in the control’s Mapped elements tab, helping you see related gaps, remediation work, or audit findings. To link a control to an issue, open the issue and add the control from the issue’s mapped elements area.
Deactivating or deleting custom controls
Deactivating or deleting custom controls
⚠️ Note: Deactivating and deleting are different actions. Deactivating a control removes it from your security program and removes its framework and monitor mappings, but a deactivated control can be restored later. Deleting a custom control permanently removes it from your program and related frameworks, and this action can't be undone.
To deactivate: Open the control > click the ••• menu and select Deactivate > click Deactivate.
To delete: Open the control > click the ••• menu and select Delete > click Delete.
