Skip to content
Release: Australia · View source

Australia Governance, Risk, and Compliance

  • Governance, Risk, and Compliance -- Respond to business risks in real time. Connect security and IT with an integrated risk program offering continuous monitoring, prioritization, and automation.
  • GRC and the ServiceNow Store -- All GRC applications are available from the ServiceNow Store, allowing you to obtain new and updated features more rapidly. Before you can use any GRC applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them). Then, you can download them from the ServiceNow Store and activate them.
    • Download a GRC application from the ServiceNow Store for the first time -- Downloading an application from the ServiceNow Store for the first time involves several easy steps. Some steps are performed on the ServiceNow Store and some in your ServiceNow AI Platform instance.
    • Get entitlement for a GRC product or application -- The first step in installing an application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.
    • Activate an entitled GRC ServiceNow Store application -- After an application has been given entitlement, you can activate it. This process applies to applications downloaded to sub-production instances.
    • Install GRC content packs and integrations -- All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Policy and Compliance Management, are visible in the ServiceNow Products tab on the store. Content pack and integration add-ons are visible in the Certified Apps tab.
    • Update a GRC application -- If you have previously downloaded an application from the ServiceNow Store and a new version is available, you can update it in your instance. When you update, the latest version of the application is installed from the application store along with the application package.
    • Upgrade your instance to the next GRC family release -- If you are currently running a family release (London for example) and want to upgrade to the next release, it is not necessary to acquire the applications from the ServiceNow Store. The application is automatically updated when the platform is updated to the minimum required version.
  • AI Risk and Compliance -- The ServiceNow AI Risk and Compliance application, along with the ServiceNow AI Control Tower, enables the risk and compliance managers to ensure that the organizations comply with the regulations and policies with respect to their AI systems.
    • Explore -- Learn how you can use the AI Risk and Compliance application to manage your artificial intelligence (AI) capabilities ethically, mitigate AI risks, and ensure compliance.
    • AI assets -- An AI asset is a digital resource that leverages artificial intelligence technologies to perform specific functions or address defined business needs.
      • AI systems -- An AI system is an AI-powered solution that is developed, deployed, and managed under a formal governance framework. This framework ensures that the system operates in a responsible, compliant, and risk-aware manner throughout its life cycle.
      • AI models -- An AI model goes through design, deployment, and monitoring in accordance with structured governance frameworks that support ethical use, regulatory compliance, and risk mitigation throughout its life cycle.
      • Datasets -- Datasets in AI Risk and Compliance capture and govern the data used by AI models, enabling organizations to evaluate risk, ensure compliance, and maintain transparency across the AI asset life cycle.
      • 360° AI asset view -- Use the 360° AI asset view to explore the relationship between your AI assets and all its associated records in a distinctive visualization. To use this feature, you must integrate AI Risk and Compliance with the 360° Relationship Visualization application.
    • Entity Based Access for AI assets -- The GRC: Entity Based Access application enables you to segregate data on the AI asset records to ensure that only authorized users can access sensitive AI Risk and Compliance data while maintaining visibility into core entities. Entity-based access administrators can use this application to set up secure, controlled access to various AI assets and its related objects.
    • AI Risk and Compliance workspace -- The AI Risk and Compliance workspace is the central hub for AI risk and compliance managers to monitor risk posture, track assessments, manage controls and issues, and oversee AI cases across the enterprise.
      • Risk & compliance tab -- The Risk & compliance tab on the AI Risk and Compliance displays the risk classification of an AI asset inventory and the compliance posture for the selected authority documents and policies.
      • Operations tab -- The Operations tab on the AI Risk and Compliance workspace provides an overview of AI systems by state, along with metrics for assessments, control assurance, issues, policy exceptions, and AI cases.
      • AI cases tab -- Track, monitor, and analyze your AI case workflows, identify your workflow bottlenecks, and monitor your accountability of your AI-related risks by using the AI risk and compliance dashboard. As an AI steward, you can also use the dashboard to track the status and trends of your AI-related inquiries.
    • AI risk heatmap workbench -- Use the AI risk heatmap workbench to visualize assessed AI risks in a color-coded matrix. The heatmap helps you identify concentrations of higher-risk AI assets and compare current and intended risk posture.
    • Tasks page -- The Tasks page in the AI Risk and Compliance Workspace provides a view of your pending tasks, your group's tasks, and your watchlist. You can update tasks directly from the Tasks page.
    • Risk assessment project -- You can perform assessments on multiple risks and controls simultaneously by creating a risk assessment project for an AI asset. This feature enables assessors to review multiple risks to understand their potential impact, likelihood, and associated mitigation strategies.
      • Risk assessment project workflow -- The risk assessment project workflow is a structured process to assess multiple risks and controls of an AI asset simultaneously.
    • AI Risk and Compliance Content accelerator -- The AI Risk and Compliance Content application is a centralized repository of frameworks, citations, risk statements, and control objectives. Using this application accelerates the adoption of AI Risk and Compliance frameworks.
    • Automatic AI case and inquiry creation from email -- The system automatically creates AI cases and inquiries from inbound emails using keywords in the subject line and body based on configured email intake settings.
    • AI governance life cycle -- Learn more about how organizations can govern AI from initial demand through deployment and ongoing governance monitoring by using the AI Control Tower and AI Risk and Compliance applications together.
      • Intake requests -- Intake requests are the entry point for managing and governing AI initiatives. They capture essential information about proposed AI systems, models, and datasets so that requests can be reviewed, triaged, and evaluated early in the AI life cycle.
      • AI cases and inquiries -- AI cases and inquiries provide a structured way to report, track, and manage AI-related concerns and questions as part of AI governance in AI Control Tower and AI Risk and Compliance.
      • Assessment templates -- The AI Risk and Compliance application uses assessment templates to evaluate AI assets for risk, regulatory compliance, and ethical alignment.
      • Risk assessment methodologies -- The AI Risk and Compliance application uses risk assessment methodologies (RAMs) to define the scoring frameworks and classification criteria used during risk assessments.
      • Offboarding AI assets review -- Offboarding AI systems, models, and datasets helps ensure that governance, risk, and compliance requirements are addressed throughout assessment, preparation, and retirement of AI assets, including impact evaluation, residual risk management, documentation preservation, data‑handling decisions, and audit traceability.
    • Exploring Now Assist in AI Risk and Compliance -- With Now Assist in AI Risk and Compliance, part of the Now Assist for Integrated Risk Management (IRM) application, you can use agentic workflows and generative AI skills that streamline issue summarization, control objective creation, and respond to smart assessment questions.
    • Configure -- To use the AI Risk and Compliance application, you download and activate the application and then you must publish the assessment templates and set up the assessments and their automation logic to ensure accurate risk assessment scores.
    • Install application -- You can install the AI Risk and Compliance application (sn_grc_ai_gov) if you have the admin role. The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
    • Content pack -- The ServiceNow AI Risk and Compliance Content Pack provides foundational content to help organizations manage AI-related risk and compliance.
      • Install content -- Install the AI Risk and Compliance content application (sn_grc_ai_gov_cont) to add predefined governance content such as frameworks, authority documents, control objectives, and risk statements.
      • Activate or update EU Artificial Intelligence Act -- Activate or update the EU Artificial Intelligence Act framework and select the citations relevant to your organization. The citations are installed into your instance so they can be mapped to control objectives and used in assessments.
      • Activate or update NIST Risk Management Framework -- Activate or update NIST Risk Management Framework to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.
      • Activate or update the Colorado Artificial Intelligence Act -- Activate or update the Colorado Artificial Intelligence Act (Senate Bill 24-205) to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.
      • Activate or update the Transparency in Frontier Artificial Intelligence Act (SB 53) -- Activate or update the Transparency in Frontier Artificial Intelligence Act (SB 53) to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.
    • Configure workspace -- Configure the AI Risk and Compliance Workspace using UI Builder.
    • Set up properties -- Configure AI Risk and Compliance properties to specify which authority documents and policies you want to display on the home page. You can also specify a default automated risk classification assessment RAM for AI systems and specify a default RAM to be used for risk assessments of AI systems.
    • Advanced Risk assessment properties -- Enable Advanced Risk Assessments (ARA) to confirm that risk‑based assessments and risk score roll‑up function correctly in the AI Risk and Compliance application.
    • Configure email intake -- Configure email-based intake so that incoming email messages create intake records in AI Risk and Compliance.
    • Use -- Use the AI Risk and Compliance to request AI systems, AI models, AI datasets, and so on and perform assessments for them to determine their risk posture.
    • Request an AI use case -- Request the development or procurement of an AI system to initiate and document the need for an AI‑driven solution within an organization. This process helps ensure that AI implementations are aligned with business goals, compliant with regulations, and technically feasible.
      • Request an AI use case form -- The Request an AI use case form is designed to streamline the request process for developing or procuring an AI-based solution. This intake form confirms that all necessary details, supporting documents, and compliance considerations are captured before moving forward with development and deployment of the AI-solution.
    • Request an AI model -- Request the development or procurement of an AI model to support an AI system. This process captures the technical and business context needed to initiate governance review, risk assessment, and life cycle tracking for the model.
      • Request an AI model form -- The Request an AI model form is designed to streamline the request process for developing or procuring an AI model. This intake form confirms that all necessary details, supporting documents, and compliance considerations are captured before moving forward with the approval process.
    • Request a dataset -- Request a dataset to support AI model training, testing, validation, or analytical use cases. This process helps ensure data sources are reviewed for quality, privacy, and compliance.
      • Request a dataset form -- The Request a dataset form is designed to streamline the request process for procuring a dataset. This intake form confirms that all necessary details, supporting documents, and compliance considerations are captured before moving forward with the approval process.
    • Raise an AI inquiry -- Submit your questions about AI systems, models, or datasets and their business applications.
      • Raise an AI inquiry form -- Use the Raise an AI inquiry form in the Employee Center to submit your questions about AI systems, models, or datasets and their business applications.
    • Report an AI case -- Report an AI case by providing a detailed description, such as system behavior, affected users, and relevant data. Include supporting attachments for prompt resolution.
      • Report an AI case form -- Use the Report an AI case form in the Employee Center to report an AI case with the necessary details.
    • Report an AI case anonymously -- Report an AI case without revealing your identity using the Anonymous Reporting Center. Your name and contact details are not shared with investigators. Save the report key and report number provided after submission to track updates or provide additional information later.
      • Report an AI case form -- Use the Report an AI case form in the Anonymous Report Center to report an AI case with the necessary details. After you submit the AI case report, mandatory fields and input format are validated before submission.
      • Follow up on an anonymous report -- After you submit an anonymous report, save the Report key and Report number. Use these reference numbers to follow up or address comments on your case anonymously.
    • Create an AI issue -- Identify and manage issues related to the impacted areas for the reported AI case in the AI Risk and Compliance workspace.
      • Create New AI Issue form -- Use the Create New Issue form to identify and manage issues related to the impacted areas for the reported AI case.
    • Remediate an issue -- After an issue has been created, reported, identified, triaged, and investigated, you can remediate it.
    • Initiate AI assessment on an AI asset -- Initiate AI assessment for the whole AI asset.
    • Perform impact assessment on an AI use case -- Perform an impact assessment of an AI use case to identify risks like copyright issues, bias, privacy breaches, misinformation, or surveillance, enabling improved oversight and risk management.
    • Initiate risk assessment -- Initiate risk assessment to enable the risk assessor to perform risk assessments on AI systems, evaluating the likelihood and impact of potential risks.
    • Perform risk assessments -- Perform risk assessments on AI systems to evaluate the likelihood and impact of potential risks using the AI Risk and Compliance application.
    • Manage controls -- You can add, remove, and delete controls for an AI asset using the AI Risk and Compliance.
      • Add controls -- Add controls manually from published control objectives to an AI asset in AI Risk and Compliance. Use this task when controls were not automatically generated by a post-assessment action, or when you need to apply additional controls beyond those mapped through the impact assessment.
      • Remove controls -- Remove associated controls from an AI asset to keep the inventory accurate and up to date. This step is essential to retire outdated or irrelevant controls without deleting their records.
      • Delete controls -- Delete controls from an AI asset to remove them permanently from the control table. This task confirms outdated or unnecessary controls are deleted.
      • Create control attestations for an AI asset -- Create control attestations for AI assets to document the existence, implementation, and effectiveness of controls that govern behavior, data usage, performance, and risk posture. Attestations serve as formal evidence that the AI asset meets regulatory, ethical, security, and operational standards.
    • Request risk assessments -- Request risk assessments for risks identified during the AI system's impact assessment. These risks are generated based on the responses provided during the impact assessment of the AI system.
    • Create risk assessment project -- Create a bulk risk assessment project to perform assessments on multiple risks and controls simultaneously using the AI Risk and Compliance workspace. You can define the project context, including the assessable entity, Risk assessment methodology (RAM), project name, description, and identify and add stakeholders.
    • Perform bulk assessment in stacked view -- Perform assessments on multiple risks and controls simultaneously in a risk assessment project using AI Risk and Compliance Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
    • Perform bulk assessment in grid view -- Perform assessments on multiple risks and controls simultaneously in a risk assessment project in the grid view using AI Risk and Compliance Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
    • Create an AI case -- Create an AI case in the AI Risk and Compliance workspace by providing a detailed description, such as system behavior, affected users, and any relevant data. Ensure all necessary information, such as supporting attachments, is included for prompt resolution.
      • Create New AI case form -- Use the Create New AI case form in the AI Risk and Compliance workspace to report an AI case with the necessary details.
    • Reference -- Reference topics provide additional information such as tables and roles that are installed with the AI Risk and Compliance application.
    • Roles installed -- The AI Risk and Compliance installs the essential roles to perform respective day-to-day operational tasks for managing AI assets across the enterprise.
    • Tables installed -- Tables are added with the activation of the AI Risk and Compliance application.
    • Advanced Risk properties -- Reference for the Advanced Risk system properties available in the AI Risk and Compliance application, including the properties that control risk assessment methodology behavior, risk score roll-up, and risk appetite configuration.
    • Assessment templates -- Reference table listing the assessment templates installed with AI Risk and Compliance. Templates are delivered in Draft state and must be published before use.
    • Risk assessment methodologies -- Reference table listing the default risk assessment methodologies (RAMs) installed with AI Risk and Compliance. RAMs define the scoring frameworks, classification criteria, and contributing factors used to evaluate risks associated with AI assets.
    • AI governance email notifications -- Email notifications are sent automatically when specific events occur across AI governance workflows, including AI Control Tower, AI Risk and Compliance, and inherited Risk Management processes.
  • Audit Management -- The ServiceNow Audit Management application involves a set of activities related to planning audit engagements, executing engagements, and reporting findings to the audit committee and executive board. Engagement reporting assures key stakeholders that the organization's risk and compliance management strategy is effective.
    • Exploring Audit Management -- The Audit Management automates the work streams of internal audit teams, optimizing resources and productivity, and eliminating recurring audit findings. Audit Management uses compliance and risk data to scope, plan, and prioritize audit engagements. The on-going review of policies and procedures, risks, and control breakdowns provide an opportunity for fixing issues before they become audit failures.
    • Audit entry for GRC objects -- The audit entry field marks a record as third-line, restricting its visibility to users who hold the third-line manager role. Third-line records are excluded from the views and calculations that second-line users rely on.
      • Create an audit entry record -- Create audit entry records to track third-line audit objects in the Audit Workspace. Audit entry records are read-only after the first save and are hidden from second-line users.
      • Duplicate a second-line record as an audit entry -- Use the Duplicate as audit entry action to copy a second-line control, control objective, risk, or risk statement into a new third-line record. Each source record can be duplicated only once.
    • Configure -- You can run the GRC Audit Management application by downloading it from the ServiceNow Store and then configuring the settings in the setup checklist to meet your needs. Mandatory and optional setup steps, as well as an implementation checklist, are provided to simplify the setup.
    • Activate Audit Plugin -- Before you run GRC: Audit Management (com.sn_audit) in your instance, you must download it from the ServiceNow Store.
    • Audit Setup Checklist -- This checklist includes the setup tasks that you're required to complete in your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance the Audit Management functionality.
    • GRC Audit Test Suite -- Validate that GRC: Audit Management still works after you make any configuration change such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
    • Advanced Audit App Setup Checklist -- Complete the checklist that includes the setup tasks required to complete in your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation.
    • Audit Management Overview -- The scope of audit management includes automation of the work streams of internal audit teams, optimizing resources and productivity, and eliminating recurring audit findings.
    • Audit Report Templates -- Create an audit report template to generate an audit report. If you're an audit developer, you can use either the HTML, Script, or XML format to create an audit report template. You can then use the audit report template to display data in an audit report.
    • Audit Test Template and Plans -- An audit engagement may include control testing activities during which controls are evaluated for design and operational effectiveness.
      • Audit Test Template Creation -- Test templates allow audit managers to quickly create many test plans using much of the same testing criteria.
      • Link Test Template to Control Objectives -- Audit owners can create generic control test templates for a control objective, avoiding the creation of individual control test plans for every control.
      • Audit Test Plan Creation -- Test plans can be created from scratch or based on test templates and describe how a feature is to be tested.
      • Multiple Test Plan Creation -- If GRC: Policy and Compliance Management is installed, a test template can be used to create test plans for all the controls associated with the control objective of the test plan.
    • Manage engagements -- The audit engagement process involves creating, planning, scoping, and conducting engagements as well as reporting on engagement findings.
      • Audit task management -- Audit tasks are completed throughout an engagement and provide documented evidence that the organization is complying with external regulations and internal policies.
      • Create Audit Engagement -- Audit managers create engagements to manage audit information and collect entities, controls, and control tests that are relevant to the audit.
      • Audit Report Generation -- Generate an audit report and maintain different versions of audit reports from an engagement in Follow up state.
      • Copy Audit Engagement -- Audit managers can create engagements from previous engagements to reduce the need to redefine the scope, auditors, and approvers for similar engagements that are conducted throughout the year.
      • Control Test Creation -- After defining a control, audit managers create control tests that run periodically and provide documented evidence of whether the associated control is operating correctly.
      • Auto Control Test Creation -- After adding an entity to an engagement, you can automatically generate control tests.
      • Audit Task Activity Creation -- After defining a control, audit managers create activities that explore and provide documented evidence of whether the associated control is operating correctly.
      • Audit Interview Task -- After defining a control, audit managers create interviews with control owners to discuss and provide documented evidence of whether the associated control is operating correctly.
      • Audit Walkthrough Task -- After defining a control, audit managers create walk throughs that will be conducted to observe and provide documented evidence of whether the associated control is operating correctly.
      • Audit KB Article Creation -- Audit managers can generate a KB article that summarizes the findings of an engagement so report findings can be communicated to executives.
      • Engagement Approval Actions -- Audit users that are assigned as approvers for an engagement can approve or reject engagements in the Awaiting Approval state.
      • Add Engagement Entities -- Audit managers can define which entities are involved in the audit engagement. When you add an entity to an engagement, the corresponding risks, controls, test plans, and indicator results of the entity are also added to the engagement.
      • Use the Audit Engagement -- The Engagement Workbench provides a timeline view from which you can select an audit engagement to view details or create a new engagement.
      • Workbench Engagement Setup -- The Engagement Workbench provides a timeline view from which you can select an audit engagement to view details or create a new engagement. Audit managers create engagements directly from the Workbench to manage audit information and collect entities, controls, and control tests that are relevant to the audit.
    • Cloud Document Management -- You can manage your documents and work papers with Audit Management as cloud files using cloud providers like Microsoft instead of attaching them to the record.
      • Prerequisites to Manage your Documents using Microsoft -- Complete the prerequisites to manage your documents using Microsoft so that you can enable the cloud file integration.
      • Cloud File Access Setup -- The GRC Workspace administrators can create a Cloud file configuration on engagements and audit tasks from the Cloud file configuration module.
      • Cloud File Configuration -- Create a cloud file configuration record to manage the access permissions on the cloud document.
        • Cloud File Form Setup -- Update the access permissions for a record in the Cloud file configuration record form.
      • File Access Permissions -- Create a File access permission record and manage the access permissions on the cloud document.
        • File Access Form Setup -- Update the File access permission record form for a Cloud file.
        • File Access Configuration -- The Workspace administrators with the sn_grc_workspace.admin role can configure the file access permissions for the users and groups.
      • Cloud File Upload -- Upload local documents from your local to Microsoft cloud and manage the access to the cloud files.
      • Link Cloud File -- Link a cloud file on Microsoft using file path and file name with a GRC ​record in the Workspace.
      • Link a reference cloud -- Link a reference cloud file that is already associated to other GRC records.​ You can link shareable files​ only.
      • Mark a cloud file -- Select one of the already linked files and mark it as a non-sharable file. Once a cloud file is marked as non-sharable, it cannot be linked to another record, or it cannot be referenced by any other record​.
      • Mark a cloud file as shareable -- Select one of the non-sharable files and mark it as sharable. Once the cloud file is marked as shareable, it can be linked to another record, or it can be referenced by other records.​
      • Remove a linked cloud -- Remove a linked cloud file from a record in the Audit Workspace.
    • Risk Monitoring & Indicators -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. Supporting information can be collected for those indicators through automatic data collection or manual tasks. Indicator results are then used to create issues for controls, update risk scores, and provide supporting information for audit activities and control testing.
      • Audit Engagement Overview -- The Engagement Overview is contained in the Audit Management application and provides an executive view into audit results, engagement breakdowns by task, and allows areas of concern to be identified quickly.
      • Create a GRC indicator -- Create an Indicator to monitor the controls and risks and collect evidence of performance.
      • Create GRC indicator template -- Compliance or risk managers create indicator templates from which many indicators can be created.
    • Confidentiality flag for Audit -- You can set the confidentiality flag at the record level for an issue, engagement, observation, control test, activity, interview, and walkthrough records. The users whom you determine to view and update these records are allowed users.
    • Audit Issues & Remediation -- Issues can be created manually to document audit observations or remediations, or to accept any problems. They are automatically generated from indicator results, attestation results, or control test effectiveness.
      • Manually create issues -- As a GRC user, you can manually create issues to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.
      • Issue form -- Use the Issue form to create a new issue.
    • Audit Evidence Request -- Evidence request is used by audit and compliance teams for requesting supporting documents during an audit. Auditors and compliance teams require these documents from the first line of defense.
      • Evidence request workflow -- Evidence request helps customers to electronically request the information that they need from the first and second line of defense. The individuals being audited can then immediately upload their documents to the system, significantly reducing manual processing time.
      • Request evidence for audit -- Request evidence at any stage during an audit. The details about the items for which evidence is requested are also provided to the person responsible for providing the evidence.
      • Provide requested evidence -- Provide evidence when you are requested. When evidence is requested, the person who must provide the evidence receives an email. The process to provide the evidence begins.
      • Approve evidence before evidence -- Approve the evidence being provided before the requester views the evidence. When evidence is provided in response to an evidence request, the evidence may need an approval before the evidence is sent back to the requester. This ability ensures security and confidentiality of the evidence.
      • Accept, reject, or cancel -- Accept, reject or cancel an evidence request when you receive the evidence you requested. After requesting an evidence request, when the requester receives the evidence, the requester can accept, reject, or cancel the evidence request.
    • Audit Plan Overview -- An audit plan enables you to plan all your audit engagements in a systematic and logical manner.
      • Create an audit plan -- Create an audit plan to manage different types of audits in a periodic manner and group engagements in a logical manner.
      • Approve a plan -- Approve a plan if you're assigned as an approver after plan creation. You can also request that the plan be reviewed or request more information about the plan from the plan creator.
      • Engagement with advanced planning -- Use the advanced planning capabilities to create an engagement that automatically creates an engagement project. After an engagement project is created, you can add resource plans and cost plans to the engagement. The values of these plans roll up to the engagement and to the audit plan.
      • Add auditors for an engagement -- Assign audit tasks to auditors in an engagement from the resource plans. Resource plans track the cost associated to auditors. Considering this cost is important while planning the engagement.
      • Create an auditable unit -- Create auditable units with entities such as business units, departments, vendors, products, business processes, business applications, locations, authority documents, and policies to perform risk assessments on the auditable units.
      • Audit Types Overview -- There are many types of audits and each of the audit types has a specific use in an audit engagement.
    • Audit Milestone Management -- Milestones can be used to track the progress of an engagement.
    • Audit observations -- Audit observations are the results of an audit. As an important part of the audit report, audit observations represent the results of reviews, analysis, interviews, and discussions.
    • Audit Expense Rollup -- Any audit project has associated costs, budgets, and resources. Roll ups of these costs, budgets, and resources enable the audit manager to view the entire costs and resources in a consolidated manner.
    • Integrating Audit Management with Time Card -- Audit users and audit managers can now use the Time Card Management feature to log and capture hours for engagements and other tasks on an engagement.
    • Audit Workspace Overview -- Audit workspace is a single-pane view for audit supervisor and auditor to view the overall audit timeline and status, track budget and resources for engagements, trace high priority observations and issues, and monitor ongoing control testing and audit task progress.
    • Audit Supervisor Workspace -- An audit supervisor organizes and manages internal audits according to plans.
      • Create a test template -- Create a test template and use it to create test plans applying much of the same testing criteria.
      • Create a test plan -- Create a test plan to document the control testing procedure. You can create a test plan from scratch or based on a test template to describe how a feature is to be tested.
      • Create a plan -- Create a plan to manage different types of audits in a periodic manner and group engagements in a logical manner.
      • Create an audit engagement -- Create an engagement in the workspace and assign it to an audit supervisor. Use the workspace to schedule the engagement, plan the details, and budget the expenses.
      • Manage an engagement from -- After you create and save an engagement with the basic information such as the description, dates, scope, and the objectives, you can see the overview page.
      • Create an auditable unit -- Create auditable units to identify business entities that can possibly be at risk and scope them into audits.
      • Create a milestone for an engagement -- Create a milestone for an engagement to track the progress of an engagement. You can also add audit tasks to a milestone.
      • Audit Task Management -- Audit tasks are completed throughout an engagement and provide documented evidence that the organization is complying with external regulations and internal policies.
      • Create a control test -- Create a control test that runs periodically and provides documented evidence of whether the associated control is operating correctly or not.
      • Create an activity -- Create an activity that explores and provides documented evidence of whether the associated control is operating correctly or not.
      • Create an interview -- Create an interview with control owners to discuss and provide documented evidence of whether the associated control is operating correctly or not.
      • Create a walkthrough -- Create and conduct a walk through to observe and provide documented evidence of whether the associated control is operating correctly or not.
      • Add entities to an engagement scope -- Add entities related to the selected auditable units to the engagement. In addition, you can also add entities other than the ones created for auditable units to the engagement.
      • Create an issue -- Create an issue to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.
      • Request evidence during audits -- Request evidence at any stage during an audit using the Audit Workspace. The details about the items for which evidence is requested are also provided to the person responsible for providing the evidence.
      • Request evidence using Audit -- Request evidence at any stage during an audit using the Audit Workspace. The details about the items for which evidence is requested are also provided to the person responsible for providing the evidence.
      • Audit observations in Audit -- Audit observations are the results of an audit. As an important part of the audit report, audit observations represent the results of reviews, analysis, interviews, and discussions.
      • Create an observation -- Create an audit observation to present a summary of problems, discoveries, and recommendations. The audit team can then review the observations to determine if the observation is a reportable issue.
    • Audit Workspace Limited -- The Lite Audit workspace is a simplified version of the Audit Management workspace. In this workspace, you can access engagements, add existing entities to an engagement, and create activities. If the advanced core store app is installed, evidence(s) can also be associated with the engagement.
    • Create the Tests step -- Apply the objective effectiveness of the test step and the operating effectiveness, desired effectiveness of the control test to determine the control effectiveness of the control test. A test step is applied to check the control test at a granular level.
    • Create test step plans -- Create a test step plan from the Audit Workspace by selecting a test plan, opening the Test step plans tab, and entering details like identifier and assessment objective.
    • Create test step templates in the test templates -- Create and add a test step template to a test template from the Audit Workspace to define control assessment steps.
    • Approve or reject an engagement in Audit Workspace -- If you are an audit user and are assigned as an approver for an engagement, you can approve or reject an engagement in the Awaiting Approval state.
    • Generate an audit report for an engagement using Microsoft Word template -- Generate an audit report for an engagement record using Microsoft Word template that is in the Validate state or any subsequent states. You can manage the generated report either on cloud (Microsoft SharePoint) in the Cloud files tab or as a sys_attachment to the engagement.
      • Create a Microsoft Word template record for an audit report -- Generate your audit reports for an engagement in Microsoft Word template to collaborate with your auditors in an effortless and user-friendly manner.
      • Word template form -- The table gives a description of the field values for the Word template form.
      • Word template category form -- The table gives a description of the field values for the Word template category form. Template categories enable you to categorize similar reports and filter them accordingly. For example, Audit or CAM is a category.
    • Generate a report for an engagement in a classic report template -- Generate a report that summarizes the findings of an engagement to communicate the report findings to executives.
    • Audit Workspace for the Auditor -- The auditor workspace is a centralized workspace for managing audit activities.
    • Audit Management reference -- The following sections show the roles and access limitations to the tables used in Audit Management.
    • Components installed with Audit Management -- Activating the GRC: Audit Management (com.sn_audit) plugin adds or modifies several tables, user roles, and other components.
    • Roles required for Engagement project planning for Project Portfolio Management -- The advanced planning capability enables integration of Advanced Audit with the Project Portfolio Management (PPM) product. The capability creates an equivalent project for the engagement, and provides planning features that could be used for resource planning, cost planning, and so on, from the engagement project.
    • Roles required for Advanced planning capability -- The advanced planning capability enables integration of Advanced Audit with the Project Portfolio Management (PPM) product. The capability creates an equivalent project for the engagement, and provides planning features that could be used for resource planning, cost planning, and so on, from the engagement.
    • Domain separation and Audit Management -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conkeyref at the end that describes domain separation.Domain separation is supported for Audit Management. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Analytics and Reporting Solutions for Audit Management -- Platform Analytics contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.
    • Audit Engagement Overview Performance Analytics dashboard -- The Audit Engagement Overview dashboard provides an executive view into audit results and engagement breakdowns by task, allowing areas of concern to be identified quickly.
    • Audit Manager Performance Analytics dashboard -- The Audit Manager dashboard provides the current view of audit engagements and related audit activities. Users with the sn_audit.manager role can view this dashboard. This Audit Manager dashboard is part of the Advanced GRC dashboard.
  • Business Continuity Management -- ServiceNow Business Continuity Management application gives your organization the capability to continue to deliver products and services at an acceptable level when a disruptive incident occurs. The ongoing activities of this application are aimed to reduce the operational risks and improve your organizational ability to respond, react, and recover from issues and disruptions.
    • Explore -- Learn how you can use the Business Continuity Management application to manage continuity tasks through predefined templates and structured workflows. The application helps you analyze business impact, develop continuity plans, test your readiness through exercises, and respond to real‑world crises.
    • BCM Configurable Workspace -- Starting with version 5.x.x, the Business Continuity Management application supports BCM Configurable Workspace. You can perform your business continuity tasks with an intuitive functionality in BCM Configurable Workspace.
      • Home page view -- The Home page in Business Continuity Workspace serves as the landing page of the BCM application.
      • My tasks page view -- My tasks page displays a single-pane view of your pending tasks, tasks assigned to your user group, and the tasks that are on your watchlist.
      • List view -- The List view in the BCM Configurable Workspace displays BIA, planning, exercise, and crisis event records along with their key metrics. You can filter records, create new ones, and open them to display the scope of all BCM functional components and their key metric information.
      • Crisis map view -- When you install the GRC: Crisis map application in your instance, you can view the Crisis map icon in the List view. You can integrate the Crisis map application with BCM and analyze real-time threat alerts from different locations in a map view. You can then take remedial actions and manage the crisis events from Business Continuity Workspace.
    • Business impact analysis -- Business impact analysis is a structured process where you assess the impact categories and dependencies and predict the consequences of a disruption on a business process or business function.
      • Use cases for BIA -- You can use the Business Continuity Management application to assess the impact of a downtime on your business services or processes and technical entities such as datacenters or applications. For creating a business impact analysis for your organization, you can refer to the common use cases that are used for managing the business continuity tasks.
      • Business impact analysis -- The Business Continuity Management application provides pre-configured business impact analysis (BIA) templates for creating a business impact analysis. If you are the BCM or BIA administrator, you can use the BIA Templates module in the Business Continuity Management application. You can then select the type of the template, elements, impact categories, and so on, for the business impact analysis.
      • Grid configurations and categories -- You can set up the grid configuration to render the BIA dependency assessment grid with configured columns. You can define the grid category such as Dependency Assessment for which the grid configuration is applicable.
    • Business continuity planning -- Business continuity planning helps you enact and mitigate risk at the time of an event. You can address and plan on the primary scope of the activities, documentation, loss scenarios, recovery teams, approvals, and so on. You can then configure a structured workflow of your business continuity planning tasks in BCM UIB Workspace.
      • Assets and plans -- You can identify the assets and plans related to a business continuity plan. You can then recover the assets in your planning stage. Reuse the configuration item relationship data that flow from CMDB to business impact analysis (BIA) during dependency assessment to identify the assets in your plan.
      • Recovery teams, loss scenarios -- Business continuity planning workspace guides you to complete your business continuity plan. You can create a recovery team, define roles for the users, and direct the team to execute the plan. When you create a continuity plan for a department or a business unit, it is necessary to identify the loss scenarios to the business continuity plan.
      • Use cases for business continuity planning -- This section describes the common use cases that are used for business continuity planning in the Business Continuity Management application. You can deploy these use cases individually or you can combine them to meet your specific needs.
    • Element definitions and variables -- An element definition is a configuration item that is assessed in the business impact analysis. The element definitions are also recovered in the business continuity plan. If you have the administrator role, you can set up an element variable that is required for a particular dependency of an element.
    • Exercises -- Exercises are used to provide continuous testing and improving of continuity plans. You can use the exercises to finalize your business continuity plan and improve its effectiveness and usability in an actual crisis event. You can manage your exercises in BCM UIB Workspace.
    • Crisis events -- Managing a crisis event in BCM UIB Workspace helps you to minimize the downtime of critical business functions and processes across your organization. It is also used to minimize the financial, reputation, legal, and regulatory impact during a crisis event.
    • Crisis map interface -- You can integrate Crisis map with the BCM application and initiate the response workflows for crisis management. After installing the Crisis map application, you can view the Threat and Alert Data Feeds module in your BCM application instance.
    • Emergency notifications in Everbridge -- You can integrate Crisis Management in the BCM application with Everbridge notifications system. You can then send an emergency notification to an individual or a group of people alerting them of an impending emergency. It provides a one-way notification and two-way communication through properly established delivery channels.
    • Configure -- Configure the Business Continuity Management application to perform the business continuity tasks for your organization.
    • BCM and ServiceNow Store -- Business Continuity Management applications are available from the ServiceNow Store, enabling you to obtain new and updated features more rapidly. Before you can use the Business Continuity Management applications, you must verify that you have an entitlement to use them.
      • Get entitlement for the BCM application -- The first step in installing an application is to verify that the application or the product and its associated applications have valid ServiceNow entitlements.
      • Install BCM from ServiceNow Store -- You can install the Business Continuity Management application if you have the admin role. This application includes demo data and installs the related store applications if they are not already installed.
      • BCM lite operators -- The Business Continuity Management application provides flexible user licensing terms. The terms are based on whether your operator has read-only access or can complete certain types of tasks.
    • General administration setup for BCM -- If you are the BCM administrator, you can set up the Business Continuity Management application by performing certain administrative tasks.
      • Dependency Configuration records -- The BCM administrators configure the Dependency Configuration records.
      • Configuring impact analysis dependency updates -- The BCM administrators configure the Impact analysis dependency update configuration record so that an auto-update of the BIA dependencies can be scheduled based on the source data and relationships in the CMDB.
      • Configuring planning dependency updates -- The BCM administrators configure the Planning dependency update configuration record so that an auto-update of the related assets in the plans can be scheduled based on the source data and relationships in the CMDB and BIA.
        • Set up Planning dependency update configuration -- Configure the Planning dependency update configuration record to configure the plan record (for which the dependencies are updated), its target records, sources, and notification preferences.
        • Planning dependency update configuration form -- Use the Planning dependency update configuration form to configure the plan record, its sources, and preferences such as the plan record name, sources, and notification preferences and schedule an auto-update of the related assets in the plans.
      • Configuring sources for adding event dependencies -- The BCM administrators configure the sources in the Event dependency source configuration record so that the impacted assets are added in the events and exercises based on the source data and relationships in the BIA, CMDB, and plans.
      • Configure impact category for BIA -- Configure an impact category for your business, when you are performing the business impact analysis. Use the Impact Categories module in the Business Continuity Management application navigator to define the name, criteria that the impact category contributes to, applicable timeframes, maximum RTO value, and so on.
      • Impact Category record form -- Use the Impact Category record form to add details about the impact category such as name, criteria that the impact category contributes to, applicable timeframes, maximum RTO value, and so on in BCM UIB Workspace.
      • Configuring the documentation section -- You can configure the documentation section of a business continuity plan in a structured format. You can describe high level details of the plan such as its purpose, scope, coverage areas, goals, and success criteria.
      • Configure documentation section -- Configure the documentation section to describe your plan through structured components: a high-level checklist, purpose, scope, and coverage areas.
      • Configure element definition -- Configure element definitions to identify the configuration item that has to be assessed in a business impact analysis and recovered in a business continuity plan. Use the Element Definitions module in the Business Continuity Management application navigator to configure an element definition.
      • Element definition record form -- Use the Element definition record form to configure a recovery tier with a set of business applications by using BCM UIB Workspace.
      • Configure element variables for element definitions -- Configure an element variable for a specific dependency of an element. To do this, use the Element variables module in the Business Continuity Management application navigator.
      • Element variable record form -- Use the Element variable record form to configure an element variable. Element variables are custom elements that are used in the Grid configuration. You can set up an element variable that is specific custom columns, which are required for a particular dependency of an element.
      • Configure loss scenarios in the plan -- Configure a plan for an identified loss scenario by using the loss scenario template in the Business Continuity Management application. Use the documented plan that has the needs and requirements listed for a potential disaster.
      • Loss Scenario record form -- Use the Loss Scenario record form in BCM UIB Workspace to configure a plan for an identified loss scenario.
      • Configure impact ratings -- Configure an impact rating to assess an impact category as low, moderate, high, or critical. Use the Impact Ratings module in the Business Continuity Management application navigator to help you measure the intensity of the loss when a business downtime occurs.
      • Impact Rating record form -- Use the Impact Rating record form to assess an impact category such as low, moderate, high, or critical by using BCM UIB Workspace.
      • Configure recovery tiers for BIA -- Configure a recovery tier with a set of business applications that follow a similar range of recovery time objective (RTO) values. Use the Recovery Tiers module in the Business Continuity Management application navigator to configure a recovery tier.
      • Recovery Tier record form -- Use the Recovery Tier record form to configure a recovery tier with a set of business applications by using BCM UIB Workspace.
      • Set up recovery timeframes -- Set up a recovery timeframe for a recovery tier. The recovery timeframe starts from when a disruptive event happens to the time when your business can resume usual operations. You can use the Recovery Timeframes module in the Business Continuity Management application to set up the timeline for the recovery timeframe.
      • Configure grid categories -- Configure a grid category such as Dependency Assessment for the grid configuration. Use the Grid Categories module in the Business Continuity Management application navigator to configure the grid categories.
      • Grid category record form -- Use the Grid category record form to configure a grid category such as Dependency Assessment for the grid configuration by using BCM UIB Workspace.
      • Configure grid for BIA assessment -- Configure the grid to render the BIA dependency assessment grid with configured columns. Use the Grid Configurations module in the Business Continuity Management application navigator to configure the grid.
      • Grid configuration record form -- Use the Grid configuration record form to set up the BIA assessment grid in the classic Workspace.
      • My tasks page configurations -- If you are the Business Continuity Management application user, you can use My tasks page configurations in the General Administration module to view your assigned tasks.
      • Approval configuration -- Approver configurator provides you with capabilities to define multiple levels of approvals based on business rule definitions.
      • Set up approval configuration -- Set up approval configuration to enable multiple levels of approvals and select approvers for each level based on approval rules.
      • Set up approval levels -- Assign multiple levels of approvals to users or groups to support each step of your BIA, BCP, or events workflow processes.
      • Set up approval rules -- Set up rules for approvals at each approval level by selecting an approver type and the requirement of approval from either one or all the stakeholders. Define filter conditions on the source table to which the approval rule is applied.
      • BCM properties -- You can configure the BCM properties in the Properties module.
      • Properties installed with BCM -- Properties are added with the activation of Business Continuity Management.
    • Setup for a BIA -- The administrative tasks that are associated with a business impact analysis (BIA) are listed in General Administration of the Business Continuity Management application.
      • Configure BIA templates -- Configure a business impact analysis (BIA) template in the Business Continuity Workspace with a legacy assessment. Select the type of elements, impact categories, and dependencies to be assessed. The legacy assessment uses the older method of selecting impact categories.
      • BIA template form -- Use the BIA template form to configure the business impact analysis with the legacy template. You can add details such as name, description, elements, impact categories, and so on in the form.
      • Create Smart Assessment templates for BIA -- Create Smart Assessment templates in the Assessment Workspace for the Business Impact Analysis (BIA) workflow.
      • Configure RTO and RPO Smart Assessment templates workflow -- Configure Recovery Time Objective (RTO) and Recovery Point Objective (RPO) assessments using the Smart Assessment Engine for Business Impact Analysis (BIA). The Smart Assessment Engine replaces the traditional non-smart assessment questionnaires with an automated, rule-based approach.
      • Configure BIA templates with SAE -- Configure a business impact analysis (BIA) template in the Business Continuity Workspace with the Smart Assessment. Select the type of the elements, impact categories, and dependencies that are assessed in the BIA. The Smart Assessment lets you choose a custom Smart Assessment template for the BIA.
      • BIA template record -- Use the BIA template record form to configure the business impact analysis with the Smart assessment. You can add details such as name, description, primary element assessed and select the impact assessment template in the form.
    • Setup for a BCP -- The business continuity plan (BCP) administrator can perform certain administrative tasks that are listed in the General Administration section of the Business Continuity Management application.
      • Configuring plan template -- As a BCP plan manager, you can create a business continuity plan that can be used for your respective business units during a disruptive event. The Business Continuity Management application provides pre-configured business continuity plan templates. You can streamline the process of a plan creation by using pre-configured plan templates. You can also create a plan template for your business requirement.
      • Configure the BCP template -- Configure the business continuity plan template in the Business Continuity Management application for your business. You can use the plan template to recover a specific primary element such as Employees or Web Servers. Similarly, you can create a plan template for different plan authoring types such as documentation, loss scenarios, and recovery tasks.
        • Plan Template form -- Use the Plan Template form in BCM UIB Workspace to input details regarding the business continuity plan.
      • Configure Task templates and Task template groups -- Create task templates and task template groups to save individual tasks or groups of tasks for reuse. Add templates to new plans or insert them into existing ones.
        • Task template form -- Use the Task template form to define a reusable recovery task or event task that can be inserted into plans, loss scenarios, recovery strategies, exercise events, crisis events, or activated plans.
        • Task template group form -- Use the Task template group form to bundle related task templates and define dependencies between them. Apply the group from a plan, loss scenario, recovery strategy, exercise event, crisis event, or activated plan to create the underlying tasks in bulk.
    • Set up the phases -- Set up the phases in the Business Continuity Management application to map them to recovery and event tasks effectively. Once the phases are set up, BCM users can tag these phases to recovery tasks and event tasks and execute them in the set order, ensuring a logical execution sequence.
      • Phase form -- To configure phases as part of recovery activities, use the Phase form to set up phases for recovery and event tasks in the BCM Configurable Workspace. You can then associate these phases with recovery and event tasks, enabling you to track their progression effectively.
    • Generating reports using Document designer -- Starting with BCM release 9.0.x, the ServiceNow Document designer with Microsoft Word application (sn_grc_doc_design) is integrated with BCM. It enables you to generate customized reports of the business impact analyses (BIAs), business continuity plans (BCPs), and events in Microsoft Word format. This integration resolves the improper page breaks and truncated content that occasionally appeared in PDFs generated by the previous template.
      • Install Document designer with Microsoft Word -- Install the Document designer with Microsoft Word (sn_grc_doc_design) application. It extracts metadata (including fields, related lists, and reference fields with their associated elements) from ServiceNow tables and enables the insertion of repeating content blocks (for example, 10 blocks for 10 issues) based on record count. When applied to specific records, the template generates a Microsoft Word document.
      • Set up the template configurations -- Set up the template relationship registry using the Template Configurations module from the General administration setup. Configure data relationships, content configurations, and scripted variables for using the Document designer application so that required data gets displayed in the reports.
      • Configuring the data relationships -- Configure the data relationships in the Template Configurations module, which helps you to navigate from a record in the template configuration to any table. When you create these paths, you can fetch necessary data from each of these records in the BCM report template.
      • Set up the content configurations -- Set up the content configurations in the Template Configurations module to define the data you want to view or fetch when creating a report template. You can configure it to display a list of records or aggregated data, such as a list of remediation tasks or top priority issues. You can fetch up to 200 records from any table.
      • Define the scripted variables -- Define data for the scripted variables using the Template Configurations module for creating a report template in the BCM application. You can configure the data in either text or HTML format.
      • Manage Microsoft Word document templates -- Manage Microsoft Word document templates centrally using the Admin module in the BCM application. This feature enables you to create or edit templates for BIA, BCP, or other events, providing customized and controlled document generation.
      • Microsoft Word template form -- Use Microsoft Word template form to add details about Microsoft Word template for creating reports in the Business Continuity Workspace.
      • Install the Document designer add-in -- Install ServiceNow Document designer add-in in Microsoft Word. You can then customize the BIA, BCP, event reports, and Microsoft Word templates according to your business needs.
      • Save Microsoft Word document as template -- Save your Microsoft Word document as a template using the Design template provided in the Document designer, enabling you to create a reusable template in your instance.
      • Generate reports for the BIAs, BCPs, and events -- Generate customized reports for BIAs, BCPs, and events directly from their respective records in Microsoft Word format. This functionality enables you to streamline reporting of impact analyses, plans, and events within your organization.
    • Format PDF templates for BIAs, BCPs, and Events -- Format the PDF templates that are used for generating the PDFs of business impact analyses, business continuity plans, or events. You can format the PDFs according to your organizational requirements and templates.
    • Configure 360° relationship registries and views -- Configure 360° view configurations with the sn_bcm.admin role.
    • Setup for Everbridge notifications -- The setup steps help you to establish a consistent connection and successful notification delivery workflow with Everbridge notifications system. BCM administrators and application users must configure certain pre-requisite data so that you can set up emergency notifications in BCM UIB Workspace.
      • Create connections and authenticate credentials -- Establish a connection and authenticate your login credentials with an Everbridge instance. You can then send out a notification using the delivery channel. This connection helps you to send and receive communications with an Everbridge instance.
      • Create Connection and Credentials form -- Use the Create Connection and Credential form to establish a connection and authenticate your login credentials with an Everbridge instance.
      • Import the delivery channels -- Import the delivery channels from the Everbridge instance. You can then easily send the notifications through the delivery channels.
      • Import the record types -- Import the record types for your organization ID from Everbridge and use them to create the contacts for notifications.
      • Create templates for emergency notifications -- Create a template with pre-defined information. You can then use it to send the notifications to your users in an emergency.
      • Notification Template form -- Use the Notification Template form to create a template with pre-defined information for sending out the notifications.
      • Create contacts for emergency notifications -- Create the contacts manually to send out an emergency notification and synchronize them with the Everbridge instance.
      • Contact form -- Use the Contact form to create the contacts manually and then synchronize the contacts with Everbridge.
      • Create the contact import rules -- Create a contact import rule to apply on the User table. You can then filter out the users as the contacts for emergency notifications.
        • Contact Import Rules form -- Use the Contact Import Rules form to create a contact import rule that you can apply on the User table.
      • Create notification contact groups -- Create a notification contact group using the ServiceNow AI Platform groups. Use the group members as the contacts for an emergency notification. Synchronize the group members as the contacts with Everbridge and track the non-synchronized members as exceptions.
      • Notification Contact Group form -- Use the Notification Contact Group form to create a notification contact group.
    • Setup for Crisis map -- BCM administrators perform the administrative tasks to set up the Crisis map interface.
      • Customization properties -- The Crisis map application users can configure the customization properties for Google Maps in the Google Maps Properties module.
      • Customization properties table -- Customization properties for Google Maps are explained in the Google Maps Properties table.
      • Google Maps APIs -- The Fam-map component in Crisis map utilizes various Google Maps APIs to provide interactive mapping functionalities. This section lists the Google Maps APIs that are integrated into the Fam-map component, along with their usage information.
      • Configure Scheduled Imports -- Configure a Scheduled Data Imports record for the Crisis map application. You can then manage your subscriptions to the threat feeds from an internal or external source in the BCM Configurable Workspace.
      • Scheduled Data Imports form -- Use the Scheduled Data Imports form in the BCM Configurable Workspace to add details about a Scheduled data imports record.
      • Configure Resource Configuration records -- Configure a Resource Configuration record for the Crisis map application in UIB Workspace. You can then plot the assets of your organization on the Crisis map. The assets can be locations, employees, datacenters, suppliers, and others. Configuring resources is also required as an input to set up the alert rules.
      • Resource Configuration form -- Use the Resource Configuration form in BCM UIB Workspace to add details about a resource configuration record.
      • Configure alert rules -- Configure an alert rule in the Crisis map so that you can define when a feed is displayed as an alert on the dashboard. You can also specify the conditions under which an alert is no longer valid and dismiss it from the dashboard.
      • Alert Rules form -- Use the Alert Rules form in BCM UIB Workspace to add details about the alert rules.
      • Configure alert actions -- Configure an alert action from the Crisis map interface in the BCM Configurable Workspace.
      • Alert Action form -- Use the Alert Action form in BCM UIB Workspace to add details about the alert actions.
    • Setup by system administrators -- If you are the system administrator, you can set up the Business Continuity Management application by performing certain setup tasks.
      • Update number of records for reference fields -- Update the number of the records that are displayed for a reference field in the Business Continuity Management (BCM) Workspace. You can configure the referenceFieldLoadLimit system property to control the number of the records that are displayed for each reference field on the grid configuration pages.
      • Update count of element definitions -- Update the number of the element definitions that are displayed on the Dependency Assessment tab in the Business Continuity Management (BCM) Workspace. You can configure the dependencyAssessmentElementsLimit system property to control the number of the element definitions that are used for the dependency assessment in a business impact analysis.
      • Application menu options -- The table lists the application menu options that are available for the main users of the business continuity management application to view and navigate.
    • Setup for the UI Builder -- You can set up and extend the BCM Workspace pages and components by using the UI Builder.
    • BCM implementation -- Use the steps in the Business Continuity Management application checklist to download the Business Continuity Management from the ServiceNow Store, and get it ready for operation.
    • BCM in the Classic Workspace -- Setting up the Business Continuity Management (BCM) application for use requires configuring certain pre-requisite data.
      • Element definitions in Classic Workspace -- Configure element definitions to identify the configuration item that has to be assessed in a business impact analysis and recovered in a business continuity plan.
      • Impact rating in Classic Workspace -- Configure a rating for each category to help you measure the intensity of loss when a business downtime occurs.
      • Recovery tier in Classic Workspace -- Configure and use recovery tier to assign a single recovery time and name to a similar range of recovery time objective (RTO) values.
      • Grid configuration -- Grid configuration for column display helps you to capture specific columns in the dependency grid that corresponds to an element.
      • Set up element variable -- As a functional system administrator, you can set up an element variable that is specific custom columns, which are required for a particular dependency of an element.
      • Set up grid configuration -- Set up the grid configuration to render the BIA dependency assessment grid with configured columns.
      • Set up recovery timeframe -- Set up recovery timeframe that starts from when an incident or crisis happens to the time your business can resume usual operations.
      • Configure a documentation section -- Configure a documentation section of a plan to describe the plan in structured sections providing a checklist of high level details, purpose of the plan, scope describing purpose of the plan and coverage areas, its goals and success criteria.
      • Configure a plan for a loss scenario -- Loss scenarios are identified and documented so that the plan has the needs and requirements listed for any particular disaster that may strike. Each potential threat requires unique recovery steps and the need for each loss scenario vary. Your plan must be well laid to maintain operations for any potential impacted loss.
      • Configure a BIA template -- Define the business impact analysis (BIA) template to create and assign BIAs with standard object types. The object types can be business processes, applications, facilities, and others, the impact of which are assessed in a BIA.
      • Configure a BCP template -- Configure the business continuity plan (BCP) template to create and assign business continuity plans with standard object types. The object types can be business processes, applications, employees, hardware, software, and others.
      • Configure an impact category -- Configure an impact category to define the timeframe during which the organization would experience a downtime of its business processes. Based on the timeframe, you can determine the recovery time objective (RTO) of the assets that the business process depends on.
    • Manage -- You can use the features and capabilities of the Business Continuity Management application and manage business continuity workflow tasks in BCM Configurable Workspace.
    • Structured workflows for BIAs -- Perform the tasks that are outlined in this section to create a business impact analysis in Business Continuity Workspace (also known as BCM Configurable Workspace).
      • Impact categories and ratings -- Impact categories are the types of an impact that you can assess during a business impact analysis. The BCM administrator of an organization is responsible for defining the impact categories and the timeframe during which an organization may experience a downtime. This information is used to determine the recovery time objective and recovery point objective of the assets.
      • RTO, RPO, and recovery tiers -- Due to unforeseen disruptive events, the business processes in your organization can face a downtime. It is important to classify your business processes in the recovery tiers and calculate the amount of time and amount of data loss that your organization can handle without significant effect on the operations.
      • Calculating RTO and RPO -- The BCM application provides an assessment questionnaire for calculating the recovery time objective (RTO) and recovery point objective (RPO) in the business impact analysis (BIA). As a pre-requisite to the BIA, BCM administrator defines the impact ratings and sets up the assessment questions. After receiving the responses to the assessment, the BCM application calculates the RTO and RPO.
      • BIA states and UI actions -- When you create a business impact analysis (BIA), certain UI actions are associated with each state.
      • Configuring dictionary, UI policy, and element variables -- Starting with Release 6.1.x, administrators have the capability to configure different aspects of a dependency. This includes the Dictionary, UI policy, element variables, and UI view. These configurations play a crucial role in determining specific columns, required fields, and overall display in the list view and form view of a dependency within the dependency assessment of a BIA.
      • Using latest assessment for conducting BIAs -- Beginning with the Yokohama release, you can use the latest assessment template for conducting a Business Impact Analysis (BIA). The BIA template is now integrated with the Smart Assessment Engine, enabling you to use the Smart Assessment along with the legacy assessment.
      • Create a business impact analysis -- Create a business impact analysis in BCM UI Builder Workspace to get the necessary information for a plan.
      • Create New Impact analysis form -- Use the Create New Impact analysis form to add details about the business impact analysis, assessments, approvals, and so on in BCM Configurable Workspace.
      • Scheduling an auto-update of dependencies -- You can schedule an auto-update of the dependencies in the business impact analysis based on the source data and relationships in the CMDB. You can receive an email notification with details of the BIA dependency updates from the BCM application.
      • Update the BIA dependencies -- Update the business impact analysis (BIA) dependencies manually from the snapshot if the scheduled job is not activated in the Impact analysis dependency update configuration module. You can update the dependencies in an active BIA.
      • Assess impact categories and dependencies -- Assess the impact categories and dependencies in BCM UIB Workspace to get the necessary information for a plan. Use the business impact analysis to identify the recovery time objective for an item and prioritize the assets that have the least and most critical dependencies. Use the information to establish their recovery strategies during the planning phase.
      • Approve the business impact analysis -- Approve the business impact analysis in BCM UI Builder Workspace in the BCM application. If you’re the business impact analysis owner or the BCM lead for the business impact analysis, you can approve the business impact analysis.
      • Update dependencies of BIAs in Self-Service -- Use the contributor role to update the impact category result, RPO Impact analysis responses, state of the impact dependency group, and the work notes in the Activity section in the BCM application.
      • Visualize 360° relationships for BIAs -- Visualize the 360° relationships for a business impact analysis and its associated entities in BCM UIB Workspace. You can access the 360° view at any time while creating a business impact analysis.
      • Generate BIA reports in PDF or Microsoft Word -- Generate a PDF or Microsoft Word copy of a business impact analysis in the BCM Configurable Workspace and save it for a future reference.
    • Structured workflows for BCPs -- Perform the structured workflows that are outlined in this section to create a business continuity plan in Business Continuity Workspace (also known as BCM Configurable Workspace).
      • States and UI actions for a BCP -- When you create a business continuity plan (BCP), certain UI actions are associated with each state.
      • Recovery strategy and task templates -- Business continuity planners often rebuild the same recovery structures each time they author a plan. Reusable templates remove that repetition by capturing standard strategies, tasks, and task groupings once and applying them wherever they are needed.
      • Create a business continuity plan -- Create a business continuity plan in BCM UIB Workspace.
      • Create New Plan form -- Use the Create New Plan form in BCM UIB Workspace to add the details about the business continuity plan (BCP).
      • Create a plan from a plan template -- Create a business continuity plan from a plan template in BCM UIB Workspace so that the loss scenarios, recovery strategies, and recovery tasks defined on the template are generated automatically.
      • Scheduling auto-update of related assets -- You can schedule an auto-update of the related assets in the plans based on the source data and relationships in the CMDB. You can receive an email notification with details of the plan dependency updates from the BCM application. Dependencies are fetched from different sources such as BIA upstream dependency, BIA downstream dependencies, and CMDB.
      • Update the planning dependencies -- Update the plan dependencies manually from the snapshot if the scheduled job is not activated in the Planning dependency update configuration module. You can update the dependencies in an active plan.
      • Add asset and scope to the BCP -- Add an asset and the scope to the business continuity plan (BCP). You can then view the primary elements in the BCM Configurable Workspace.
      • Create documentation sections -- Create a documentation section in the business continuity plan. You can then document the recovery capabilities of your business continuity plan in BCM UIB Workspace.
      • Add associated plans and recovery teams -- Add your business continuity associated plans and recovery teams to your business continuity plan. You can then view the details in BCM UIB Workspace.
      • Associating related plans to a recovery task -- You can now associate related plans with recovery tasks, making it easier to identify and manage plans during recovery. You can then use auto-generated nested plans in an event, reducing the manual effort of adding plans and improving system performance.
      • Add loss scenarios -- Add a loss scenario and define the related asset dependencies in your business continuity plan. You can then view the details of the assets in BCM UIB Workspace and then plan a recovery strategy for an identified loss scenario.
      • Add recovery strategies for dependencies -- Add a recovery strategy for the related asset dependencies and estimate the time to implement the strategy. You can then get the assets up and running quickly in an identified loss scenario.
      • Create New Recovery strategy form -- Use the Create New Recovery strategy form in BCM UIB Workspace to add details about the recovery strategy for the identified loss scenario.
      • Configure a recovery strategy template -- Configure a reusable recovery strategy template so business continuity planners can apply a pre-defined strategy to loss scenarios without re-entering the implementation details each time.
      • Recovery strategy template form -- Use the Recovery strategy template form to define a reusable implementation profile that planners can apply to loss scenarios in business continuity plans.
      • Mapping recovery tasks to phases -- Starting with BCM, version 9.x.x, BCM administrators set up active phases for plans and events, enhancing recovery and event task management. BCM managers then map these phases to recovery and event tasks, executing them in a desired, logical sequence.
      • Add recovery tasks -- Add a recovery task as part of the planned recovery strategy. You can add one or more recovery tasks for a loss scenario and those recovery tasks are displayed in the loss scenario itself. Automate the recovery tasks in a plan for a faster recovery.
      • Create New Recovery task form -- Use the Create New Recovery task form in the BCM Configurable Workspace to input the necessary details regarding the recovery task.
      • Apply Task templates and Task template groups -- Save individual tasks or groups of tasks for reuse across plans. You can add templates to new plans or inserted into existing ones. You can also generate templates directly from tasks and plans that already exist in the system.
      • Create a quick recovery task -- Create a quick recovery task from Recovery tasks or as part of the planned recovery strategy for a business continuity plan. Using the quick insert feature, you can create tasks without navigating to a separate form. Tasks can be ordered, inserted in sequence (before, after, or in parallel with existing tasks), and dependencies are updated automatically.
      • Create a quick recovery task form -- Use the Create a quick recovery task form in the BCM Configurable Workspace to insert details on the recovery task quickly.
      • Visualize recovery tasks on Gantt chart -- Use the Gantt chart component on recovery task pages to provide a visual timeline view of tasks associated with the current plan. Customize the view by adding, removing, or reordering columns as needed. The chart is implemented as a UI page to enable customizations and to support multiple versions without requiring changes to existing page behavior.
      • Synchronize assets between loss scenarios and recovery strategies -- Use the asset syncing fields in the plan template to configure whether assets synchronize to loss scenarios, to recovery strategies, or both. Syncing is a two-step process: assets flow from the plan to loss scenarios first, and then from loss scenarios to recovery strategies.
      • Automate recovery tasks -- Automate the manual recovery task within the business continuity plan. You can classify the manual recovery task as an automated task first and then attach an automated flow to it.
      • Create a subflow form -- Use the Create a subflow form to automate a manual recovery task within the business continuity plan.
      • Submit the BCP for approval -- Submit the business continuity plan (BCP) for an approval. You can then view the details in BCM UIB Workspace.
      • Visualize 360° relationships for the BCP -- Visualize the 360° relationships for a business continuity plan (BCP) and its associated entities in BCM UIB Workspace. You can access the 360° view at any time while working on the business continuity plan.
      • Generate BCP reports in PDF or Microsoft Word -- Generate a PDF or Microsoft Word copy of a business continuity plan in the BCM Configurable Workspace and save it for a future reference.
    • Structured workflows for Exercises -- Manage exercises using structured workflows in the Business Continuity Workspace (also known as BCM Configurable Workspace).
      • States for an exercise and crisis event -- This section describes the states of progression for an exercises and crisis event.
      • Event assets -- When an event is initiated, event assets are managed by using different recovery management methods.
      • Mapping event tasks to phases -- Starting with BCM, version 9.x.x, BCM administrators set up active phases in the Core UI for improved event task management. BCM users then map these phases to event tasks and execute them in the set order, ensuring a logical execution sequence. The phases can be deactivated only; they cannot be deleted.
      • Using nested plans -- Configure a system property to control activated plan levels in an event. The system automatically creates nested plans within an event, reducing the manual effort of adding plans and improving system performance. You can also add dependencies between multiple activated plans by updating the Dependencies field in the event tasks.
      • Adding dependencies of impacted assets -- You can add the dependencies of the impacted assets in the events and exercises based on the source data and relationships in the CMDB, BIAs, and plans.
      • Enhancing event task management with Hierarchical view -- The Hierarchical view for event tasks has been enhanced with several key features. It now displays dependencies between tasks, and shows color-coded states with planned start and end dates. Dependencies can be updated directly through the Hierarchical view (Gantt chart), streamlining event task management.
      • Event task creation progress -- When event tasks are created in bulk from task template groups or task templates, the Event tasks list defers refresh to avoid impacting large events. This topic explains the banner and auto-refresh behavior.
      • Create an exercise -- Create an exercise in BCM UIB Workspace. You can then test your business continuity and recovery plans on a planned date and monitor the completion of the event tasks.
      • Create Exercise Event form -- Use the Create Exercise Event form in BCM UIB Workspace to add details about an Exercise event.
      • Update the event dependencies -- Update the event dependencies manually by selecting the Update dependencies UI action. You can update the dependencies in an active event.
      • Track impacted assets and add associated plans -- Track the impacted assets and add an associated plan to the exercise. You can then monitor the assets and plans for the exercise in BCM UIB Workspace.
      • Creating action items in events -- Starting with BCM release 9.0.x, crisis managers can create action tasks for recovery members or teams anytime during a crisis event or exercise, as long as the event remains open. Crisis managers can create these tasks on the fly without mapping them to event assets or recovery plans. These action tasks are also not included in the event recovery timeline.
      • Create task and assessment-type action items in events -- Use integration of events and Smart Assessment for creating necessary action items related to an event.
      • Creating similar tasks groups -- In BCM, when the same plan is activated multiple times, it can result in multiple redundant tasks. Starting with BCM release 9.0.x, the Similar tasks groups tab in events helps you to eliminate redundant tasks by grouping duplicate tasks from multiple plans for similar scenarios. This functionality streamlines event task management and reduces duplication of efforts.
      • Create a similar tasks group -- Identify similar or duplicate event tasks associated with an event and add them to a similar tasks group by grouping them in the Similar tasks groups tab. It helps you to streamline event task management and reduce duplication of efforts.
      • State changes for event tasks in groups -- The original and duplicate event tasks in the Similar tasks group move through different states until the original task is closed.
      • Import plans and recovery tasks -- Import the business continuity plans and associated recovery tasks in the event. Using automated tasks during an exercise enhances efficiency and reduces response time for users.
      • Monitor event tasks and create ad-hoc tasks -- Monitor event task completion and create ad-hoc tasks as necessary in the exercise from the BCM Configurable Workspace. The tasks are then completed in a sequence.
      • Create New Event Task form -- Use the Create New Event Task form in BCM UIB Workspace to add details about an event task.
      • Importing and exporting event tasks in Microsoft Excel -- Use Export to download event task records into a structured Microsoft Excel file — complete with dropdowns, instructions, and field protection. Edit records offline, then use Import to upload the updated file and apply bulk changes.
      • Export data into Microsoft Excel and update the file -- Export event task records to an Microsoft Excel file, edit the data offline, and re-import the updated file to apply changes in bulk. Use this task for updating multiple event task records simultaneously outside the ServiceNow interface.
      • Import data from Microsoft Excel -- Import data such as event task records from Microsoft Excel to apply changes in bulk. Use this task for updating multiple event task records simultaneously outside the ServiceNow interface.
      • Start an event -- To initiate an event, first pull the relevant plans into the event, and then review the event tasks listed in the Event tasks tab.
      • Request an approval and approve the event -- Approve the exercise in BCM UIB Workspace.
      • View recovery tasks from Self-Service -- View the recovery tasks that are assigned to you or the recovery task team to recover assets from a crisis event or exercise. Your BCM program manager assigns the tasks to you and you can view them from the self-service application menu.
      • View 360° relationships for exercises and crises -- Visualize the 360° relationships for an exercise or a crisis event and the associated entities in BCM UIB Workspace. You can access the 360° view at any time while creating an exercise and a crisis event.
      • Generate reports in PDF or Microsoft Word -- Generate the PDF or Microsoft Word copy of an exercise or a crisis event in the BCM Configurable Workspace and save it for a future reference.
    • Structured workflows for Crisis events -- Manage crisis events using structured workflows in the Business Continuity Workspace (also known as BCM Configurable Workspace).
      • Start a crisis event -- Report a crisis event in the BCM Configurable Workspace. A crisis event is any significant disruption that threatens business operations. The BCM Configurable Workspace enables you to create crisis records, classify severity levels, set priorities, assign response teams, and document initial actions.
      • Create Crisis Event form -- Use the Create Crisis Event form in BCM UIB Workspace to add details about a crisis event.
      • Using nested plans -- Configure a system property to control activated plan levels in an event. The system automatically creates nested plans within an event, reducing the manual effort of adding plans and improving system performance. You can also add dependencies between multiple activated plans by updating the Dependencies field in the event tasks.
      • Track impacted assets and add related plans -- Track the impacted assets and add a related plan during a crisis event. You can monitor the assets and plans for the crisis event in BCM UIB Workspace. You can then recover your assets in the planning stage.
      • Add a task to the crisis event -- Add a task to the crisis event in BCM UIB Workspace. You can then monitor and complete the required actions to respond to the crisis event.
      • Import automated tasks and start an event -- Import the automated task from the business continuity plan in an actual event. Utilizing automated tasks during an actual event enhances efficiency and reduces response time for users.
      • Creating action items in crisis events -- Starting with BCM release 9.0.x, crisis managers can create action tasks for recovery members or teams anytime during a crisis event or exercise, as long as the event remains open. Crisis managers can create these tasks on the fly without mapping them to event assets or recovery plans. These action tasks are also not included in the event recovery timeline.
      • Create task and assessment-type action items -- Use integration of crisis events and Smart Assessment for creating necessary action items related to the crisis event. The action items can be of task and assessment type.
      • Create a similar tasks group in a crisis -- Identify and group similar or duplicate tasks related to a crisis event using the Similar tasks groups tab. Grouping similar tasks helps you to optimize event task management and minimize redundant work.
      • Request an approval and approve the crisis -- Approve the crisis event in BCM UIB Workspace.
    • Structured workflows for Crisis map -- Use the Crisis map interface in the BCM Configurable Workspace to monitor and receive alerts about potential threats to your organization's business operations. You can then manage these alerts by initiating response workflows.
      • Enhanced performance with UIB pages -- The Crisis map application is now built with a UI Builder (UIB) page. Previously, the single-use component limited the ability to customize the user interface (UI), add filters, or modify the design in the Crisis map. By adopting the UIB page, you can gain full control over the implementation, enabling you to extend support for your specific use cases.
      • Manage alerts from the map interface -- Manage alerts from the Crisis map interface to identify threats and their geo-locations relative to your assets. You can open alerts for details, dismiss them when resolved, adjust the impacted area boundaries, or undo recent changes.
      • Set controls to customize the alerts -- Set controls in the Crisis map interface in BCM UIB Workspace. You can then customize the alerts for assets, locations, and so on.
      • Select resource layer clustering -- Select resource layer clustering in the Crisis map within the BCM Configurable Workspace to view assets or resources on the map.
      • Monitor assets within the impacted areas -- Monitor at-risk assets in the Crisis map within the BCM Configurable Workspace when alert threats appear near your business locations. This functionality enables you to protect resources in impacted areas and help prevent significant losses to your organization.
      • Initiate the response actions -- Initiate the response workflows for your recovery teams in BCM UIB Workspace. You can then notify the stakeholders and help them respond to the threat and take the necessary actions.
    • Managing plans with BCM mobile application -- Business continuity plan (BCP) managers and viewers can manage and view plans using the Business Continuity Management (BCM) application on Android or iOS mobile devices.
    • Platform Analytics dashboards -- Platform Analytics dashboards provide Business Continuity Workspace users with a configurable summary of their work items and actions. Unlike Workspace pages built with the UI Builder, most users can set up or customize Platform Analytics dashboards without writing code or configuring UI components.
      • Create an inline-editor dashboard -- Duplicate and customize the base system BCM dashboard to create a personalized homepage view. The inline editor lets any BCM user build a dashboard without technical knowledge. You can start from scratch or duplicate the delivered base system dashboard.
      • Configure a record overview dashboard -- Add Platform Analytics reports to the Overview tab of a BCM record page. Only BCM admins can configure record overview dashboards. Reports added to an overview page are automatically pre-filtered to the current record and are visible in read-only mode to all users who can access that record.
    • Using BCM Classic Workspace -- This section provides information on managing the business continuity tasks in Business Continuity Management classic Workspace.
      • Customizing BCM classic Workspace -- You can set up the basic settings and features in the Business Continuity Management classic Workspace for your specific requirements.
      • Migrating reports and custom changes -- If you are an existing customer of the Business Continuity Management application and you have customized UI actions, you must migrate those actions to BCM UIB Workspace.
      • Structured workflows for BIA -- Business impact analysis helps you to predict the consequences of a disruption on a business process or business function.
      • Create a business impact analysis -- Create a business impact analysis (BIA) to get the necessary information for a plan. Use the BIA to identify the recovery time objective for an item and prioritize assets that have most and least critical dependencies. Use the information to establish their recovery strategies during the planning phase.
      • Assess impact categories and dependencies of process -- Assess the different components of a business impact analysis (BIA). First by assessing and determining the impact categories of a business process. Second, by identifying any underlying dependencies that the business process requires across different dependency types.
        • Review an impact category and assess its recovery time -- Review the impact categories and define the timeframe during which the organization would experience the downtime of its business processes. Analyze the downtime or disruption duration, which helps to determine the recovery time objective for the asset that is assessed.
        • Assess RPO impact of technology assets -- Use the RPO impact assessment tab to enter asset information. The information can be critical from the objective of its recovery, the data value of the asset, and the frequency at which the data changes in the asset.
        • Identify critical dependencies -- Use the Dependency Assessment tab to identify items or assets that belong to a definite object type or a dependency group.
        • Add dependencies based on CI relationships -- Add an item by referencing its CI relationship to drill down to the item that is related directly to the dependency group. You can map the item's relationship with the dependency group while assessing the business impact analysis of an asset that is at risk.
        • View business impact analysis details -- Use the Details tab to view the general information of the business impact analysis. You can also adjust the recovery time objective and recovery point objective results of the primary element as per your requirement.
        • View approval state flows for BIA -- View the approval state transitions sent at each level of the approval process, and the details of the approvers as you direct the business impact analysis through multiple levels of approvals.
        • Update dependency details of a BIA in Self Service -- Use contributor role to update the disruption duration of the impact category result, RPO Impact analysis responses, state of the impact dependency group, and the work notes in the Activity related item.
      • Structured workflows for Business Continuity Planning -- Business Continuity Planning (BCP) helps you enact and mitigate risk at the time of an event by addressing action items such as plan assets, activities, recovery teams, documentation, policies, and procedures.
      • Create a business continuity plan -- As a program manager you can create a plan for the respective business units that can be used in times of business disruption. You can use a specific plan template for each plan type to streamline the process of a plan creation.
      • View plan details -- Use the Overview tab to gain a quick understanding of how robust your business continuity and emergency plans are. This tab gives an overview of the scores of important plan elements, each as a scorecard.
        • Plan overview scorecards -- The Overview tab gives you the details of the plan and the exercise and actual events that use the plan. It also indicates how successful the plan was in recovering the assets in a loss scenario.
      • Add an asset to the scope of BCP -- Use the Scope tab to add an asset to the scope of the plan. If the business impact analysis (BIA) application is installed, you can view the primary elements defined in the plan template, its recovery time objective (RTO) and recovery point objective (RPO) details, and the business impact analysis.
      • Add related assets and related plans -- Identify related assets and their referred plans to recover the assets in your planning stage. Reuse the configuration item relationship data that flow from CMDB to business impact analysis (BIA) during dependency assessment to identify the assets in your plan.
      • Manage plan documentation sections -- Use the documentation section to document the recovery capabilities of the plan.
      • Assign roles to recovery teams -- Identify individuals and groups and assign them to the recovery team so that they are aware of their roles and the responsibilities of the role to act in a crisis situation.
      • Identify loss scenarios -- When you create a continuity plan or a recovery plan for a department or a business unit, it is necessary to identify and align loss scenarios to the plan.
      • Establish recovery strategies -- Use the Loss Scenarios tab to add asset dependencies and identify recovery strategies to deal with various loss scenarios. A plan, complete with recovery strategies for the identified loss scenarios, helps to address gaps that exist.
      • Group recovery tasks -- Create tasks in a plan to recover your business from various disaster situations. Prioritize the tasks by determining the critical assets that have to be recovered and estimate the time by which the task must be completed.
      • View details of a business continuity plan -- Use the Details tab of the plan to view the general information about the template that is used for the plan, its type, and other details.
      • View approval state flows for BCP -- View the approval state transitions sent at each level of the approval process, and the details of the approvers as you direct the business plan through multiple levels of approvals.
      • Structured workflows for Exercise and Crisis Management -- Business Continuity is an ongoing set of activities aimed at reducing the risk of an organization and improving its ability to respond to and recover from disruptions. To this effect, recovery and exercise management helps in continuous testing and improving of your continuity plans, and minimize business disruptions when a crisis strikes.
      • Start an exercise event -- Create an exercise event to test your business continuity and recovery plans on a planned date and monitor the completion of the event tasks.
      • Start a crisis event -- Unlike an exercise event, a crisis event strikes suddenly. Your business must be equipped to face the challenge and must be able to recover the critical business functions quickly to save you from business loss.
      • Review and start an exercise event -- Review the details of an event in the Details tab, start an event to test your business continuity or recovery plan, and monitor completion of the event.
      • Manage a crisis event -- Review and update the details of a crisis event in the Details tab. Get the event ready for a crisis that may strike and disrupt your business.
      • Monitor event task completion -- View the event details and add impacted items to start an event.
        • Add assets and plans to an event -- Quantify the performance of your continuity and recovery plans through event-based testing. Measure success by tracking the completion of tasks associated with each plan.
      • Data flow, planning, and execution in an event -- When the configuration item data is available on the ServiceNow AI Platform the same items can be used to assess dependencies in business impact analysis (BIA). The dependencies from the BIA can then be used in the planning and events. The configuration items (CIs) can be added manually to the plans and events as well.
      • View recovery tasks from Self-service -- View the tasks assigned to you or a recovery task team that you are a part of to recover assets from a crisis or exercise (Functional type) event. Your BCM Program Manager assigns the tasks to you and you can view them any time you want from the self-service application menu.
      • Crisis Management map -- You can integrate the crisis management application with the Crisis Management map to receive alerts as the alert feeds on possible threats in continuing the business operations of your organization.
      • Setting up the crisis map -- Before you integrate the crisis management map with the geographical locations of your assets, there are certain configurations that you must do to display the active alerts in the crisis map.
      • View and manage alerts in the crisis map -- Business Continuity Management integrates with the Crisis Map to provide you the capability of identifying a threat and its geolocation from your asset locations.
      • Set controls to customize alerts -- Use a set of controls on the crisis map to display the alerts that are critical to your asset locations.
      • View resource layer clustering -- View your assets or resources on the map.
      • View assets at risk within the impacted area -- View the list of resources that are at stake because of an alert threat that is near your business locations. Take actions to protect your resources and prevent major loss.
      • Notify stakeholders and initiate response workflows -- Notify the stakeholders and initiate multiple workflows for the recovery teams across your organization and help them respond to the threat and take necessary actions.
      • Integrating Crisis Management with Everbridge -- You can integrate Crisis Management in Business Continuity Management application with Everbridge notifications system. Everbridge system enables you to send emergency notification to individuals or group of people alerting them of an impending emergency. It provides a one-way notification and two-way communication through properly established delivery channels.
      • Setup steps for emergency notification -- Setting up the Emergency Notification feature requires you, as a BCM admin, to configure certain pre-requisite data. The setup steps help you to establish a consistent connection with Everbridge and a successful notification delivery workflow on the Everbridge side.
        • Create connection and authenticate credential -- As a first step, establish a connection and authenticate your login credentials with an Everbridge instance to send out a notification using a delivery channel. This connection not only helps you to send but also receive communications.
        • Import delivery channels from Everbridge -- After setting up the connection and credentials with Everbridge, you must import the delivery channels from Everbridge. Sending notifications is made easier through these delivery channels.
        • Import delivery channels from Everbridge -- Import the record types for your organization ID from Everbridge and use them to create contacts.
        • Define a template for emergency notification -- Create a template with pre-defined information that you can use to send notification quickly to your users in an emergency.
        • Create contacts for emergency notifications -- Use the ServiceNow users list to create contacts manually and synchronize the contacts with Everbridge to send emergency notifications.
        • Create contact import rules -- Create a contact import rule to apply on the User table and filter out users as contacts for emergency notifications.
        • Create a notification contact group -- Create a notification contact group using the ServiceNow AI Platform groups. Use the group members as contacts for emergency notification. Synchronize the group members as contacts with Everbridge and track the non-synchronized members as exceptions.
      • Create an emergency notification and monitor its workflow -- Use the Emergency notification tab in the event workspace to create a notification for a crisis event or an exercise event where the exercise method is Functional.
        • Create an emergency notification -- The table lists the different states to which the emergency notification proceeds in the Everbridge side. You can track the notification delivery and monitor its status in the workspace until it is successfully delivered to the contacts from the Everbridge side.
    • Integrate -- You can use Everbridge in the BCM Configurable Workspace to send emergency notifications and inform stakeholders about crisis events.
    • Workflow status of emergency notifications -- When you send an emergency notification for a crisis event with Everbridge, it creates a corresponding incident along with a notification. You can track the notification delivery and monitor its status in the Business Continuity Workspace until it’s successfully delivered to the contacts from Everbridge.
    • Create emergency notifications -- Create an emergency notification in BCM UIB Workspace. You can then use Everbridge to notify the stakeholders.
    • Reference -- Reference topics provide additional information such as tables, roles, and properties that are installed with the Business Continuity Management application.
    • Components installed with Business Continuity Management -- Several types of components are installed with activation of the Business Continuity Management application.
    • Data Relationships Framework -- The Data Relationships Framework application (sn_grc_rel_config) supports the BCM application with the underlying framework to fetch the dependencies in the BIAs, plans, and events from different sources such as CMDB, BIA, and BCP. Beginning with the Australia release, the Data Relationships Framework (sn_grc_rel_config) application is installed with the BCM application by default.
      • Create a main node configuration record -- Create a main node configuration record to configure the source for fetching the dependencies. You can configure the details of the main node such as its name, source, table name, filter conditions, and so on.
      • Main node configuration new record form -- Use the Main node configuration new record form to create a main node configuration record in the Data Relationships Framework.
      • Create a relationship registry record -- Create a relationship registry record to set up relationship between the record and object defined in the table. You can configure the details of the main node such as its name, source, table name, filter conditions, and so on.
      • Relationship registry new record form -- Use the Relationship Registry form (the Relationship Registry [sn_data_registry_relationship] table) to create relationships between objects.
      • Configure the properties -- Configure the properties for the Data Relationships Framework application.
      • Data Relationships Framework properties form -- Use the Data Relationships Framework properties form to configure the relationship properties for Data Relationships Framework APIs.
    • GRC record page template for BCM records -- Beginning with the Australia release, the GRC records use the common GRC record page template. You can leverage the new variant of record pages to streamline page creation, simplify maintenance, and minimize the cost of page ownership.
  • Compliance Case Management -- Report, investigate, analyze, and resolve a compliance case or raise a compliance request by using the ServiceNow GRC: Compliance Case Management application.
    • Explore -- Learn how you can use the GRC: Compliance Case Management application to report, investigate, analyze, and resolve a compliance case, or raise a compliance request for your organization.
    • Compliance case workflow -- The workflow in the Compliance Case Management application is a process that enables you to report and manage cases that need the compliance team's attention.
    • Compliance request workflow -- Use the request workflow in the Compliance Case Management application to raise and manage compliance requests within an organization. By using this workflow, your compliance requests are addressed effectively and efficiently by your compliance team.
    • Landing page -- See an overview of all your compliance case-related information on your GRC: Compliance Case Management landing page. You can also create the cases, requests, and issues from this GRC: Compliance Case Management landing page.
    • Using -- The compliance case overview related list shows the details about a case. For example, you can see the description, state, schedule and milestones, case tasks, and issues that are related to a case in the GRC: Compliance Case Management application.
    • Smart assessments in Compliance Case Management -- Use the Smart Assessment Engine to perform smart assessments on compliance case action tasks.
    • 360 degree relationship visualization -- Use the 360° compliance case view to explore the relationship between your compliance case and all its associated records in a distinctive visualization. To use this feature, you must integrate Compliance Case Management with the 360° Relationship Visualization application.
    • Configure -- You can configure the Compliance Case Management application to report, investigate, analyze, and resolve a compliance case or requests.
    • Download application -- Before you run the Compliance Case Management application in your instance, you must download it from the ServiceNow Store.
    • Install application -- You can install the GRC: Compliance Case Management application (sn_comp_case) if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes the demo data and related ServiceNow Store applications and plugins if they aren’t already installed.
    • Create a case type -- Create a case type in the GRC: Compliance Case Management application to categorize the compliance cases by the type of occurrence. For example, you can create a case type, such as a financial case, code of conduct, or HR case.
      • Case Type form -- Use the Case Type form in the Compliance Case Management application to categorize the compliance cases by their type.
      • Create view rule -- Define the view rules for the workspace and default view in the GRC: Compliance Case Management application. By defining the rules, you can control how the compliance case or request form appears.
      • View Rule form -- Use the View Rule form to define the workspace and default view rules in the GRC: Compliance Case Management application.
      • Create assignment rule -- Create an assignment rule and apply it to a compliance case type or request type by using the Compliance Case Management application. By using an assignment rule, you can determine the appropriate person or group to handle a compliance case.
      • Assignment Rule Form -- Use the Assignment Rule form to define the case assignment rules in the Compliance Case Management application.
    • Create Request type -- Create a request type in the GRC: Compliance Case Management application to categorize and manage the compliance requests. After you create a request type, the compliance analysts and managers can select the required request type on the request form.
      • Request Type form -- Use the Request Type form in the Compliance Case Management application to categorize the compliance requests by their type.
    • Create compliance state model -- Create a state model to define the workflow states and transition conditions for compliance case types and request types.
      • GRC State Model form -- Use the GRC State Model form to define the workflow states and transition conditions in the Compliance Case Management application.
    • Create workflow state -- Create a workflow state for a compliance case or request to define the life cycle of the case or request using the Compliance Case Management application. GRC State Model is to configure the states and the state transitions that are created as part of the table.
      • Workflow State form -- Use the Workflow State form to define the workflow states in the GRC: Compliance Case Management application.
    • Define model state transitions -- Define the transition conditions to control how a compliance case traverses through the different workflow states by using the GRC: Compliance Case Management application.
      • Model state transition condition form -- Use the GRC Model State Transition Condition form to define the transition conditions to control how a compliance case or request traverses through the different workflow states by using the GRC: Compliance Case Management application.
    • Create assessment template -- Create an assessment template to request responses from the assessor or reviewer. You can create this template by using the assessment metric type form in the GRC: Compliance Case Management application.
      • Assessment Metric Type form -- Use the Assessment Metric Type form to create an assessment questionnaire template by using the GRC: Compliance Case Management application.
    • Update an assessment template -- Publish a new version of an assessment template in Compliance Case Management to revise its questionnaire and response options.
    • Use -- Report compliance cases and manage the lifecycle of a case by using the GRC: Compliance Case Management application.
    • Report compliance case -- You can report a compliance case or an event that needs the attention of the compliance team by using the GRC: Compliance Case Management application.
      • Employee Center -- Report any violation of the organization's policies or guidelines by using the Employee Center application. By reporting a case, you reduce and avert the adverse regulatory actions that could impact the company's financials, reputation, and growth.
      • Report compliance case form -- Use the Report a Compliance Case form in the Employee Center to report a compliance case.
      • Create compliance case -- Report any violation of the organization's policies or guidelines by using the Compliance Case Management application. By reporting a case, you reduce and avert the adverse regulatory actions that could impact the company's financials, reputation, and growth.
      • Compliance case form -- Use the Create Compliance Case form in the GRC: Compliance Case Management application to report a compliance case.
      • Report a compliance case anonymously -- Use the Anonymous Reporting Center (ARC) to submit any suspected or confirmed compliance case without disclosing your identity.
      • Anonymous compliance case form fields -- The fields in the Report a compliance case form capture details about the suspected or confirmed compliance issue without disclosing the reporter's identity.
      • Report through email -- Report a compliance issue by sending an email to your organization's compliance mailbox. This creates a compliance case automatically in Compliance Case Management.
    • Raise compliance request -- You can raise a compliance request to the compliance team by using the GRC: Compliance Case Management application. For example, you can submit a compliance request to seek advice or guidance on the organization's policies and guidelines.
      • Employee Center -- Raise a compliance request regarding organization's policies, inquiries, and guidelines by using the Employee Center application. By seeking guidance, clarification, or approval, you contribute to maintaining a culture of compliance within your organization.
      • Raise a Compliance Request form -- Use the Raise a Compliance Request form in the Employee Center to raise a compliance request.
      • Compliance workspace -- Raise a compliance request regarding organization's policies, inquiries, and guidelines by using the Compliance Case Management application. By seeking guidance, clarification, or approval, you contribute to maintaining a culture of compliance within the organization.
      • Compliance request form -- Use the Create new compliance request form in the GRC: Compliance Case Management application to raise a compliance request.
    • Compliance case task workflow -- You can collaborate with multiple teams to investigate, perform an impact assessment, and gather the evidence to capture the details and responses for review in the GRC: Compliance Case Management application.
      • Create action task -- Create an action task to investigate, gather evidence, and perform an assessment so that you can analyze and assess a reported case in the GRC: Compliance Case Management application. Each case can have multiple case tasks that you can assign to different owners across multiple teams.
      • Case task form -- Use the Case Task form in the GRC: Compliance Case Management application to create a case task for a reported compliance case.
      • Work on action task -- Accept the Action task, provide the details requested by the case analyst, and submit the Action task for a review in the GRC: Compliance Case Management application. When an action task is assigned to an assignment group, any user from the assignment group can accept and work on the task.
      • Reassign Action Task -- Reassign an Assessment type Action task to another user in the GRC: Compliance Case Management application. For example, a case analyst or an action task owner can reassign a compliance Action task to another Action task owner if an action task is wrongly assigned or isn’t accepted by the Action task owner.
      • Review and close action task -- Review and close an action task after an action task owner provides responses and observations for the case in the GRC: Compliance Case Management application.
    • Add impacted area -- Add an impacted area or object that is affected by the compliance case or event in the GRC: Compliance Case Management application.
    • Add related area -- Add an area that is related to the compliance case or event that is reported in the GRC: Compliance Case Management application.
    • Add cause and consequence -- Define the root cause for the reported compliance case or event and its consequences on the organization by using the GRC: Compliance Case Management application.
      • Cause and Consequence form -- Use the Cause and Consequence form to define the cause and consequence that a case has on your organization in the GRC: Compliance Case Management application.
    • Add compliance regulations -- Add the regulations that are or can be impacted by the reported compliance case. In the ServiceNow platform, regulations are captured as authority documents. Adding the regulations to the case enables you to identify which regulations are breached or violated and prevents your organization from getting penalties or fines for this case.
    • Add issue -- Identify and add an issue that is related to the impacted areas of a reported compliance case. You can also create an issue from the GRC: Compliance Case Management landing page.
      • Create an Issue form -- Use the Create an Issue form in GRC: Compliance Case Management to add an issue to a compliance case, report findings or observations or compliance deficiencies, or matters that require immediate attention from the respective owners.
    • Export report to PDF -- Create Portable Document Format (PDF) reports for compliance cases or requests using predefined or customized templates in the GRC: Compliance Case Management application. This feature enables the stakeholders who may not have access to the application can still access the data.
    • Compose email -- Compose and send an email for compliance cases and requests by using the GRC: Compliance Case Management application. This feature helps you to communicate with different stakeholders within or outside your organization.
    • Configure due dates -- Set up a pre-defined rule to automate due date calculations. Rules are designed to run and becomes effective when a new record is reported into the application.
    • Smart assessments -- Use the Tasks page on the Employee Center for a consolidated view of all your tasks, including all assessments, enabling you to access and complete them efficiently.
    • Reference -- Reference topics provide additional information such as the tables and roles that are installed with the GRC: Compliance Case Management application.
    • Installed Tables -- Tables are added with the activation of the GRC: Compliance Case Management application.
    • Installed Roles -- The GRC: Compliance Case Management installs the essential role to perform respective day-to-day operational tasks towards managing compliance cases for the enterprise to perform their respective tasks.
  • Continuous Authorization and Monitoring -- Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.
    • Explore -- Learn about the CAM benefits and workflows for users.
    • Configure -- Follow the steps in the checklist to download CAM from the ServiceNow Store and get it ready for operation.
    • Checklist for Continuous Authorization and Monitoring setup -- The checklist includes the tasks that you must complete to prepare the base system.
    • Assign Continuous Authorization and Monitoring roles to users and groups -- Assign roles to users and groups to prepare to use the CAM application.
    • Use -- To provide CAM services, you implement the seven steps defined by the NIST Risk Management Framework (RMF), implement controls and assessment objectives, and perform continuous authorization and monitoring.
    • RMF step 0 - Prepare the authorization package -- In the Prepare step, you set up authorization boundaries, control overlays, and information types, as well as create the actual authorization package.
      • Define the authorization boundary -- An authorization boundary defines the scope of a particular system that can be continuously managed and monitored using the CAM application.
      • Create an authorization package -- After you have defined the authorization boundaries for the assets or systems to send through the Authorization to Operate process, you must create an authorization package for that purpose. The package is processed through the seven steps mandated by the RMF.
    • RMF step 1 - Categorize the authorization package -- In the Categorize step, you define the criticality or sensitivity of your information system according to potential worst-case scenarios. This involves selecting NIST information types for the package and using the information types to define the impact levels for the package.
    • RMF step 2 - Select controls for an authorization package -- When the impact levels for the package have been approved, it is time to select baseline controls.
      • Set up baseline controls -- Use the baseline controls to inherit a control, mark a control as common, or create a hybrid control. Create a hybrid control to inherit requirements partially from common controls and the remaining requirements are created for the control that was generated from the baseline control.
      • Inherit from a common control -- After you have created a common control, you can identify other controls that can inherit protection and compliance from that common control.
      • Inherit from multiple providers -- Inherit individual control requirements from different provider packages to create a fully inherited control within an authorization package.
    • RMF step 3 - Implement controls -- After you have selected controls for implementation and performed any of the possible actions on them, you can implement the controls.
      • View controls in grid view -- View and edit controls and their requirements in a hierarchical data grid that enables bulk operations and in-line editing.
    • RMF steps 4, 5, and 6 - Assess, authorize, and monitor -- After you have implemented controls, you can assess internal and external controls, generate Plans of Action and Milestones (POA&M), and manage change requests and vulnerable items.
    • CAM workflow configuration -- Configure custom workflows in Continuous Authorization and Monitoring to support compliance requirements beyond the default National Institute of Standards and Technology NIST Risk Management Framework.
      • Enable CAM workflow configuration -- Enable the CAM workflow configuration to use custom workflows and frameworks in CAM. This feature enables you to configure workflows beyond the default National Institute of Standards and Technology (NIST) framework and adapt CAM to your organization's specific requirements.
      • Run migration scheduled job -- Run the migration scheduled job to associate existing authorization packages and boundaries with the workflow after enabling the CAM workflow configuration property. The migration confirms that existing data is compatible with the workflow configuration.
      • GRC state model configuration -- Create a Governance, Risk, and Compliance state model to define the steps, transitions, and validations for a custom workflow in CAM. State models control how authorization packages move through workflow life cycles and determine which actions are available at each step.
      • Create GRC workflow states -- Add Governance, Risk, and Compliance workflow states to a state model to define the individual steps in your workflow. Each workflow state represents a phase in the authorization package life cycle and determines what you can do at that stage.
        • Configure transition between state models -- Create state model transitions to define valid paths between workflow states. State model transitions control how authorization packages move from one step to another and verify that packages follow the correct sequence through your workflow.
        • Create GRC model state transition conditions -- Add Governance, Risk, and Compliance model state transition conditions to a state transition to validate data before enabling authorization packages to move between workflow steps. Transition conditions verify that the required information is complete and accurate before packages proceed.
      • Add existing attributes to a GRC workflow state -- Add existing Governance, Risk, and Compliance state model attributes to add special capabilities to workflow steps without custom code. Attributes control features like approval requirements, report generation, and Open Security Controls Assessment Language (OSCAL) file exports for specific workflow states.
      • Create a new state model attributes -- Create custom state model attributes to add specialized capabilities to workflow steps.
      • Workflow configuration -- Define workflow, framework, regulation, and its associated versions, impacts, and view rules. CAM ships National Institute of Standards and Technology (NIST) workflow configuration by default, but you can create additional workflows for other frameworks such as Protective Security Policy Framework (PSPF) or custom internal frameworks.
      • Add version to workflow -- Add workflow versions to a workflow configuration to support different revisions or iterations of your workflow. Workflow versions filter control objectives based on the version requirements.
        • Add impact to version -- Add impact levels to a version to categorize authorization packages by risk level. Impacts filter control objectives based on the impact requirements and work with versions.
      • Add view rules to workflow -- Configure custom view rules to display specific fields, sections, or layouts for authorization packages using a particular workflow configuration. View rules enable workflow-specific user interfaces without modifying the base package form.
      • Skip Attestations -- Skip Attestations lets you bypass the attestation stage for all controls in a package. When enabled (before implementation), controls move directly from Draft to Review, attestation-related UI elements are hidden, and Review/Monitor actions replace attestation workflows.
    • Implement controls and assessment objectives -- NIST 800-53A – assessment objectives are included in the base system with the CAM application. The assessment objectives are mapped to revision 5 control objectives.
      • Generate assessment procedure plans for a test plan -- Use the test plan that is automatically generated for a control, which is in an assess state, to view and determine if the control is assessed in accordance with the assessment procedure plan.
      • Determine control effectiveness of a control test -- Apply the objective effectiveness of the assessment procedures and the operating effectiveness of the control test to determine the control effectiveness of the control test. An assessment procedure is applied to check the control test at a granular level.
      • Define control requirements -- You can break down a control at a more granular level as requirements when you generate the control at the control objective level.
      • Modify control requirement -- Approve the authorization package when it is in the Select step to create controls. After approval, the authorization package moves to the Implement step and the controls are generated. You can still modify the control requirement implementation status at the control level.
      • Control requirement generation and upgrade steps -- The Creates controls automatically and Create control requirements options in the control objective form and the state of the authorization package are important to create control requirements.
      • View control tests in grid view -- View and edit control tests and assessment procedures in a hierarchical data grid.
    • Continuous authorization and monitoring tasks in the CAM Workspace -- The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.
      • Monitoring and managing security from the CAM Workspace Home page -- The CAM Workspace is a centralized hub where you can continuously monitor and manage compliance of users and systems with the NIST Risk Management Framework to ensure adherence to your security policies and guidelines.
      • Monitor and manage your NIST security posture -- Access the CAM Overview, AO Overview, and SCA Overview dashboards from the CAM Workspace to monitor and analyze data and view CAM reports.
      • Monitor and manage CAM tasks -- Use the Tasks page to address the approvals, control attestations, and all other items that are assigned to you and to your group.
      • Managing POA&Ms issues -- In CAM application, all issues related to an authorization package are called as Plan of Actions and Milestones (POA&Ms). The issues can be package issues, or control issues, engagement issues, or control test issues that are related to the package.
      • View reports on authorization boundary elements -- Use the authorization boundary overview page to define the parameters of a security measure for an organization.
      • Configure boundary hierarchy -- Establish parent-child relationships between authorization boundaries to improve boundary management, visibility, and organizational structure within Continuous Authorization and Monitoring. You can assign a parent boundary and associate multiple child boundaries to authorization boundary.
      • Create a boundary filter -- Create boundary filters to define system elements within an authorization boundary based on specific table conditions.
      • View package details in CAM Workspace -- Use the authorization package overview page to view documents and evidence that help you to assess your organization's security posture.
      • Apply overlays to the baseline controls -- You can include overlays to the baseline control objectives in the Authorization Package using either addition, subtraction, or a custom action.
      • ATO artifacts for an authorization package -- Generate Authority to Operate (ATO) artifacts such as System Security Plan (SSP), Security Assessment Report (SAR), Plan of Actions and Milestones (POA&Ms), Security Assessment Plan (SAP), Authority to Operate (ATO Letter), and Executive Summary from an authorization package in Microsoft Word format. Generating ATO artifacts as Microsoft Word format enhances ease of editing, collaboration, and compliance, confirming professional and portable documents.
      • Generate ATO artifacts -- From the Authorization package overview record page, generate Authority to Operate (ATO) artifacts in Microsoft Word format. This action enables you to download your ATO artifacts from CAM.
      • Request control tailoring -- Control tailoring requests enable you to modify baseline controls for an authorization package after the Select step without reverting the package to earlier workflow steps.
      • Create a control tailoring request -- Create a control tailoring request to modify baseline controls for an authorization package after the Select step without reverting the package to earlier workflow steps.
      • Approve or reject a control tailoring request -- As an Authorizing Official (AO) or AO Delegate, review and approve or reject control tailoring requests to ensure governance and oversight of baseline control modifications.
      • CAM OSCAL -- Open Security Controls Assessment Language (OSCAL) provides a standardized way to express control-related information, enabling interoperability, consistency, and automation in IT security. It supports the JSON format only. CAM supports OSCAL version 1.1.2.
      • Export in OSCAL format -- CAM supports the Open Security Controls Assessment Language (OSCAL) used by the National Institute of Standards and Technology (NIST) that provides control-related information in standardized machine-readable formats. CAM supports Catalog, Profile, SSP, Assessment Plan (AP), Assessment Results (AR), and Control Tailoring Request data.
        • Export OSCAL catalog -- From the Control objective list view page, you can export the catalog in OSCAL JSON format for the selected control objectives. This action enables you to export your control objectives from CAM.
        • Export OSCAL SSP -- From the Authorization package overview record page, generate zip files and export the record's mapped content details in OSCAL format. To generate OSCAL SSP, the selected Authorization package must be in implemented state or after that. This action enables you to export your authorization package from CAM.
        • Export OSCAL POA&M -- Generate zip files Plan of Action and Milestones (POA&M) data in Open Security Controls Assessment Language (OSCAL) JSON format from the Authorization package overview record page. The authorization package must be in Implement state or later, and a POA&M file must link to the selected authorization package.
        • Export an OSCAL Assessment Plan -- Export engagement data as OSCAL Assessment Plan files to share testing plans with auditors or import into external systems.
        • Export OSCAL Assessment Results -- Export the OSCAL Assessment Results (AR) file for an authorization package from the CAM Workspace.
      • Import in OSCAL format -- The CAM OSCAL import offers a playbook-style experience designed to streamline the integration of security control data.
        • Import OSCAL catalog -- From the New Import playbook experience page, you can import OSCAL files in the Catalog model into CAM workspace. This task focuses on uploading and processing the required JSON files to begin the import process.
        • Import OSCAL SSP -- From the New Import playbook experience page, you can import OSCAL files in the System Security Plan (SSP) model into CAM workspace. This action enables you to seamlessly upload authorization package data in OSCAL format.
        • Import an OSCAL Assessment Plan (AP) -- Import OSCAL Assessment Plan files to automatically create engagements, control tests, and assessment procedures in your authorization package.
        • Import OSCAL Assessment Results (AR) -- Import OSCAL Assessment Results (AR) from similar NIST RMF frameworks to create an engagement.
    • Analytics and Reporting -- Platform Analytics Solutions contain prepackaged Performance Analytics and Reporting content for use with ServiceNow AI Platform products. The solutions help you to track and analyze CAM performance analytics dashboard reports.
    • CAM Overview dashboard -- The CAM Overview dashboard provides multiple tabs with reports on critical aspects of your CAM security posture.
    • AO Overview dashboard -- Users with the Authorization Official [sn_irm_cont_auth.authorization_official] role can view the reports in the AO Overview module.
    • SCA Overview dashboard -- The SCA Overview dashboard enables you to view and manage control assessments as they occur.
    • Reference -- Reference topics provide the detailed descriptions of tables, properties, forms, and roles that are installed with the CAM application.
    • CAM user roles -- Assign users and groups with roles to prepare them to user the CAM application.
    • Control Requirement Details View -- The CAM view of the Control form has fields that have been added to capture the control requirement details.
    • Compliance impact on control requirements -- Control objective requirements are created for a control objective. The control requirements are generated for all the controls that are associated with a control objective. However, a control or a control requirement can become non-compliant because of an attestation failure or issue creation at either of the two levels.
    • Fields on the Authorization Boundary form -- An authorization boundary defines the scope of a particular system that can be continuously managed and monitored using the CAM application.
    • Fields on the Authorization Package form -- After you have defined the authorization boundaries for the assets or systems to send through the Authorization to Operate process, you must create an authorization package for that purpose. The package is processed through the seven steps mandated by the RMF.
    • Components installed with Continuous Authorization and Monitoring -- Activating the GRC: CAM plugin adds or modifies several tables, user roles, and other components.
    • Configuring ATO artifacts report templates -- Configure the ATO artifacts report templates using the ServiceNow Document Designer with Word add-in.
      • Install the add-in -- Install the ServiceNow Document designer add-in to your Microsoft Word document to create audit and CAM report templates and generate report content using the AI Reporting Assistant.
      • Create content configurations for CAM -- Define the data that you want to view or fetch, whether it's a list of records or an aggregation when creating an ATO artifacts. For example, specify if you want to see a list of closed POA&M or the list of system elements. A maximum of 200 records can be fetched from any table.
      • Word template form -- The table gives a description of the field values for the Word template form.
      • Word template category form -- The table gives a description of the field values for the Word template category form. Template categories enable you to categorize similar reports and filter them accordingly. For example, Audit or CAM is a category.
  • Model Risk Management -- The ServiceNow Model Risk Management application enables you to identify, assess, validate, and address risks associated with a model throughout their life cycle.
    • Explore -- Learn how you can use the Model Risk Management application to identify, assess, and mitigate risks related to the quantitative models.
    • Model Risk Workspace -- The Model Risk Workspace enables the model risk governance team and model validators to view the action items that require their immediate attention.
    • Configure -- Plan and configure the implementation of the Model Risk Management application. You can follow the steps listed in this topic.
    • Install Model Risk Management -- Install the Model Risk Management application (sn_model_risk_mgmt). The application installs related ServiceNow Store applications and plugins if they aren’t already installed.
    • Configure Model Workflow Settings -- Configure the conditions and frequency for scheduling assessment and validation tasks to maintain a structured and timely approach to model risk management.
    • Use -- Use the Model Risk Management to identify, assess, and mitigate risks related to the quantitative models.
    • Request a new model -- Request a new model in the Employee Center to initiate the model intake process and capture all required details for review and approval.
      • New Model Intake form -- Use the New Model Intake form to request a new model by providing details such as the purpose, owner, model complexity, and expected outputs.
    • Initiate a model risk assessment -- Initiate a model risk assessment by verifying the details, assigning stakeholders, and create an assessment using the Model Risk Management application.
    • Perform model risk assessment -- Perform the model risk assessment initiated by the Model Governance team to identify and assess the risks related to a quantitative model using the Model Risk Management application.
    • Create a validation task -- Create a validation task by selecting a predefined validation template, assigning a validator, and setting a due date. This task defines the validation scope and responsibilities, preparing the model for formal validation and deployment.
    • Perform model validation -- Perform model validation to assess and validate the model, collect required documents, report any issues, and determine if the model is fit for use. This process confirms that the model meets required standards and is ready for deployment.
      • Request evidence for model -- Send evidence collection request for all the required documents to complete the model validation. Evidence request helps validators to electronically request the information that they need from the model owner to perform model validation.
      • Request evidence form -- Use this form to electronically request the information needed from the model owner to perform model validation.
    • Approve or reject model assessment and validation tasks -- Approve or reject the model assessment and validation tasks either from the Employee Center or Model Risk Workspace.
    • Create an issue for model -- Add or create model issues and their remediation actions. Capture validation findings or performance problems and follow them through to resolution.
      • Create an issue form -- Use the Create an issue form to capture validation findings or performance problems for a model.
    • Create assessment in the Pre-deployment stage -- Create a model risk assessment by verifying the details, assigning stakeholders, and create an assessment using the Model Risk Management application in the Pre-deployment stage.
    • Schedule assessment and validation tasks -- Schedule assessment and validation tasks for model risks in the Monitor stage to ensure regulatory compliance and effective risk management.
    • Reassign model assessments and validations -- Reassign an model risk assessment or validation to another assignee from the stakeholder list of the model risk record when the task is in the In-progress state. It ensures that the task continues without delay if the original assignee is unavailable.
    • Copy assessment responses -- Enable the option to copy responses from the most recent completed assessment into new assessments. Respondents can review and edit the pre-filled responses before submission to save time and ensure consistency.
    • Override model ratings -- Override the risk rating and materiality tier of a model manually at any stages of its life-cycle. This helps maintain data accuracy, transparency, and governance when business context or expert judgment requires adjustments to system-calculated values.
    • Link existing documents to a model record -- Link documents from your repository to a model record. This feature helps you manage all model-related documents in one place, ensuring version control, audit readiness, and traceability.
    • Reference -- Reference topics provide additional information such as default notifications, roles, and tables that are installed with the Model Risk Management application.
    • Model Risk Management email notifications -- Default Model Risk Management notifications inform users about important events and status changes throughout the Model Risk Management workflow.
    • Roles installed with Model Risk Management -- The Model Risk Management application installs the essential roles to perform respective day-to-day operational tasks for managing models.
    • Tables installed with Model Risk Management -- Tables are added with the activation of the Model Risk Management application.
  • Operational Resilience -- Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.
    • Explore -- The Operational Resilience application provides a complete view of your operational resilience status including business service details, entities, and the status of your core business areas.
    • Key dependencies for Operational Resilience -- Before you install the Operational Resilience application, you must install the required GRC applications in your instance.
    • Common Service Data Model for Operational Resilience -- Starting with Release 20.1.x, the Operational Resilience application supports the latest Common Service Data Model (CSDM). CSDM is the data framework that administrators use when configuring ServiceNow products and applications. It ensures that configuration items (CIs) and their relationships are properly defined and stored in the relevant Configuration Management Database (CMDB) tables.
      • CSDM data workflow and business model views -- The CSDM model offers a framework for evaluating and enhancing an organization's reporting and resilience environment, applicable to various business model views. ServiceNow products are CSDM aware, and their Configuration Management Database (CMDB) data is organized according to CSDM guidelines, leveraging this structure for improved functionality.
    • Main node configurations: A component of the Data Relationship Framework -- Starting with Release 20.1.x, the Main node configurations, supported by the Data Relationships Framework, are available with Operational Resilience to define dependency roll-up chains. Operational Resilience administrators configure the entity types and pillars, generate the entities, and then establish relationships between different CSDM objects. After this setup is complete, data from the CMDB is fetched into Operational Resilience, displaying rolled-up dependencies in the Workspace view.
      • Node relationship configurations -- Node relationship configurations are used to set up relationships between the records and objects defined in the table. You can configure the details of the main node such as its name, source, table name, filter conditions, and so on.
      • Relationships between CSDM objects -- You can configure relationships between various CSDM objects such as business services, service offerings, business processes, and application services by using the Main node configurations. The [sn_grc_m2m_profile_profile table] serves as the source table for establishing these relationships.
      • Nexus map configurations -- Beginning with Operational Resilience, version 21.1.x, the Nexus map configuration has been introduced. To display a main node in the Operational Resilience Workspace, you must configure the Nexus map. The Node Map configuration UI allows you to visualize related data hierarchically, track issues, and identify areas needing attention for effective resolution or health monitoring.
      • Node and edge configurations and property setting from the UI -- To access the Node map configuration from the Operational Resilience Workspace, BCM administrators must set up the Main node configurations. Once the Main node configuration table is set up, it enables you to create configurations for entities such as services, business services, offerings, business processes, and application services. You can update the properties, node, and edge configuration details.
      • Main node configuration source -- You can set up the source for the Main node configurations.
    • Configure -- Configure the Operational Resilience application to identify risks, failed controls, monitor services and processes, and ensure a complete resilience of your organization.
    • Install Operational Resilience application -- Install the GRC: Operational Resilience application from the ServiceNow Store and run it in your instance.
    • Assign Operational Resilience roles to users -- Assign the appropriate roles to the users of the Operational Resilience application.
    • Setting up pillars, entity types, entity filters, and entities -- This section helps you configure the Operational Resilience application to organize and track your organization's operational data through a structured hierarchy of pillars, entity types, and entities.
      • Set up pillars and entity types from Workspace UI -- Set up the pillars and entity types from the Operational Resilience Workspace UI. You must activate the pillars first and then activate the entity types. If you prefer the classic experience, you can navigate to the module using the Admin setup in the Core UI.
      • GRC Choices form -- Use the GRC Choices form to set up a pillar to define the core areas for your business entity.
      • Entity type new record form -- Use the Entity type new record form to create an entity type depending on your business requirement.
      • Set up pillars and entity types from Core UI -- Set up the pillars and entity types using Admin setup from the Core UI in the Operational Resilience application.
      • Configure the entity filters -- Configure entity filters to define the records from ServiceNow tables that populate each entity type after setting up pillars and entity types. Entity filters use selection criteria to identify and pull relevant records automatically. You can build custom filter conditions tailored to your requirements or select from predefined (saved) queries for common scenarios.
      • Create new entity filter form -- Use the Create New Entity Filter form to create a filter condition for an entity type depending on your business requirement.
      • Activate the entity filters -- Activate the entity filters directly from the form by adding the Active check box to the layout. This field is hidden by default. Follow the steps in this section to make it visible.
      • Verify the configuration of entity filters -- Verify that entity filters are configured correctly and produce accurate results. Confirm that filters are active, assigned to the correct entity types, and use valid field conditions. If possible, test your filter logic directly in the source CMDB table to see which records match your criteria. This proactive verification helps you capture the right data without including unwanted records.
      • Generate entities automatically using a scheduled job -- Generate entities automatically via scheduled job once pillars, entity types, and entity filters are active. Entities are individual records matching your filter criteria. For actual entity creation, you should run the GRC Profile Generation scheduled job in the GRC: Profiles application rather than using entity filters.
      • Add entities manually -- Add entities manually from the Operational Resilience Workspace as an optional step once pillars, entity types, and entity filters are active. Entities are individual records matching your filter criteria. Automatic generation is recommended for most scenarios; manual addition is available for exceptions.
    • Configure the Main node configurations -- Create the Main node configuration record to fetch data into Operational Resilience for reporting. Main node configurations are available with the base system. You can use the existing Main node configurations or create new Main node configurations for your business needs.
      • Main node configuration form -- Use the Main node configuration form to create a Main node configuration record in the Data Relationships Framework.
      • Configure the Node relationship configurations -- Create a Node relationship configuration record to establish relationships between nodes. Update the node relationships including source table, both Configuration Items (CI) and non-CI relationships. The Node relationship configurations define the connections between the source table and other tables (target tables), specifying how they are related.
      • Node relationship configuration form -- Use the Node relationship configuration form to configure the node relationships. You can also view these settings in the Nexus map.
      • Relationship registry record form -- Use the Relationship Registry form (the Relationship Registry [sn_data_registry_relationship] table) to create relationships between objects.
      • Configure the Nexus map configurations -- Configure the appearance of the Nexus map (Resilience map) for a specific main node by defining its UI settings. It involves defining visual elements such as colors, icons, and edge configurations. By configuring the settings at the Nexus map level, you can associate a single main node with multiple Nexus configurations, enabling flexible loading of settings for different entities.
      • Nexus map configuration form -- Use the Nexus map configuration form to define the UI configuration for the selected Main node configuration. It also helps you to define the node and edge configurations, determining how the Nexus map is displayed.
      • Configure the Node configurations -- Configure the settings for the selected node. It helps you to determine the UI display in the Nexus map. You can select the table associated with the node and configure the primary label, icon, secondary label, tooltip, and so on for the node.
      • Node configuration form -- Use the Node configuration form to configure the settings such as the primary label, icon, secondary label, tooltip for the selected node.
      • Configure the Node status configurations -- Configure the Node status conditions and parameters for the selected node configuration table. You can then customize the map display by assigning specific colors and icons to the nodes that meet certain conditions.
        • Node status configuration form -- Use the Node status configuration form to configure the Node status conditions and parameters for the selected node configuration table.
      • Configure the Edge configurations -- Configure the Edge configurations settings for the selected Nexus map configuration. You can then configure the label, tooltip, default edge type for the edge of the selected node.
      • Edge configuration form -- Use the Edge configuration form to configure the Edge configurations settings such as the label, tooltip, default edge type for the edge of the selected node.
      • Configure the Edge status configurations -- Configure the Edge status configurations for the selected Nexus map configuration. You can customize the display of connectors that meet specific conditions by assigning them distinct colors and connector types.
        • Edge status configuration form -- Use the Edge configuration form to configure the Edge status settings for the selected Nexus map configuration. You can customize the display of connectors that meet specific conditions by assigning them distinct colors and connector types.
    • Configuring Operational Resilience properties -- Configure main properties of the Operational Resilience so that you can set up and fetch data into the application for reporting purposes.
    • Configuring 360º views for services and processes -- Configure 360º views for the services, business services, business processes, and application services. You can select the table for which you want to update the sector configurations, relationship registries, and their positions on the 360º view.
      • Opres with CSDM header Main node configuration -- The Opres with CSDM header Main node configuration, used by new customers, fetches CMDB objects such as business services, business processes, service offerings, and application services into Operational Resilience. Existing customers typically use the Service (CMDB) Main node configuration. Administrators or UI Builder administrators can display or hide the Services overview or Business services overview tab from the Workspace view based on organizational needs.
      • Service (CMDB) Main node configuration -- The Service (CMDB) Main node configuration defines the relationships for the services. Existing customers typically use the Service (CMDB) Main node configuration, while new customers use the Opres with CSDM header Main node configuration. Administrators can display or hide the Services overview or Business services overview based on organizational needs.
      • Business process to dependencies Main node configuration -- The Business process to dependencies Main node configuration defines the relationships from a Business process to its dependencies.
      • Business service to dependencies Main node configuration -- The Business service to dependencies Main node configuration defines the relationships from a Business service to its dependencies.
      • Service offering to dependencies Main node configuration -- The Service offering to dependencies Main node configuration defines the relationships from a Service offering to its dependencies.
      • BCM dependencies related Main node configurations -- When the Business Continuity Management application is installed in an instance, BCM dependencies are fetched into the Operational Resilience application.
    • Sample Services to dependencies configuration -- Create a Services to dependencies sample Main node configuration record for linking services to dependencies.
    • Sample Application service to dependencies configuration -- Create an Application service to dependencies sample Main node configuration record for linking an application service to the dependencies.
    • Sample end-to-end workflow for a business service -- Configure an end-to-end workflow for a business service to fetch the CSDM dependencies and red flags data to Operational Resilience. You must ensure that entities are generated and associated with pillars, and that the Main node configurations are set up before fetching the required data.
    • Sample end-to-end workflow for services -- Configure an end-to-end workflow for the service to fetch the CSDM dependencies and red flags data to Operational Resilience. You must ensure that entities are generated and associated with pillars, and that the Main node configurations are set up before fetching the required data.
    • Completing general administrative tasks -- A user with the sn_oper_res.admin role can perform the setup tasks in the Operational Resilience application.
      • Create a scenario and link it to an event -- Create a scenario in the Operational Resilience application so that you can associate it with an event and assess its impact on your business services.
      • Scenario New record form -- Use the Scenario New record form to create a scenario and test how an event that is associated with a scenario can impact your organization.
      • Create an event group for the scenario -- Create an event group in the Operational Resilience application so that you can categorize the events that are defined in a scenario.
      • GRC Choice New record form -- Use the GRC Choice New record form to classify your events and organize them into event groups.
      • Create an event for the scenario -- Create an event in the Operational Resilience application so that you can associate it with a scenario and assess its impact on your services.
      • Event New record form -- Use the Event New record form to create an event that you can associate with a scenario and assess its impact on your services.
      • Add a participant role for the scenario analysis -- Add a participant role for your scenario analysis in the Operational Resilience application so that you can collect the observations and recommendations of the participants by their roles and functions.
      • GRC Choice New record form for participant roles -- Use the GRC Choice New record form to add a role for the participants of your scenario analysis.
      • Update the Important choices module -- Update the rating of the assessment in the Operational Resilience application so that you can update the criticality and the order of the assessment for your business services.
      • GRC Choices form -- Use the GRC Choices form to set up the rating of the assessment by updating its criticality and the order of the choice in the Important choices module.
      • Set up the Importance and Impact Tolerance Rating Scale -- Set up the Importance and Impact Tolerance Rating Scale in the Operational Resilience application so that you can define new parameters for your business services.
      • Rating Scale New Record form -- Use the Rating Scale New Record form to set up the default importance rating scale to define the parameters of the rating scale for your business services.
      • Create and edit the attestation template -- Create a customized attestation template in the Operational Resilience application that suits your business needs. By customizing an attestation template, you can add your own questions for your self-attestation. You can also edit an existing attestation template for your own business needs.
      • Assessment Metric Type New Record form -- Use the Assessment Metric Type New Record form to create an attestation template to create the attestations. Use the template form to create a record.
      • Create a Smart Assessment template -- Create a Smart Assessment template and impact automation that can be used in the vulnerability types of an operational vulnerability.
      • Set up Legacy assessment template -- Create your own questionnaire (assessment) template instead of using the default template in the Operational Resilience application to suit your business needs.
        • Assessment Metric Type form -- Use the Assessment Metric Type form to create an assessment questionnaire template instead of using the default template. You can also use this form to request responses from the assessor.
      • Create HTML and PDF document templates -- Create a customized HTML document template​ in the Operational Resilience application to suit your business needs. You can use the customized HTML document template instead of the default HTML template to export an attestation.
      • HTML Template form -- If you have the sn_oper_res.admin role, use the HTML Template form to create an HTML template instead of using the default HTML template.
      • Show Business services overview tab in Workspace view -- Starting with Release 20.1.x, the Services overview and Business services overview tabs are displayed on the landing page of the Operational Resilience Workspace. Administrators or UI Builder administrators can show or hide one of these tabs from the Workspace view based on organizational needs.
      • Setting up the Operational vulnerability module -- Configure the Operational vulnerability feature in the Operational Resilience Workspace to help identify and address operational vulnerabilities within your organization.
      • Set up the Operational vulnerability type -- Set up the Operational vulnerability type. By defining the type and nature of the Operational vulnerability, Operational Resilience administrators can efficiently assign the operational vulnerabilities to the appropriate teams and address any issues in a timely manner.
      • Set up the State model and Action task model -- Set up the Vulnerability state model and Action task model to manage the workflow of the Operational vulnerability record. These models define the workflow states and transition conditions for a record type and an action task, respectively. Both the Operational vulnerability record type and the action task adhere to the workflow states configured in their corresponding models.
      • Set up the Vulnerability Assessment Template -- Create the Vulnerability Assessment Template by defining the assessment parameters for Operational vulnerability. The assessment template is based on the Metric type assessment. It helps you to define important assessment details such as the assessment duration, associated tables, filter conditions, and so on.
        • Assessment metric type form -- Use the Assessment Metric Type form to create an assessment questionnaire template instead of using the default template for Operational vulnerability.
      • Set up the Document Template -- Set up the Document Template (HTML Template) that is used for generating the PDF of the Operational vulnerability record.
    • Manage -- Starting with GRC version 16.x.x, a new workspace has been introduced for the GRC: Operational Resilience application. You can use Operational Resilience Workspace for managing your resilience tasks and monitoring the resilience metrics from a single dashboard.
    • Gathering data aligned with the CSDM setup -- Beginning with Release 20.1.x, the Operational Resilience application supports the latest Common Service Data Model (CSDM). This section details the steps for setting up services, business services, service offerings, and business processes in Operational Resilience and gathering data aligned with the latest CSDM setup.
      • Using the flexible data model -- Starting with Operational Resilience, Release 21.0.x, the flexible data model enhances operational resilience metrics by improving data visualization and the flow of dependent services. It also supports multiple dashboards with insights into red flags, business service importance, and impact tolerance.
      • Data setup for business services -- Operational Resilience managers typically verify that data is set up for services or business services and monitor their resilience metrics on the dashboard. The Service (CMDB) Main node configuration fetches service-related data, while the Opres with CSDM header Main node configuration sets up the business services-related data.
      • Add a service to Operational Resilience reporting -- Manage services, business services, service offerings, business processes, and application services from the CSDM modules in the Operational Resilience Workspace.
      • Create New Service form -- Use the Create New Service form in Operational Resilience Workspace to set up a business service and configure its related lists.
      • Add a business service to Operational Resilience reporting -- Add a business service to Operational Resilience reporting in the Operational Resilience Workspace. The Operational Resilience managers with [sn_oper_res.manager] roles can add business services, service offerings, business processes, and application services to their entity types from the business service form or the list actions.
      • Create New Business Service form -- Use the Create New Business Service form in Operational Resilience Workspace to set up a business service and configure its related lists.
      • Add a service offering to Operational Resilience reporting -- Add a service offering to Operational Resilience reporting.
      • Create New Offering form -- Use the Create New Offering form in Operational Resilience Workspace to set up a service offering and configure its related information.
      • Add a business process to Operational Resilience reporting -- Add a business process to Operational Resilience reporting.
      • Create New Business Process form -- Use the Create New Business Process form in Operational Resilience Workspace to set up a business process and configure its related lists.
      • Add an application service to Operational Resilience reporting -- Add an application service to Operational Resilience reporting. Beginning with Operational Resilience, Release 21.0.x,the Application services module is supported in the Operational Resilience Workspace.
      • Create New Service Instance form -- Use the Create New Service Instance form in Operational Resilience Workspace to set up an application service and configure its related lists.
      • Verify the Main node configurations and relationships -- Verify that the Main node configurations are set up and the relationships are configured in Operational Resilience.
      • Execute the scheduled jobs -- Execute the scheduled jobs required for the main node relationships. After the scheduled jobs are executed, CSDM objects with their configured relationships are imported into Operational Resilience for reporting.
    • Interacting with the Nexus map UI from the Workspace -- Use the Nexus map (Resilience map) to define relationships between different records and configuration to show related data with hierarchy and plot those in a node map. You can examine the map's current configuration and identify areas for change. By modifying the configuration, you can observe how the map is updated accordingly.
    • Fetching dependencies from the CMDB and BIA -- You can fetch the dependencies for the services or business services from CMDB in Operational Resilience. Similarly, when the BCM applications are installed, the Operational Resilience scheduled job also monitors for the changes in the business impact analysis (BIA) dependencies and fetches the dependency updates.
    • Scenario analysis -- Conduct a scenario analysis to assess how a critical service performs under adverse conditions. Starting with Operational Resilience, version 22.3.1, you can use the advanced scenario analysis with simulation in the Operational Resilience Workspace, apply statistical modelling to quantify financial impact, and record a treatment decision.
      • Scenario analysis using simulation -- Scenario analysis using simulation is a guided, playbook-driven workflow in the Operational Resilience Workspace. It uses statistical modelling to quantify how critical services perform under adverse-event scenarios. The analysis takes you from scoping a service through to a treatment decision and, optionally, logging operational vulnerabilities and issues.
      • Building a scenario analysis using simulation -- Use the scenario analysis process to assess how critical services perform under adverse conditions using statistical simulation. Starting with Operational Resilience, version 22.3.1, Operational Resilience application, you can follow a guided playbook to perform a scenario analysis.
        • Verify the Smart Assessment templates setup -- Verify that the input and output Smart Assessment templates are set up and published in the Assessment Workspace before running an advanced scenario analysis. The Statistical model profile in the advanced scenario analysis uses these templates to present plain-language questions and display simulation results.
        • Create a scenario analysis record using simulation -- Create a Scenario analysis record to assess how a critical service performs under adverse conditions using statistical modelling. Use the guided Playbook experience to move through scoping, scenario selection, simulation, results review, and treatment decision.
        • Create Scenario Analysis form using simulation -- Use the Create Scenario Analysis form using Playbooks in Operational Resilience Workspace. Enter the details of a scenario analysis, such as its name, goal, method, and owner, before running the guided playbook.
        • Define the scope and dependencies -- Define the scope of the Scenario analysis by selecting the service to analyze and adding the dependencies that support it during a disruption.
        • Add scenarios and review reference data -- Select the adverse-event scenarios to test against the scoped service, then review the historical reference data that the system will use to auto-populate simulation inputs.
        • Start simulation and run scenario testing -- Complete the simulation assessment questionnaire to provide the statistical model with the input values required to run the simulation.
        • Run a scenario analysis using the manual method -- Run a scenario analysis on subject-matter-expert (SME) judgment instead of statistical simulation. The manual method reuses the guided playbook but omits the Reference Data step and the quantitative Results step.
        • Review results and decide the treatment -- Review the simulation output metrics, then select a treatment strategy to address the identified risk.
        • Log operational vulnerabilities and issues -- Optionally document operational weaknesses and link issues identified from the scenario analysis results to support remediation tracking.
        • Mark the scenario analysis as complete -- Complete the Scenario analysis after all required playbook steps are finished to lock the record and make the results available for reporting and governance review.
      • Scenario analysis entry points and flow configuration -- Starting with Operational Resilience, version 22.3.1, the advanced scenario analysis flow (sn_oper_res_scenario_analysis_advance) replaces the legacy scenario analysis flow (sn_oper_res_scenario_analysis) across different entry-point surfaces in the Operational Resilience Workspace.
      • Legacy scenario analysis -- By performing a scenario analysis, you can determine the risks that might impact your business. You can analyze the impact of the scenarios and events on your business services. You can also track the actions and improvements from the scenario analysis in Operational Resilience Workspace.
      • Enable the legacy scenario analysis flow -- Complete admin procedure to activate the legacy scenario analysis flow (sn_oper_res_scenario_analysis) across the four entry-point surfaces in the Operational Resilience Workspace. Deactivate the advanced flow when you want to continue using the legacy scenario analysis flow.
        • Create a legacy scenario analysis -- Create a scenario analysis for the business service in Operational Resilience Workspace. You can analyze the impact of the scenarios and associated events. You can then calculate the disruptions and determine if any of your services are breached.
        • Create Scenario analysis form -- Use the Create Scenario analysis form in Operational Resilience Workspace to add the details about the scenario analysis, milestones, assignees, and so on.
        • Associate a scope and define the dependencies -- Associate a scope by adding services and define the dependencies with the scenario analysis by adding services. You can then begin to analyze the impact of the scenarios and events in Operational Resilience Workspace.
        • Request the plan approval -- Request the plan approval from the analysis approver. You can then proceed with the scenario analysis in Operational Resilience Workspace.
        • Approve the plan for the scenario analysis -- Approve the plan for the scenario analysis in Operational Resilience Workspace if you're the plan approver. You can track the actions for the scenario analysis by checking your email notifications.
        • Adding a scenario event to the analysis -- You can add a scenario event to the scenario analysis and analyze its impact on your business service. If you are the scenario analysis owner, you can add the stakeholders and reviewers to the scenario analysis in Operational Resilience Workspace. You can then collate the observations of all participants and use their inputs to analyze the scenario.
        • Add a scenario event -- Add a scenario event to the scenario analysis and analyze its impact on the business service. By adding the participants, dependencies, services, issues to the scenario analysis in Operational Resilience Workspace, you can determine the impact of the scenario event on the business service.
          • Scenario event form -- Use the Scenario event form in Operational Resilience Workspace to associate a scenario event with your scenario analysis.
          • Scenario analysis response task form -- Use the Scenario analysis response task form in Operational Resilience Workspace to add the details about the response task that is associated with a scenario event.
        • Add a participant and monitor the responses -- Add a participant to the scenario analysis first and then add the scenario event, services, issues, and so on. If you are the scenario analysis owner, you can add the stakeholders and reviewers to the scenario analysis in Operational Resilience Workspace. You can then collate the observations of all participants and monitor their responses to analyze the scenario.
        • Link issues and operational vulnerabilities -- Link an issue to your scenario analysis by either creating a new issue or adding an existing one. You can also include operational vulnerabilities in the analysis to identify resilience gaps and create a plan to mitigate them.
        • Submit the scenario analysis and receive an approval -- Submit the scenario analysis for an approval in the Operational Resilience Workspace. The analysis approver for the scenario analysis reviews the details and subsequently approves it. Having an scenario analysis is the final step in the workflow.
        • Close the scenario analysis -- Close the scenario analysis in the Operational Resilience Workspace. Typically, scenario analyses that are incomplete or canceled are moved to the Closed state. Once closed, you can share your observations and notes with stakeholders.
    • Performing Importance and impact tolerance assessment -- By analyzing the importance and the impact tolerance of your business service or service offering, you can measure how possible disruptions might impact the performance of a service. You can use the assessment questionnaire template​ in Operational Resilience Workspace to measure the importance and the impact tolerance of your selected business service and its child records.
      • Create an Importance and impact tolerance assessment -- Determine the importance and impact tolerance of a business service by conducting an assessment using either Smart Assessment or Legacy assessment. The assessment questionnaire helps you to measure the service's importance and its impact on customers based on their responses. By evaluating the feedback, you can effectively gauge the significance of your business service and understand its effects on your customers.
      • Create New Importance and impact tolerance assessment form -- Use the Create New Importance and impact tolerance assessment form in Operational Resilience Workspace to create an assessment for the business service.
      • Define the scope and begin the assessment -- Define the scope by adding a business service to the Importance and impact tolerance assessment. With this assessment, you can estimate the impact and possible disruptions that can affect your business services.
      • Submit the assessment -- Log in as an assessor of the Importance and impact tolerance assessment, respond to the questionnaire, and submit the assessment in Operational Resilience Workspace for an approval.
      • Request an approval for the assessment -- Request an approval for the Importance and impact tolerance assessment in Operational Resilience Workspace. With an approval, you can make sure that an accurate rating is assigned to your business services.
      • Close the assessment -- Close the inactive Importance and impact tolerance assessment in the Operational Resilience Workspace.
    • Certifying services using self-attestation -- Certify the operational resilience status of your business services by completing the self-attestation process in the Operational Resilience Workspace. Complete the self-assessment questionnaire about the services, generate a self-attestation report, and upload the PDF so that you can have a copy of the report for your records. You can perform self-attestation on the selected business service and its child records.
      • Perform the self-attestation assessment -- Create an assessment for the self-attestation and certify the resilience status of services in the Operational Resilience Workspace. Perform the self-attestation assessment using the Smart Assessment template provided with the base system.
      • Create New Self attestation form -- If you're the owner of the self-attestation, use the Create New Self attestation form in Operational Resilience Workspace to submit the self-attestation for the services.
      • Submit the self-attestation report -- Submit the self-attestation report to its owner for the certification. You can then generate the PDF of the self-attestation report in the Operational Resilience Workspace for your records.
    • Managing Operational vulnerability -- Operational vulnerabilities are weaknesses in systems, processes, or procedures that can be exploited by attackers to compromise the security and integrity of an organization's operations. These vulnerabilities can arise from a variety of factors, including IT and non-IT operations.
      • Operational vulnerability -- The Operational vulnerability capability in Operational Resilience empowers users to flag operational vulnerabilities or critical functionality gaps, engage with key stakeholders, analyze underlying causes, and identify remedies.
      • Reporting Operational vulnerability -- Any Operational Resilience application user can report an operational vulnerability that needs the attention of the Operational Resilience team.
      • Report an Operational vulnerability from the Employee Center -- Report an operational vulnerability from the Employee Center. Any employee or user can report the operational vulnerabilities and complaints directly to the supporting teams for a quick response. The user in the assignment group can assign an analyst for the operational vulnerability. Reporting the issues helps to reduce and avert losses in a timely manner.
      • Report an Operational vulnerability from the module -- Report an operational vulnerability from the Operational vulnerability module in the Operational Resilience Workspace.
      • Report an Operational vulnerability from Importance assessment -- Report an operational vulnerability from the Importance and impact assessment in the Operational Resilience Workspace.
      • Report an Operational vulnerability from the Scenario analysis -- Report an operational vulnerability from the Scenario analysis in the Operational Resilience Workspace.
      • Report an Operational vulnerability from the Self-attestation module -- Report an Operational vulnerability from the Self-attestation module in the Operational Resilience Workspace.
      • Report an Operational vulnerability from the Service record -- Report an operational vulnerability from the Service record available in the Self-attestations list.
      • Add the primary origin -- Add a primary origin of an operational vulnerability in its record. Once the primary origin of the operational vulnerability is specified, its upstream dependencies are automatically included in the impacted areas. It enables you to view the operational vulnerability from all affected perspectives. The source is automatically added as the primary origin on the Primary origin tab.
      • Primary origin form -- On the Primary origin form, fill in the fields.
      • Add the impacted area -- Add an impacted area or an object to the operational vulnerability record in the Operational Resilience Workspace.
      • Impacted area form -- On the Impacted area form, fill in the fields.
      • Update the state of the Operational vulnerability -- Update the state of the Operational vulnerability record to the Assessment or Treatment state. At this stage, the vulnerability is being evaluated to determine the best course of action and create an action task accordingly.
      • Creating an action task for the operational vulnerability -- The Operational vulnerability analysts gather additional information or an evidence on the vulnerability by creating one or more action tasks. An action task can be of an assessment or investigation type.
      • Manage an assessment-type action task -- Create and manage an action task for the Operational vulnerability, where the type of the task is assessment. You can then assign it to an appropriate task owner.
        • Create New Action task form -- On the Create New Action task form, fill in the fields.
        • Reassign or accept the assigned action task -- Reassign or accept the assigned action task that is listed in the My items list of the Tasks module if you are the task owner. You must review the task details listed in the Details tab, reassign the action task to another task owner, or accept the work.
        • Perform an assessment on the action task -- Perform an assessment on the action task by reviewing its assessment details. As the action task owner, you can view the details of the action task and assessment history in the action task record and then complete the assessment.
      • Manage an investigation-type action task -- Manage an investigation-type action task for the Operational vulnerability. An investigation-type action task is initiated when additional investigation is needed to resolve the vulnerability. If the approver rejects the Operational vulnerability and requests more investigation, the task owner can create an investigation-type of action task, assign it to an appropriate user, review their completed work, and then request an approval again.
      • Request an approval for the action task -- Complete the work on the assessment-type or the investigation-type action task and then request an approval from the approvers of the Operational vulnerability record.
      • Decide the treatment and perform a root cause analysis -- Decide the treatment and perform a root cause analysis for the Operational vulnerability. After completing the action tasks, the vulnerability analyst devises the next course of treatment and updates their observations and analysis in the Details tab of the Operational vulnerability record.
      • Add or create an issue for the Operational vulnerability -- Add an existing issue from the available issues or create an issue for the Operational vulnerability.
      • Request an approval -- Request an approval for the Operational vulnerability record. When you request an approval, the state of the vulnerability is updated to the Pending approval state and then to the Requested state respectively.
      • Approve the operational vulnerability -- Approve the Operational vulnerability record after verifying its details such as the root cause analysis, treatment plan, timelines, and so on.
      • Close the operational vulnerability -- Verify the details and close the Operational vulnerability record as the Operational vulnerability analyst.
    • Maintaining Digital resilience third-party registers -- The Digital resilience third-party registers application enables the customers to maintain the contractual arrangements on the use of Information and Communication Technology (ICT) services, that support critical or important functions provided by ICT third-party service providers. Customers can manage the contractual arrangements details through the graphical user interface (GUI) or by importing or exporting Microsoft Excel files.
      • Exploring Digital resilience third-party registers -- The Digital resilience third-party registers application empowers the financial entities to maintain registers of contractual arrangements with Information and Communication Technology (ICT) third-party service providers and comply with Digital Operational Resilience Act (DORA) regulation.
      • Use cases for updating the information registers -- Users with third-party registers and contractual details spread across various systems can automate the process of populating their information registers. This section outlines common scenarios for recording third-party data into Digital resilience third-party registers.
      • Register of information regulatory packages -- The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital resilience third-party registers application in the Operational Resilience Workspace.
      • Validation framework for Register of Information in Operational Resilience -- The validation framework helps to verify that RoI packages meet regulatory requirements defined by the DORA.
      • Configuring Digital resilience third-party registers -- Set up Digital resilience third-party registers in the Operational Resilience Workspace to manage the records of ICT third-party service providers.
      • Creating and reviewing the records -- The Operational Resilience administrators and managers can access the Digital Resilience Choices records in an instance. For best results, it is important to create or update the records such as legal entities, branches, functions, contracts, and so on in a specific order into the Digital resilience third-party registers application. Those specifics are outlined in this section.
      • Validate the Register of Information packages -- Run real-time validation on Register of Information (RoI) packages to help ensure compliance with DORA requirements.
      • Display the help tips on the forms -- Display the help tips on the forms by updating the preferences. Help tips provide extra details about the fields and their related actions.
      • Using Digital resilience third-party registers -- Use the Digital resilience third-party registers application in the Operational Resilience Workspace to create, update, and track records of ICT third-party service providers.
      • Create a legal entity and enhance digital resilience data -- Create a legal entity record in Digital resilience third-party registers. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a branch and enhance digital resilience data -- Create a branch record in Digital resilience third-party registers. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a function and enhance digital resilience data -- Create a function record in Digital resilience third-party registers where you can configure details of the function such as function identifier, license activity, function name, criticality or importance assessment details, and so on. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a third party and enhance digital resilience data -- Create a third party record in Digital resilience third-party registers. Add the details of the third party company such as its name, address, phone number, vendor manager, and so on. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a third-party engagement and enhance digital resilience data -- Create a third-party engagement record in Digital resilience third-party registers. Add details of the third-party engagement such as name of the third party, its type, annual spend, engagement tier, and so on. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a contract and enhance digital resilience data -- Create a contract record in Digital resilience third-party registers where you add details of the contract such as vendor name, start and end dates, state, substate, and so on. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create a supply chain and enhance digital resilience data -- Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers. Add details of the supply chain such as type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services, and so on. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create an assessment and enhance digital resilience data -- Create an assessment of the Information and Communication Technology (ICT) service in Digital resilience third-party registers. Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create Microsoft Excel download and upload request -- Create a Microsoft Excel upload and download request to upload and download the records from and into the Digital resilience third-party registers for auditing purposes.
      • Currency conversion and third-party aggregation -- Beginning with Digital Operational Resilience Management (sn_dora_accel), version 22.x.x, currency conversion and third-party aggregation capabilities are supported for DORA reporting of third-party expenses. As a DORA application user, you can convert and aggregate contractual expenses from multiple currencies to a regulator-required designated base currency using automated daily exchange rates.
        • Convert and aggregate contractual expenses to regulator-required currencies -- Convert and aggregate contractual expenses to regulator-required currencies and generate consolidated reports for reporting submissions. Beginning with Digital Operational Resilience Management (sn_dora_accel), version 22.x.x, these currency conversion and third-party aggregation capabilities are supported for DORA reporting.
      • Create records in bulk -- Create records in bulk from the Digital resilience third-party registers using Third-party Risk Management rather than creating one record at a time for single or multiple entities. You can save time and effort by working on multiple records at a time.
      • Update existing records in bulk -- Update existing records in bulk from the Digital resilience third-party registers using Third-party Risk Management.
      • Generate a register of information package -- Generate a register of information package. Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.
      • Validate LEI codes -- Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.
        • Level 4 LEI Validation Report columns -- The Level 4 LEI Validation Report (Level4_LEI_Validation_Report.csv) is generated during Plain-CSV Reporting Package download and lists the validation result for each Legal Entity Identifier (LEI) code found in the reporting package.
    • Using Digital resilience incident reporting -- Beginning with the Yokohama release, users of the Operational Resilience Workspace can report Information and Communication Technology (ICT) related incidents to regulators using the Digital resilience incident reporting module. This module, integrated with Incident Management and Security Incident Response, creates or updates incident case task records whenever a major incident is created or updated in these applications. The report is generated in the specified format and shared with regulators.
      • Explore -- The Digital resilience incident reporting module in the Operational Resilience Workspace is used to log and report incidents data to the regulators.
      • Configure -- Digital Resilience Incident administrators can configure conditions in Workflow Studio to auto-trigger incident reporting in Digital resilience incident reporting.
      • Set up entities for the targets -- Set up an entity record in the instance and map it to an incident or security incident. You can map one or multiple entities to the selected incident.
      • Map regulations to the entities -- Map single or multiple regulations with the entity linked to an incident or security incident.
      • Set up DRIR Smart Assessment templates in the Assessment Workspace -- Set up the Smart Assessment templates in the Assessment Workspace. You can then use them to set up the action task configuration templates in the Regulatory Agency Profile for Digital resilience incident reporting.
      • Set up action task templates in Regulatory agency profile -- Set up action task templates in the Regulatory Body Management Agency Profile [sn_reg_body_mgmt_agency_profile.list] table. Verify that the action task configurations (with Smart Assessment Smart Assessment template configurations) for the selected regulation are correctly set up.
      • Set up the flows in Flow Designer -- Set up the flows and conditions for Digital resilience incident reporting in Workflow Studio. As administrators of the Operational Resilience application, you can update (customize) the flow configurations to meet your organizational requirements.
      • Manage -- This section details the steps that you can take to report major incidents in the Digital resilience incident reporting application. Assess whether any critical services are affected and classify the reported incident as a major incident if necessary. Notify regulators of major incidents, categorized by their severity and security ratings.
      • Reporting incidents from SOW and SIR Workspace in DRIR -- When a high-impact, high-urgency incident is created or an existing incident is marked as high priority in the Service Operations Workspace (SOW) of Incident Management or Security Incident Response Workspace (SIR Workspace), it is classified as a major incident. These major incidents are then logged and reported in the Digital resilience incident reporting application.
      • Report a major incident manually -- Report a critical incident manually in the Digital resilience incident reporting application from the Operational Resilience Workspace.
      • Reporting incidents or security incidents for multiple regulations -- You can now report incidents or security incidents for multiple regulations for various legal entities in Digital resilience incident reporting. The application streamlines operations by automating tasks, migrating data, helping to prevent duplicates, and verifying accurate reporting.
        • Complete action tasks and report incidents associated with regulations -- Report incidents or security incidents associated with multiple regulations for various legal entities. The automated workflow generates regulatory reporting assessments of IT incidents, and Digital resilience incident (DRI) Initial, Intermediate, and Final reports, all within regulatory timelines. Complete the action tasks and generate reports in Microsoft Word format, as required by regulatory authorities for analysis.
      • Generating Microsoft Word reports using Document designer -- Digital resilience incident reporting administrators (sn_dri_inc_rptg.digital_resilience_incident_administrator) can now set up Microsoft Word templates and Digital resilience incident reporting managers (sn_dri_inc_rptg.digital_resilience_incident_manager) can download action task reports in Microsoft Word format​.
        • Install the Document designer with Word application -- Install the ServiceNow Document designer with Word (sn_grc_doc_design) application. It extracts metadata (including fields, related lists, and reference fields with their associated elements) from ServiceNow tables and enables the insertion of repeating content blocks (for example, 10 blocks for 10 issues) based on record count. When applied to specific records, the template generates a Microsoft Word document.
        • Create Template configurations -- Use the Template Configurations module to set up the template relationship registry. This module displays document design template configurations for action tasks. It enables you to configure data relationships, content, and scripted variables via the Document designer application so that required data is displayed in your reports.
        • Create Data relationships -- Create the data relationships in the Template Configurations module, which helps you to navigate from a record in the template configuration to any table. When you create these paths, you can fetch the necessary data from each of these records in the report template.
        • Create Content configurations -- Set up the content configurations in the Template Configurations module to define the data you want to view or fetch when creating a report template. You can configure it to display a list of records or aggregated data, such as a list of remediation tasks or top priority issues. You can fetch up to 200 records from any table.
        • Create Reporting configurations -- Use the Reporting configurations (sn_esg_msoff_intg_o365_reporting_configuration) module to manage Reporting configurations that are scoped to the Digital resilience incident (DRI) business domain. The Reporting configurations module is available in the Digital resilience incident reporting application menu.
        • Create Reporting Configuration form -- On the Create New Reporting Configuration form, fill in the fields.
        • Download the manifest file -- Install ServiceNow Document designer manifest file. This add-in should be enabled for customizing the reports and Microsoft Word templates, according to your business needs.
        • Build the Microsoft Word template using the add-in -- Build the Microsoft Word template using the add-in. The Word Templates module provides the Digital resilience incident (DRI) Word templates that are used to generate Microsoft Word reports.
        • Generate a Microsoft Word report -- Generate customized Microsoft Word reports for different records using Microsoft Word templates. This functionality enables you to streamline reporting in a standardized format.
    • Creating or adding an issue -- You can associate an issue with multiple objects such as controls, control objectives, risks, and so on in Operational Resilience Workspace. You can add an existing issue or create an issue for a business service or a scenario analysis in the Operational Resilience application.
      • Create New Issue form -- Use the Create New Issue form in Operational Resilience Workspace to add an issue to a business service or a scenario analysis.
    • Landing page and dashboard views -- The landing page in the Operational Resilience Workspace provides a single-pane overview of the services, business services, and pillars in your organization. The dashboard displays resilience metrics, including operational status, completed activities, red flags, and suggestions for improvement.
    • Resilience metrics -- You can view resilience metrics for services or business services, and pillars on the landing page of the Operational Resilience Workspace.
    • Business services overview tab -- The Business services overview tab in the Operational Resilience Workspace provides a comprehensive summary of active business services, highlighting any red flags or urgent issues, status of resilience activities like assessments, scenario analysis, self-attestations. It also offers suggestions for mitigating top risks or vulnerabilities and strengthening top controls.
    • Services overview tab -- The Services overview tab in the Operational Resilience Workspace provides a comprehensive summary of active services, highlighting any red flags or urgent issues, status of resilience activities like assessments, scenario analysis, self-attestations. It also offers suggestions for mitigating top risks or vulnerabilities and strengthening top controls.
    • Pillars overview tab -- A pillar is a foundational element that supports your organization's operational resilience. You can map business services and processes to these pillars in the Operational Resilience application to establish relationships and monitor their status on the dashboard in the Operational Resilience Workspace.
    • Task page and List view -- The Tasks page in Operational Resilience Workspace provides a single-pane view of your pending tasks, your group's tasks, and the tasks that are on your watchlist. You can also update the tasks directly from the dashboard. On the List page, you can configure your operational resilience tasks.
    • Reference -- Reference topics provide additional information such as tables, roles, and properties that are installed with the Operational Resilience application. Several types of components are installed with the activation of the Operational Resilience application, including properties, roles, and tables.
    • Properties installed with Operational Resilience -- When you install the Operational Resilience application, several system properties are added to your instance. You may not need to modify these properties. The user with the sn_oper_res.admin role can maintain these properties.
    • Roles installed with Operational Resilience -- Several types of roles are installed with the Operational Resilience application.
    • Scheduled jobs installed with Operational Resilience -- When you install the Operational Resilience application, the Update CSDM and other dependencies, Calculate red flags for CSDM and dependencies, Update other dependencies scheduled jobs are added to your instance. As a user with the sn_oper_res.admin role, you may find this information useful.
    • Script includes installed with Operational Resilience -- When you download the Operational Resilience application, several Script includes are added to your instance.
    • Tables installed with Operational Resilience -- Several types of tables are installed with the Operational Resilience application.
      • Tables relevant to CSDM -- Reference topics provide additional information about CSDM, including the associated roles, scheduled jobs, and tables. This section lists the tables relevant to CSDM.
      • Tables relevant to Operational vulnerability -- Reference topics provide additional information about the Operational vulnerability, including the associated tables and roles.
    • Digital resilience third-party registers reference -- Reference topics provide additional information about Digital resilience third-party registers including roles and tables.
    • Digital resilience incident reporting reference -- Reference topics provide additional information about the Digital resilience incident reporting application, including the associated tables and roles.
  • Policy and Compliance Management -- The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.
    • Explore -- The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.
    • Structural overview -- The structural overview of Policy and Compliance Management enables you to understand how the different modules that make up the Policy and Compliance Management application of ServiceNow integrate and interact with one another.
    • Implement -- Use the steps in the GRC: Policy and Compliance Management application checklist to download the Policy and Compliance Management from the ServiceNow Store, and get it ready for operation. Mandatory and optional setup steps, as well as an implementation checklist are provided to simplify the setup.
    • Implement setup checklist -- This checklist includes the setup tasks that you are required to complete in your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance GRC: Policy and Compliance Management functionality.
    • Download -- Before you run GRC: Policy and Compliance Management (com.sn_compliance) in your instance, you must download it from the ServiceNow Store.
      • Quick start tests -- Validate that GRC: Policy and Compliance Management still works after you make any configuration change, such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
    • Perform -- Prior to performing application-specific setup, you need to prepare the system. This involves assigning user roles and setting properties.
      • Assign roles -- Before you can successfully implement or use the Policy and Compliance Management application, you must assign roles to your users.
      • Set properties -- Set properties to control various aspects and behaviors in the software.
    • Mandatory setup -- After you have assigned roles to your users and set Policy and Compliance Management properties, proceed with the mandatory setup steps.
      • Create policy -- A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.
      • Create control objective -- A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies.
      • Relate control objective -- Associate the control objective to a policy individually when the policy is in the review or draft state by clicking the edit button in the Control Objective related list.
      • Create control attestation -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Create control indicator -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.
    • Enhancement steps -- After you have set up the Policy and Compliance Management base system, you can perform the procedures listed in the following sections to enhance the functionality of the application.
      • Create article template -- Policy and Compliance managers can create templates for policy article publishing.
      • Create or deactivate citation -- Usually, authority documents, citations, and control objectives are downloaded from a third-party provider. However, citations can be created manually from an authority document. The Active option in a citation indicates whether the citation is active or inactive.
      • Set notification properties -- After an acknowledgement request has been sent to an audience, different reminder notifications are sent based on the timeliness and state of the response. Properties allow you to configure the notifications.
      • Set up GRC Virtual Agent -- Set up the Governance, Risk, and Compliance Virtual Agent to request an exception to a policy or a control objective from the Service Portal.
      • Allow policy exception requests -- Starting with Version 10.1, you can leverage new policy exception capabilities in Policy and Compliance Management from within other applications.
      • Configure policy exceptions -- Before you can request policy exceptions from applications other than Policy and Compliance Management, you must add a UI action for making the request and, optionally, create a new list view to see policy exception target records on the Policy Exception form.
      • Register other applications -- Enable other applications to request policy exception from any table such as Problem or Incident and so on. The applications must be added and configured in the Integration Registry.
      • Define policy exception reason choices -- You can define reason choices to be available to any user who requests an exception.
      • Define policy categories -- You can filter policies by specific criteria to limit the number of policies displayed when you are creating policy exceptions.
      • Create exception questionnaire -- When you are setting up the Policy Exception Integration Registry, you can define configurable questions that can be included in risk assessments created from templates. The Policy Exception Integration Registry can be associated with one template at a time.
      • Define policy exception verification rules -- The verification rule is used to verify the accuracy and completeness of a policy exception request prior to sending it out for approvals. You can define multiple levels of approvers for an application.
      • Define policy exception approval rules -- Approval rules define the criteria (risk rating, policy or control objective) that is used for sending approval requests for an exception. Rules can be configured for an application and you can identify multiple levels of approvers, as needed.
      • Define policy extension approval rules -- Enable the GRC Approval Configurator from the Policy and Compliance Properties page to allow multiple approvers for policy extension approvals, replacing the single default approver (Compliance Manager).
      • GRC Approval Configurator -- Users can now manage policy exceptions and extensions with granular, multi-level approval flows using the GRC Approval Configurator.
      • Enable GRC Approval Configurator -- Enable the GRC Approval Configurator from the Policy and Compliance Properties page.
      • Define policy exception and extension rules -- Configure granular approval rules for policy exceptions and extensions using the GRC Approval Configurator.
    • Classic UI -- You can continue to use the Classic environment to perform all Policy and Compliance Management activities.
    • Manage -- The Policies and Procedures module contains overview and detailed information related to policy approvals, policies, and control objectives.
      • Create policy -- A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates.
      • Approve and publish policy -- When a policy is approved, it is automatically published.
      • Acknowledge policy -- After a policy has been published, you can create an acknowledgement campaign to define a group of your employees who must provide an acknowledgement that a particular policy is in compliance. When the campaign has been defined, you can submit the request to the audience.
      • Set up campaign -- A policy campaign is the record used to prepare for a policy acknowledgement request. It defines the audience who must provide an acknowledgement that a particular policy is in compliance. A policy campaign is requested only if the compliance user decides it is needed.
        • Create audience -- When you set up a policy acknowledgement request, you must identify an audience responsible for providing the acknowledgement.
      • Submit acknowledgement request -- After you have created an acknowledgement campaign, you can submit the acknowledgement request to the defined audience.
      • Respond to acknowledgement request -- After you have been identified as a member of an audience to provide a policy acknowledgement, you must open and review the record, and then acknowledge it.
      • Work with acknowledgements -- After you have received a request to provide acknowledgement for a policy, you have the option of working with the request in the ServiceNow AI Platform, or you can perform your actions in the ServiceNow Service Portal.
      • Retire policy -- Retiring a policy is part of the policy management process.
      • Create article template -- Policy and Compliance managers can create templates for policy article publishing.
      • Create control objective -- A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies.
      • Deactivate a control objective -- Deactivate control objectives that are no longer relevant to their citation or parent control objective.
      • Relate control objective -- Associate the control objective to a policy individually when the policy is in the review or draft state by clicking the edit button in the Control Objective related list.
      • Relate control objective -- A single control objective can be mapped to many citations from different authority documents. This function allows you to test a control objective once while complying with many different citations.
      • Create or deactivate citation -- Usually, authority documents, citations, and control objectives are downloaded from a third-party provider. However, citations can be created manually from an authority document. The Active option in a citation indicates whether the citation is active or inactive.
      • Create authority document -- Authority documents manage a process and citations are created within them to manage points of the process. For example, the process called Building Security contains a citation for Entry Control.
      • Deactivate authority document -- The Active option in an authority document indicates whether the authority documents have been retired.
    • Manage policy exceptions and extensions -- Policy exceptions and extensions provide temporary relief for non-compliant controls.
      • Request policy exception -- Users can request exceptions for policies, control objectives, or issues by specifying the reason of exception on a particular list of the systems, applications, networks, or entities for which the exception will apply. The user must also specify the duration for which the exception is required.
      • Request policy extension -- Request an extension for the policy exception that you created.
      • Review policy exception and extension -- After reviewing a policy exception request, a compliance manager can accept or reject the request. However, if the compliance manager doesn't have enough information decide, they can request a risk assessment by the risk manager.
      • Request policy exception -- Your employees and business users within your company can request a policy exception through the ServiceNow Service Portal.
      • Request policy extension -- From the ServiceNow Portal, anyone who has requested a policy exception can request an extension before the policy deadline.
      • Integration with Vulnerability Response -- Starting with Version 10.1, you can request policy exceptions using the GRC policy exception management capability inherent in the Policy and Compliance Management application from within version 10.3 of the Vulnerability Response application.
    • Manage issues -- You can measure the effectiveness of your company's risk management program by how quickly and completely it identifies and reacts to compliance issues.
      • Manually create issues -- As a GRC user, you can manually create issues to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.
      • Group issues under new parent -- When you are creating an issue, you have the option of grouping the issue with other similar issues.
      • Group issues under existing parent -- When you are creating an issue, you have the option of grouping the issue with other similar issues as part of an existing parent issue group.
      • User hierarchy access control -- If a user is assigned to an issue or a remediation task, then the manager of the user and the manager above in the hierarchy also get access to the issue or remediation task record.
      • Report self-identified issues -- Your employees and business users within your company can self-identify an issue and submit it via the ServiceNow Service Portal. Following submission, a triage issue is automatically created.
      • Triage self-identified issue -- After an issue has been identified and submitted by employees or business users via the Service Portal, the issue triage process begins. The actual problem is identified and assigned to the appropriate owner for prioritization and resolution.
      • Remediate issue -- After an issue has been identified, triaged, and investigated, you can remediate it.
    • Manage UCF integration -- Network Frontiers Unified Compliance Framework (UCF) integrates with your ServiceNow instance through an authentication process that validates your subscription. On the UCF Configuration form, you select the type of authentication, and then enter a UCF-provided API key or a ServiceNow – provided Oauth2 client and secret.
      • Activate Compliance UCF -- The GRC: Compliance UCF (com.sn_comp_ucf) plugin is available as a separate subscription.
      • Configure UCF integration through API key -- UCF integrates with your ServiceNow instance through an authentication process which validates your subscription.
      • Configure UCF integration using UCF CCH -- Compliance administrators can download content from Network Frontiers Unified Compliance Framework (UCF) to use as GRC authority documents, citations, controls, and control objectives.
      • integrate with UCF Common Controls Hub -- Compliance administrators can download content from Network Frontiers Unified Compliance Framework (UCF) to use as GRC authority documents, citations, controls, and control objectives. The documents can be updated on pre-defined intervals. You must have a UCF Common Controls Hub account to create shared lists and import them into the ServiceNow instance.
        • Create Now Support Case -- After establishing your UCF CCH account, use the Now Support Service Portal to initiate the account integration process.
        • Download UCF Shared list -- In order for compliance managers to download UCF authority documents from the UCF CCH, the list must be marked as Shared. When updating Authority Documents or adding new ones, you must update all your authority documents to ensure that the common controls framework remains in sync with the authority documents you are using.
      • Eliminate duplicate citations -- You can eliminate duplicate citations associated with the authority documents when you receive citations from UCF content as part of the same Shared list.
    • Manage controls -- Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.
      • Create control -- Controls are automatically generated when you associate a policy with an entity type or an entity type with a control objective. A control is created for each entity listed in the entity type for the control objective. Controls can also be manually created.
      • Follow control -- Connect integrates with Policy and Compliance Management providing an overlay to the standard interface, allowing users to participate in conversations while they work and collaborate on the control record.
      • Attest control -- Attestations are surveys that gather evidence to prove that a control is implemented. If the control attestation and respondents fields are selected, when the control moves from the Draft state to the Attest state, a notification is sent to the attestation respondents.
      • Create multiple controls -- You can create multiple controls for a unique combination of an entity and a control objective to get granular control information.
    • Manage control attestations -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Create control attestation -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Create attestation type -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Group attestations using Same Response -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Group attestations using Different Response -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
      • Define assessment grouping criteria -- Attestations are surveys that gather evidence to prove that a control is implemented. Attestations document how the control is measured. This method is frequently used during the Draft and Monitor state.
    • Manage control indicators -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.
      • Create control indicator -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.
      • Create GRC indicator template -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.
    • Monitor controls -- You can link Policy and Compliance Management content and items to Performance Analytics indicators, breakdowns, and thresholds. You can associate Performance Analytics indicators with control objectives and controls to view scorecards and trends and analyze current conditions and trends.
      • Activate performance analytics integration -- You can link Policy and Compliance Management content and items to Performance Analytics indicators, breakdowns, and thresholds. You can associate Performance Analytics indicators with control objectives and controls to view scorecards and trends and analyze current conditions and trends.
      • Associate PA indicator with risk or control objective -- You can link Policy and Compliance Management content and items to Performance Analytics indicators, breakdowns, and thresholds. You can associate Performance Analytics indicators with control objectives and controls to view scorecards and trends and analyze current conditions and trends.
      • Associate PA indicator with risk or control -- You can link Policy and Compliance Management content and items to Performance Analytics indicators, breakdowns, and thresholds. You can associate Performance Analytics indicators with control objectives and controls to view scorecards and trends and analyze current conditions and trends.
      • Update associated indicators -- You can link Policy and Compliance Management content and items to Performance Analytics indicators, breakdowns, and thresholds. You can associate Performance Analytics indicators with control objectives and controls to view scorecards and trends and analyze current conditions and trends.
    • Manage evidence requests -- Evidence request is used by audit and compliance teams for requesting supporting documents during an audit. Auditors and compliance teams require these documents from the first line of defense.
      • Evidence request workflow -- Evidence request helps customers to electronically request the information that they need from the first and second line of defense. The individuals being audited can then immediately upload their documents to the system, significantly reducing manual processing time.
      • Request evidence during audits -- Request evidence at any stage during an audit. The details about the items for which evidence is requested are also provided to the person responsible for providing the evidence.
      • Reuse evidence from related engagement items -- Inform the audit and compliance user about the evidences that are already existing for the related items of an engagement. You can add such an evidence, if it is already existing for any of the related item table of an engagement for which you are requesting an evidence.
      • Provide requested evidence -- Provide evidence when you are requested. When evidence is requested, the person who must provide the evidence receives an email. The process to provide the evidence begins.
      • Approve evidence -- Approve the evidence being provided before the requester views the evidence. When evidence is provided in response to an evidence request, the evidence may need an approval before the evidence is sent back to the requester. This ability ensures security and confidentiality of the evidence.
      • Review and manage evidence requests -- Accept, reject, or cancel an evidence request when you receive the evidence you requested. After requesting an evidence request, when the requester receives the evidence, the requester can accept, reject, or cancel the evidence request.
      • Enable Related Evidence related list -- The Evidence Request feature includes a related list called Related Evidence, which it not visible by default. This related list provides a list of evidence that is not directly requested for the current record, but is associated to a related record. For example, the Related Evidence list on the Control Objective form shows evidence requested for associated controls.
    • Manage GRC tasks from Employee Center -- Employee Center is designed for enterprise services based on employee needs. The employee center is also called as Business user service portal as the portal is exclusively for GRC business users to request an issue triage or raise a policy exception.
    • Report GRC issues -- Use the employee portal to review and work on the action plan related to the observation which is confirmed as an issue that as an auditee or issue owner you need to remediate.
    • Create policy exception -- Use the Employee Center to request exceptions for policies, control objectives, controls, or issues by specifying the reason of exception on a particular list of the systems, applications, networks, or entities for which the exception applies.
    • Complete control assessments -- Use the Employee Center Home page to view all your requests, raise issue requests and policy exceptions, and complete all your GRC assessments.
    • Policy knowledge base -- You can view all the Knowledge base (KB) articles related to the published policies in Employee Center.
    • Group similar assessments -- Group the assessments that have the same entity or control objective based on metric type, and additionally the same entity, control objective, or category to provide response to similar assessments.
    • GRC Compliance workspace -- Starting with Version 13.0.0, a new workspace has been introduced for the GRC: Policy and Compliance Management application. The new workspace provides you with an improved User Experience (UX) and a simplified user journey.
    • Compliance Workspace -- Compliance Workspace is a unified interface where you can manage all your tasks related to policies, control objectives, controls, and policy exceptions.
      • Compliance Manager home -- The compliance manager home page in the Compliance Workspace gives a complete overview of the compliance posture of the organization. The workspace helps the compliance manager to centrally manage internal standards, policies, and control processes that match the external regulatory standards.
      • Compliance Analyst home -- The compliance analyst home page in the Compliance Workspace enables the compliance analyst to track compliance activities and helps compliance managers to ensure that the organization is compliant with various regulations and policies.
      • IT Compliance Manager home -- The Compliance Workspace provides an exclusive home page for the IT compliance manager to view the IT-related risk and compliance data. The workspace helps the IT compliance manager to centrally manage internal standards, policies, and control processes that are exclusively IT-related to comply with the external regulatory standards.
    • Configure -- Configuring the Compliance Workspace requires setting up certain pre-requisite steps.
      • Configure IT compliance manager data filter -- There are three distinct steps that must be followed to segregate, associate, and display the IT-related data for the IT compliance manager to view in the IT Compliance Home page.
    • Use -- The Compliance Workspace has a unified tasks page. Based on the user role you can fulfil all your tasks and your team's tasks in the page.
      • Manage control objectives and policies -- You can use the Compliance Workspace to manage information related to policy approvals, policies, and control objectives.
      • Create policy -- A policy defines an internal practice that processes must follow. You can define policies using the Compliance Workspace as policies, procedures, standards, plans, checklists, frameworks, and templates.
        • Manage compliance of policy -- The policy module helps you to create and document all policies. Policies are high-level statements that define what a business should or should not do.
      • Approve and publish policy -- When a policy is approved, it is automatically published.
      • Acknowledge policy -- After a policy is published, create an acknowledgement campaign to define an audience, notify them to confirm that the policy is in compliance, and track their responses.
        • Set up policy acknowledgement campaign -- A policy campaign is the record used to prepare for a policy acknowledgement request. It defines the audience who must provide an acknowledgement that a particular policy is in compliance. A policy campaign is requested in the Compliance Workspace only if the compliance user decides it is needed.
        • Create audience -- When you set up a policy acknowledgement request in the Compliance Workspace, you must identify an audience responsible for providing the acknowledgement.
        • Submit acknowledgement request -- After you have created an acknowledgement campaign using the Compliance Workspace, you can submit the acknowledgement request to the defined audience.
        • Respond to acknowledgement request -- After you have been identified as a member of an audience to provide a policy acknowledgement, you must open and review the record in the Compliance Workspace, and then acknowledge it.
      • Retire policy -- Retiring a policy is part of the policy management process. It can be retired using the Compliance Workspace anytime after being approved and published to the KB.
      • Create article template -- Policy and Compliance managers can use the Compliance Workspace to create templates for policy article publishing.
      • Create control objective -- A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies using the Compliance Workspace.
      • Perform CRI tiering questionnaire -- Perform CRI tiering questionnaire on an entity to determine its tier, evaluation controls associated with the tier will be created or updated. Based on the response to the CRI questionnaire from the assessor, the compliance status of each mapped control to a question is determined and the overall compliance score of the entity is calculated.
      • Perform CRI profile assessment -- Perform CRI profile assessment based on the tiering questionnaire of an entity to determine the compliance status of the controls and know the compliance score that rolls up to the entity.
      • Deactivate control objective -- Using the Compliance Workspace, you can deactivate control objectives that are no longer relevant to their citation or parent control objective.
      • Relate control objective to policy -- Control objective can be associated to a policy individually when the policy is in the review or draft state. Using the Compliance Workspace, you can choose the policy in the document field on the control objective, or edit the Control Objective related list.
      • Relate control objective to citation -- Using the Compliance Workspace, you can map a single control objective to many citations from different authority documents. This function allows you to test a control objective once while complying with many different citations.
      • Create citation -- Authority documents, citations, and control objectives are usually downloaded from a third-party provider. However, citations can be created manually from an authority document using the Compliance Workspace. The Active option in a citation indicates whether the citation is active or inactive.
      • Create authority document -- Authority documents manage a process, and citations are created within them to manage the points of the process. For example, the process called Building Security contains a citation for Entry Control.
      • Deactivate authority document -- The Active option in an authority document indicates whether the authority documents have been retired.
      • Manage policy exceptions and extensions using the Compliance Workspace -- Policy exceptions and extensions provide temporary relief for non-compliant controls. The policy exception captures the rationale, comments, and evidence to support the acceptance or rejection of a policy exception request.
      • Request a policy exception using the Compliance Workspace -- Use the Compliance Workspace to request exceptions for policies, control objectives, or issues by specifying the reason of exception on a particular list of the systems, applications, networks, or entities for which the exception applies. You must also specify the duration for which the exception is required.
      • Review the policy exception and extension request using the Compliance Workspace -- After reviewing a policy exception request using the Compliance Workspace, a compliance manager can accept or reject the request. However, if the compliance manager doesn't have enough information to decide, they can request a risk assessment by the risk manager.
      • Assess risks of policy exception using advanced risk assessments -- Take the advanced risk assessment to evaluate the risk involved with the policy exception.
      • Manage issues using the Compliance Workspace -- Using the Compliance Workspace, you can measure the effectiveness of your company's risk management program by how quickly and completely it identifies and reacts to risk and compliance issues.
      • Manually create GRC issues using the Compliance Workspace -- Using the Compliance Workspace, GRC you can manually create issues to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.
      • Linking issues to multiple objects using Many-to-many table relationship -- Issues can be linked to different types of objects such as risk, entity, control, control objective, engagement, policy, authority document, and others to determine issue impact. Use the many-to-many relationship tables for each of the objects to link similar issues to an object.
      • Triage self-identified issues -- After an issue has been identified and submitted by employees or business users via the Service Portal, the issue triage process begins. The actual problem is identified and assigned to the appropriate owner for prioritization and resolution in the Compliance Workspace.
      • Remediate an issue using the Compliance Workspace -- After an issue has been identified, triaged, and investigated using the Compliance Workspace, you can remediate it.
      • Manage controls using the Compliance Workspace -- Controls are specific implementations of a control objective. Retired controls do not appear in the list. Before defining controls, take time to rationalize, consolidate, and define the important controls in your organization.
      • Create a control using the Compliance Workspace -- Controls are automatically generated when you associate a policy with an entity type, or an entity type with a control objective, or when an entity is added to a control objective. A control is created for each entity listed in the entity type for the control objective. Controls can also be manually created using the Compliance Workspace.
      • Linking automatically generated issues to a control in Many-to-many relationship -- You can link an automatically generated issue that belongs to a different control as a related issue to a control. The Originator flag helps you to differentiate those control issues that were automatically generated from the controls that were manually created.
      • Testing common control and implementing results -- Instead of generating controls for individual entities and testing each entity separately with an individual control, you can use a common control and associate a primary entity to it.
        • Convert standard control to common control -- Mark a control as common and associate reliant entities to it. Test the common control tied to the primary entity. The reliant entities inherit the results of the common control.
        • Impact of common control on compliance score calculation -- Whenever an entity is associated to a common control and termed as a reliant entity, there is an impact on the compliance score of the entity on account of the common control test results.
        • Entity enhancements to support common controls -- Learn about the entity enhancements of the downstream inherited controls in the GRC application. For example, you can see information about the downstream inherited controls by looking at the entity record page. You can also see a summary of the downstream inherited controls by using a widget that is available on the entity overview page.
      • Group assessments for similar assessments -- Provide response to similar assessments by grouping the assessments based on metric type, and additionally the same entity, control objective, or category in the Tasks page of the Compliance Workspace.
      • Compliance score calculation of an entity -- There are two ways to calculate the compliance score of an entity. The existing method includes only the entity's direct controls, whereas the new logic considers the average of immediate downstream entities along with the average of direct controls of the entity.
      • Set up the steps required for entity compliance score calculation -- Enable the system property and run the on-demand job to calculate the compliance score of an entity based on its downstream entities' compliance scores and also its direct controls.
      • Determining the logic in calculating compliance score -- Determining the calculation of an entity's compliance score, either by its direct controls or based on its downstream entities and direct controls, is based on the Entity hierarchy based scoring property.
      • Manage control indicators using the Compliance Workspace -- Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.
      • Create a control indicator using the Compliance Workspace -- Indicator data for controls, risk, and audit evidence are measured differently depending on the GRC application.
      • Create a GRC indicator template using the Compliance Workspace -- Compliance or risk managers create indicator templates in the Compliance Workspace from which many indicators can be created.
      • Performance enhancements for Indicator nightly job -- To support parallel processing capabilities, two additional custom queues such as the Indicator Data Queue for processing indicators, and the Supporting Data Queue for handling events related to control, risk, and issue updates and to collect the supporting data, have been introduced.
      • Manage evidence requests using the Compliance Workspace -- Evidence request is used by audit and compliance teams for requesting supporting documents during an audit. Auditors and compliance teams require these documents from the first line of defense.
      • Request evidence during audits using the Compliance Workspace -- Request evidence at any stage during an audit using the Compliance Workspace. The details about the items for which evidence is requested are also provided to the person responsible for providing the evidence.
      • Provide requested evidence using the Compliance Workspace -- Using the Compliance Workspace, you can provide evidence when you are requested. When evidence is requested, the person who must provide the evidence receives an email. The process to provide the evidence begins.
      • Approve evidence before evidence review using the Compliance Workspace -- Using the Compliance Workspace, approve the evidence being provided before the requester views the evidence. When evidence is provided in response to an evidence request, the evidence may need an approval before the evidence is sent back to the requester. This ability ensures security and confidentiality of the evidence.
      • Accept, reject, or cancel an evidence request using the Compliance Workspace -- Accept, reject, or cancel an evidence request when you receive the evidence you requested. After requesting an evidence request using the Compliance Workspace, when the requester receives the evidence, the requester can accept, reject, or cancel the evidence request.
      • Review related evidence using the Compliance Workspace -- The Evidence Request feature includes a related list called Related Evidence that is not visible by default.
      • Control objective workflow -- The control objective workflow introduces a review and approval process for changes to control objective records, preventing unreviewed updates from immediately affecting downstream objects such as controls.
      • Enable the control objective workflow -- Enable the control objective workflow property to activate the review and approval process for changes to control objective records.
      • Create and publish a control objective -- Create a control objective and move it through the workflow states from Draft to Published.
      • Edit a published control objective -- Revise a published control objective by creating a staging record, drafting changes, and publishing them after approval.
      • Configure approval rules for control objective review -- Configure dynamic approval rules to define who must approve a control objective before it can be published.
      • View dashboards in Compliance Workspace -- Access Policy and Compliance Management dashboards directly from the Compliance Workspace without navigating to Platform Analytics application.
    • Policy authoring and redlining in Compliance Workspace -- Policies are effective when they’re carefully monitored and revised periodically. By reviewing and updating them at regular intervals, organizations can maintain updated policies to avoid audit and compliance risks.
    • Import policy text for redlining -- Import the policy text as an attachment if you’re unable to do the word editing.
    • Pre-requisites to enable policy redlining feature -- Certain configurations are required to be set up for policy collaborators to use the policy redlining feature in the Compliance Workspace.
    • Creating and associating policy texts from Cloud documents -- You can create and associate policy text for a policy record with any document that exist in Microsoft OneDrive, Google Drive, or in Microsoft SharePoint. You can sync the policy text and the document in cloud and get the latest version attached to the policy for publishing.
    • Sync document and view policy text -- Update the document and view the content in the Policy text field.
    • Provide document access to policy users -- Grant access to the users who have assigned roles to collaborate on the redlining-enabled policy.
    • Complete publishing checklist and request policy approval -- Use the playbook available with Compliance Workspace to complete the publishing checklist before you request approval. If approvals are complete, then the policy is automatically published.
    • View the history of a redlining-enabled policy -- Use the policy history related list to track the modifications made to the policy document.
    • Set up dynamic approval configuration on a policy record -- A policy is a set of guidelines and rules established by a business organization to govern its operations. Creating an approval configuration record for a policy enables you to define one or more approval levels and approval rules based on various dynamic conditions.
    • Policy dynamic approval setup -- Set up dynamic approval configuration on a policy. Based on the configured approval levels, the Policy and Compliance Management application configures one or more approval rules on the policy record.
    • Policy dynamic approval setup with redlining -- Set up dynamic approval configuration on a policy for which redlining is enabled.
    • 360° Relationship Visualization for Policy and Compliance Management -- When you launch the 360° view from a particular compliance record, you can instantly explore the relationship between the selected record and all its associated objects in a distinctive visualization.
    • Policy as Code Engine for Preventive compliance management -- Compliance managers can map the control objective with the Policy as Code Engine (PaCE). PaCE calls GRC passing the document reference and the PaCE policy for which exceptions need to be determined. Control owners can view the PaCE logs to understand the compliance or non-compliance instances.
    • Configure compliance data source registry -- Set up the Compliance Data Source Registry (CDSR) that provides the ability to associate policies in other ServiceNow products with control objectives in Policy and Compliance to inform an organization’s overall compliance stand, and to perform policy exceptions when required.
    • Map PaCE policy to a control objective -- Use the Policy as Code Engine (PaCE) policy related list in the Compliance Workspace to map the control objective with a PaCE policy. Compliance managers have the ability to map the control objectives with PaCE policies.
    • GRC: Policy and Compliance integrator -- The GRC: Policy and Compliance integrator application provides a common framework so that your content providers can push their content into the GRC applications. The application also enables you to review, approve, and import the data into the Policy and Compliance Management tables.
    • Workflow for GRC: Policy and Compliance integrator -- You can install the GRC: Policy and Compliance integrator application from the ServiceNow Store and execute the workflow to complete the data import process.
    • Use Policy and Compliance integrator -- You can use the GRC: Policy and Compliance integrator application module to display the details of the batch records and to import tasks. For example, you can see the content integration batch records, library import tasks, staging records, and recommendations for the records.
    • Manage content integration batch records -- You can access the batch records in the content integration batch table that is displayed in the GRC: Policy and Compliance integrator application UI. By accessing these records, you can import the data into the Policy and Compliance Management application.
    • Assign library import task -- Assign a library import task to the compliance managers assignment group by using the library import task form in the GRC: Policy and Compliance integrator application.
    • Approve library import task -- Approve the library import task by using the Library import task form in the GRC: Policy and Compliance integrator application.
    • DevOps Accelerator plugin -- GRC: DevOps Accelerator is an application that enables your customers to evaluate the compliance for DevOps policies and GRC control objectives integrating with Policy as a Code Engine (PaCE).
    • Manage continuous monitoring for controls between Configuration Compliance and Policy and Compliance Management -- Continuous monitoring for controls is a feature integration between the GRC: Policy and Compliance Management product and the Security Operations Configuration Compliance products. This feature integrates the scan results from third-party applications, like Qualys to determine the compliance status for each associated control.
    • Map control objective or controls to configuration tests -- Continuous monitoring for controls is a feature integration between the GRC: Policy and Compliance Management product and the Security Operations Configuration Compliance products. This feature integrates the scan results from third-party applications, like Qualys to determine the compliance status for each associated control.
    • Interpret configuration compliance scan results -- Continuous monitoring for controls is a feature integration between the GRC: Policy and Compliance Management product and the Security Operations Configuration Compliance products. This feature integrates the scan results from third-party applications, like Qualys to determine the compliance status for each associated control.
    • Managing mobile experience for GRC Policy and Compliance -- As a policy and compliance manager, use your Android or iOS mobile device to manage your work.
    • Setup checklist for the GRC Mobile application -- The following checklist includes the set up tasks that you are required to complete in your ServiceNow AI Platform instance and on your mobile device prior to using the GRC Mobile application. Complete these set up tasks prior to using the GRC Mobile application to view the Policy and Compliance Management application on your mobile device.
    • Log in to the GRC Mobile application -- Open the GRC Mobile application and add a ServiceNow AI Platform instance with Policy and Compliance Management to your mobile device.
    • Process pending Policy and Compliance Management approval requests with the GRC Mobile application -- Approve or reject pending policy approval requests that are submitted to you.
    • Process pending approvals for Policy exceptions with the GRC Mobile application -- Approve or reject pending policy exceptions and policy exception extension requests that are assigned to you.
    • Assign Policy and Compliance Management indicator tasks with the GRC Mobile application -- Assign unassigned Policy and Compliance Management indicator tasks to a member of your assignment group. An indicator task is related to a Control record that is assigned to your compliance group.
    • Assign Policy and Compliance Management issues with the GRC Mobile application -- Assign unassigned Policy and Compliance Management issues to a member of your assignment group. Navigate through the record to view more details about the Control Objective, the Control record, and Remediation Tasks associated with an issue.
    • Assign Policy and Compliance Management remediation tasks with the GRC Mobile application -- Assign an unassigned remediation task to a member of your group. Edit the fields including the Extend by days field. Navigate through the record to view more details about the Control Objective, the Control record, and the Issues associated with a Remediation Task.
    • Reassign overdue Policy and Compliance Management attestations with the GRC Mobile application -- Reassign overdue attestations to a member of your assignment group.
    • Reassign overdue Policy and Compliance Management issues with the GRC Mobile application -- Reassign overdue issues that are assigned to your assignment group. Navigate through the record to view more details about the Control Objective, the Control record, and Remediation Tasks that are associated with an overdue issue.
    • Filter records with the GRC Mobile application -- Set additional filters to limit the number of records that are displayed on a screen. Filtering records in the mobile app works like filtering with a condition builder on the ServiceNow AI Platform.
    • Policy and Compliance Management reference -- Reference topics provide information about tables, roles, and properties installed with the GRC: Policy and Compliance Management application.
    • Components installed with Policy and Compliance Management -- Reference topics provide additional information about components that are installed with the activation of the Policy and Compliance Management plugin. These components include tables, user roles, and properties.
    • Domain separation in GRC: Policy and Compliance Management -- Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Analytics and Reporting solutions for GRC: Policy and Compliance Management -- Platform Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.
    • Compliance Overview Performance Analytics dashboard -- The Compliance Overview dashboard provides an executive view into compliance requirements, overall compliance, and compliance breakdowns so areas of concern can be identified quickly.
    • Policy Overview Performance Analytics dashboard -- Policies Overview dashboard provides an executive view into compliance requirements, overall compliance, and compliance breakdowns so areas of concern can be identified quickly. Users with the compliance administrator and compliance manager roles view the Policies Overview dashboard.
    • Policy Exception Overview Performance Analytics dashboard -- The Policy Exception Overview Performance Analytics dashboard provides views into the number, severity, and source of policy exceptions. It also shows exempted controls.
    • Policy Acknowledgement dashboard -- The Policy Acknowledgement dashboard gives you the acknowledgement status of the policies. It includes count of policy acknowledgements that have been accepted, declined, pending, past the due date of acknowledgement, exemptions requested, and those that are exempted.
    • My Attestation Overview dashboard -- The Assessment Overview dashboard displays various assessment reports, such as Assessable Records by Type, Total Metrics by Metric Type, and Assessments by State. You can now view the dashboard in the Next Experience UI Framework.
    • NIST Cybersecurity Framework Overview dashboard -- NIST Cybersecurity Framework Overview dashboard contains a variety of reports displayed on different dashboards, available within each of the sections in the NIST CSF process.
    • NIST Framework Profiling Overview dashboard -- NIST Framework Profiling Overview dashboard contains reports within each of the sections in the NIST RMF process: Categorize, Select, Implement, Assess, Authorize, and Monitor. You can view these reports in the Next Experience UI Framework.
    • Application Risk and Compliance Overview dashboard -- The Application Risk and Compliance Overview dashboard provides the current view of risk and compliance posture for the business applications that are used in an enterprise. You can now view the dashboard in Next Experience UI Framework.
  • Privacy Management -- Use the Governance, Risk, and Compliance: Privacy Management application to help protect your customers, employees, and suppliers with integrated data privacy risk and compliance management solutions and privacy by design concepts​.
    • Explore -- The ServiceNow Privacy Management application enables you to manage your company’s privacy programs. Some examples of privacy programs are privacy regulatory compliance programs, privacy impact assessments, privacy policy management, and so on.
    • Processing activities -- A processing activity is a record that processes personal data. Examples of such records can be a business process or a business application of an organization that has personal information. Processing activities enable the privacy management teams to understand how personal information is being processed or used.
      • Understanding Processing activity hierarchy -- Track how personal data flows across vendors, applications, and systems within and beyond a processing activity to identify and mitigate privacy-related risks.
      • Hierarchy tab -- The Hierarchy tab connects your processing activity to applications, vendors, companies, entities, business processes, and other activities. It builds a clear picture of how data moves through your organization.
    • Classic assessments -- Privacy assessments are used to collect information from business owners. This information helps the privacy teams to understand how personal information (PI) is being used or stored in a processing activity.
    • Smart assessments -- The new and improved assessment experience in Privacy Management uses the Smart Assessment Engine (SAE) application. The assessment engine enables you to perform privacy screening and privacy impact assessments to collect the necessary information for the privacy teams.
    • Risk assessments -- You can perform risk assessments on your processing activities to determine their risk scores and find out the privacy risk posture of your organization.
      • Risk Assessment Methodology (RAM) -- Risk Assessment Methodology (RAM) provides a systematic and repeatable approach to identifying, evaluating, and mitigating privacy risks associated with data processing activities.
      • Privacy assessment configurations -- To perform a processing activity criticality and privacy risk assessment, two risk assessment methodologies (RAMs) are provided by default.
    • Information objects -- The purpose of an information object is to logically describe the type of data that is exchanged between an application and a database.
    • Privacy Workspace for the privacy manager -- The Privacy management dashboard provides a centralized interface for monitoring and managing privacy-related data processing activities within the organization.
      • Processing activity tab -- The Processing activity tab on the Privacy management dashboard provides a comprehensive and real-time overview of all data processing activities across the organization.
      • Risk and compliance tab -- The Risk and compliance tab on the privacy management dashboard provides a centralized view of privacy-related risk exposure and regulatory compliance performance.
      • Operations tab -- The Operations tab on the privacy management dashboard offers visibility into operational performance across key privacy compliance processes, supporting proactive management and confirming adherence to regulatory and internal risk standards.
      • Privacy cases tab -- The Privacy cases tab on the privacy management dashboard serves as a centralized interface for monitoring, analyzing, and managing privacy-related incidents and requests within an organization.
    • Privacy Workspace for the privacy analyst -- Privacy analysts manage the privacy compliance posture of the processing activity owned by them. Compliance posture refers to the overall compliance status of an organization, business process, or business application, and so on based on the compliant and non-compliant status of controls across various regulations.
    • Privacy Management solution -- The Privacy Management solution provides you with a framework to manage your privacy-specific libraries such as citations, policies, control objectives, risk statements, privacy impact assessments, and privacy risk assessments. It also provides processing activity records to track privacy risk and compliance posture.
    • Data subject types -- Data subjects are individuals whose personal data is collected, used, and processed by an organization. Data subject classification enables organizations to define and manage distinct groups, enabling a granular and context-specific representation of data processing activities.
    • Configure -- Follow the order of the tasks given here to configure Privacy Management. These tasks will help you manage your privacy program effectively.
    • Download application -- Before you run GRC: Privacy Management (sn_privacy) in your instance, you must download it from the ServiceNow Store.
    • Manage information objects -- The Privacy Management library consists of authority documents, citations, control objectives, policies, and [PI] Information objects that help to manage the privacy content.
      • Create -- Create information objects manually to associate the right data subject types with business processes or applications.
      • Configure categories -- Configure information object categories to classify information objects effectively. For example, attributes like iris scans and fingerprints are often referred to as biometric data, or email addresses and phone numbers can be grouped as contact information. Information object categories enable you to categorize these information objects under these broader classifications.
      • Classify as personal information -- Categorize information objects as personal information. Only information objects classified as personal information can be associated with the processing activities.
    • Configure smart assessment templates for screening assessments -- Create a privacy assessment template using the Smart Assessment Engine as a base for sending screening assessments and use it to detect the privacy risks and mitigate those risks.
    • Configure smart assessment templates for impact assessments -- Create privacy assessment templates using the Smart Assessment Engine as a base for sending privacy impact assessments and using them to detect the privacy risks and mitigate those risks.
    • Create a privacy assessment -- Create various types of assessments and send those assessments to the business process or business application owners to collect their responses. The responses help you to understand how personal information (PI) is being used or stored in a processing activity.
      • Write a processing activity script -- Write custom scripts on the assessment templates to update the processing activity fields using a script. The script runs when the assessment response is completed. You can write multiple scripts for both screening assessments and impact assessments.
      • Map a control objective to a question response -- Map the control objectives to the responses of the assessment questions to automatically create and apply the respective controls on the processing activity.
      • Map an information object to a question response -- Map the [PI] Information objects to the responses of the assessment questions that must be associated to the processing activity. This association helps the privacy teams to understand what personal information is being processed by the processing activity.
      • Map a risk statement to a question response -- Map the risk statements to the responses of the assessment questions to automatically create and apply the respective risks on the processing activity.
      • Map the processing activity fields to a question response -- Map some of the processing activity fields with the responses of the assessment questions to update the processing activity details based on the assessment response.
    • Create and validate an assessment configuration -- Create your assessment configurations to determine when a processing activity must be automatically created.
    • Update a privacy assessment template -- Publish a new version of a smart assessment template to revise its questionnaire, response options, or automations. Each version maintains a change history of templates used in privacy screening, impact, and breach assessments.
    • Map a table with a processing activity -- Keep your processing activity updated and in sync with any table in ServiceNow by mapping the entity fields with the processing activity.
    • Use -- As a privacy analyst or a privacy manager, you can identify which business applications or processes store and use personal information.
    • Entity scoping to plan a privacy program -- When a privacy manager plans the privacy program for an organization, the first step is to scope those business applications or processes that contain personal data. In Governance, Risk, and Compliance, these business applications or business processes are called as entities. After you identify the entities processing personal data, the processing activities are automatically created.
    • Types of privacy assessments -- Privacy assessments can be sent using various methods such as entities, entity types, and processing activities.
      • Initiating privacy assessments -- To discover whether a business process or an application is processing personal data, you can use privacy screening assessments. To regularly assess how processing activities are processing personal data, you can use privacy assessments such as privacy impact assessment (PIA).
      • Send a privacy assessment from an entity -- Send a privacy assessment to an entity owner to determine if there's personal data involved in the processing activities.
      • Send a privacy assessment to multiple entities -- Send the privacy screening assessment or the Privacy impact assessment (PIA) assessments to multiple entities to understand why and how personal data is being processed.
      • Send a privacy assessment from a processing activity -- Send a privacy assessment to a processing activity owner from a processing activity record to collect more information on why and how the processing activity is using personal information.
      • Send privacy assessments from multiple processing activities -- Send multiple privacy assessments from multiple processing activities. This capability enables you to filter the processing activities by business units, locations, data subjects, and data types.
    • Create a Risk Assessment Methodology -- Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.
    • Respond to a smart assessment -- Respond to either a screening assessment or an impact assessment from the Assessment Workspace. The assessment results help to understand the potential privacy risks and their mitigation measures.
    • Respond to a screening assessment -- As an entity owner or a processing activity key stakeholder, respond to the privacy assessment that is initiated by the privacy lead.
    • Review a privacy assessment -- As a privacy analyst, review a privacy assessment after the responders submit the assessment. You can either close the assessment after a review or you can also request for revision if you determine that the assessment requires more information.
    • Create or update a processing activity -- Manually create a processing activity or update a processing activity that is automatically created out of a privacy screening assessment. You can also update a processing activity that is created from an entity record. When you update a processing activity, you can fill in the relevant details about the personal data that is being processed.
    • Create or manage an information object -- Add information objects to the processing activity after a processing activity is created. Adding information objects helps you understand the types of personal information that is being processed and the way it is processed. This task helps in applying the appropriate controls to the processing activity.
      • Modify an information object -- Add details such as justification for storing data to an information object after you add it to the processing activity. Adding details enables you to define how the personal data is being processed.
    • Add data subject type to a processing activity -- Add data subject types to a processing activity in the Privacy Workspace.
    • Add data subject type to privacy impact assessment -- Add data subject types to privacy impact assessment from the Employee Center.
    • Classify data subject type as vulnerable -- Classify a data subject type as vulnerable. When you mark a data subject type as vulnerable, the criticality score is calculated as High.
    • Add key stakeholders to a processing activity -- Add key stakeholders to a processing activity. Based on their role, users are assigned default processing activity privileges that control whether they can edit a processing activity, view it, or respond to its privacy assessments.
    • Enable key stakeholders to update processing activities directly -- Enable stakeholders to update processing activities directly from the Employee Center by assigning the activity to them.
    • Edit processing activity from Employee Center -- Access a processing activity directly from the Employee Center and request edit access to update the details your team is responsible for.
    • Add a regulatory agency -- Add a regulatory agency in the Privacy Workspace to identify the relevant regulatory authorities that are responsible for overseeing the industries or sectors within each jurisdiction. The jurisdictions consolidate all the regulatory communications via emails and implement the notification rules for data privacy or security breaches for the reported privacy cases.
      • Regulatory agency form -- Use the Create Regulatory Agency form in the Privacy Workspace to create a regulatory agency. The regulatory agency is a new record type that handles regulatory changes.
    • Create a lineage for a processing activity -- Establish a lineage to visualize data consumption, sharing, and the associated risks for a processing activity. Each processing activity involves multiple information objects classified as personal information. These objects exchange data with various other entities, making it essential to establish a lineage or hierarchy that tracks where personal data is shared.
      • Edit a lineage -- Edit an existing lineage relationship to update the relationship type, description, or key relationship status of a connected node.
      • Delete a lineage -- Delete a lineage to remove a specific connection or node from the hierarchy of a processing activity.
      • Update maximum node level -- Update the sn_privacy.nodemap.maxLevel system property to control how many node levels are visible on the lineage map.
    • Create or manage a control on a processing activity -- Add new controls or manage the controls that are automatically added to the processing activity from the assessment responses. Adding controls ensures that the appropriate regulations are applied to the processing activity.
    • Delete a control from a processing activity -- Delete the controls that are no longer required in the processing activity.
    • Create or manage risks on a processing activity -- Add new risks or manage the risks that are automatically added to the processing activity from the assessment responses. Adding risks helps you manage processing activities using the risk-based approach.
    • Manage chat collaborations of a processing activity -- Initiate quick discussions with key stakeholders while working on a processing activity, privacy case, or a personal data rights request. The chat feature is integrated with Microsoft Teams and a group is automatically created on Microsoft Teams when a discussion is initiated.
    • Create or add issues on a processing activity -- Create issues or add existing issues for a processing activity. Associating issues to a processing activity helps you to identify and prioritize remediation actions. Relating issues reduces the number of issues customers need to manage, thus improving the overall organizational efficiency in management of these issues.​
    • Access control by legal entity -- Access to processing activity records can be restricted by using Entity-Based Access (EBA).
      • Configuring access control -- Configurie Entity-based access control in Privacy Management, including property activation, hierarchy setup, record mapping, user assignment, bulk updates, and activating entity-based record access rules.
      • Entity-based access configuration -- Configure entity-based access by installing the Entity-based Access Configurations plugin and enabling properties for record types.
      • Create an entity configuration -- Create an organizational structure by configuring entity-based access for different levels such as headquarters, regional offices, and subsidiaries. Define access rules for users and groups.
      • Add hierarchical relationships -- Define hierarchical relationships between entities (Global → Regional → Country-level) using Upstream and Downstream options. Adding an hierarchy creates a clear organizational structure.
      • Set access restrictions using an entity based record access update utility -- Set access restrictions for the existing records in bulk by using the Entity based record access update utility guided-experience. Use the workflow to enable or disable access to record types.
      • Set Entity-based record access rules -- Use entity-based record access rules to secure records and enable continuous monitoring. These rules automatically apply restrictions to new or modified records, ensuring access settings stay enforced without manual updates. When entities or processing activities change, the system updates access controls automatically.
    • Integrate Employee Center and Risk portal -- The integration of Employee Center with Privacy Management provides all employees and users a simplified user experience to perform tasks such as submitting a privacy impact assessment for a new implementation, responding to control attestations, and accessing processing activities and privacy impact assessments.
    • Privacy Case Management -- The Governance, Risk, and Compliance: Privacy Case Management application enables you to report and manage privacy violations and complaints. The solution allows for the swift and efficient management of privacy breaches and complaints through collaboration with various teams which help in investigating the root cause and key details of the breach reported.
    • Explore -- The Governance, Risk, and Compliance: Privacy Case Management application enables users to report any privacy breaches or complaints, collaborate with key stakeholders, perform breach investigations, and analyse the causes and consequences of breaches.
      • Home page -- The Privacy Case Management application home page offers the privacy case manager an overview of processing activities, risk and compliance information, operations details, and all your privacy case-related information.
      • Overview page -- The Privacy case overview page shows details, such as description, state, schedule and milestones, case tasks, and issues related to the case in the Privacy Case Management application.
      • Workflow -- The Privacy Case Management solution provides you a framework to manage any privacy breaches reported by the users. The solution provides an end-to-end workflow for the privacy team to triage the reported breach and perform the required investigation and analysis, gather evidence, record the key stakeholders, impacted areas, and regulatory violations, if any.
      • Smart assessments -- Utilize the Smart Assessment Engine to perform smart assessments on privacy case action tasks.
      • Privacy breach assessments -- Privacy breach assessments play an important role whenever there is an incident that threatens the privacy of individuals. These assessments help to determine if there is a breach and then serve as a measure to gauge the extent and impact of a breach.
      • Overview page of a breach assessment -- After a breach assessment is completed, the overview page of the assessment displays the summary of the relevant and critical information for the privacy analyst to review.
      • States of a privacy breach assessment -- After a privacy analyst initiates a privacy breach assessment, the assigned reviewer contributes their insights and includes the personally identifiable information (PI) artifacts and relevant jurisdictions before it is completed and closed.
      • Elements of a privacy breach assessment -- A privacy breach assessment must clearly indicate the jurisdiction in which the breach occurred. This is crucial because each jurisdiction operates under distinct laws and regulations pertaining to privacy and data protection. It must also specify the personally identifiable information (PI) artifacts.
    • Configure -- Follow the order of the tasks given here to configure Privacy Case Management application. These tasks help you to manage the compliance cases effectively.
      • Install -- You can install the Privacy Case Management application (sn_privacy_case) if you have the admin role.If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
      • Create a view rule -- Create view rules to define the form view of the privacy cases in the Privacy Workspace. Specifying the rules helps you to control how the privacy case form appears.
      • View rule form -- Learn about the fields on the view rule form. Use this form to define workspace and default view rules in the Privacy Case Management application.
      • Create an assignment rule -- Specify the conditions for assigning a privacy case to a particular user or group by creating assignment rules.
      • Assignment rule form -- Learn about the fields on the assignment rule form. Use this form to define case assignment rules in the Privacy Case Management application.
      • Create state model transition -- Create state models to control the workflow of a privacy case by defining the states and transition conditions.
      • Define the workflow states for a privacy case -- Define the workflow states for a privacy case that govern the lifecycle of the case.
      • Define model state transitions -- Define the transition conditions to control how a compliance case traverses through the different workflow states by using the Privacy Case Management application.
      • GRC model state transition condition form -- Use the GRC Model State Transition Condition form to define the transition conditions to control how a compliance case traverses through the different workflow states by using the Privacy Case Management application.
      • Create a privacy case assessment template -- Create an assessment and send those assessments to the privacy case task owners to collect their responses. The responses help the privacy case analysts to determine the breaches that have occurred due to the privacy case.
      • Assessment metric type form -- Use the Assessment Metric Type form to create an assessment questionnaire template instead of using the default template.
      • Configure inbound email to enable privacy case creation -- Set up a designated email address that employees can use to report privacy cases through email.
      • Configure Record Type Area -- The Record Type Area Configuration feature allows privacy case managers or analysts to add additional relevant business area types in impacted and related areas.
    • Configure privacy breach assessment -- Follow the order of the steps such as creating breach factor types, breach factors, PI data element types, and PI data elements to configure privacy breach assessment.
      • Create a breach factor type -- Create categories to help responders to identify breach factors within specific categories. For example, incident nature is a breach factor type which has factors under it as Intentional and Malicious, or Intentional and not malicious, and Unintentional or inadvertent.
      • Create breach factors -- Create breach factors to help privacy teams understand the characteristics of a breach and evaluate the related risks. Exercise your flexibility to either use the default breach factors or generate new ones. Additionally, link breach factors to specific regions or implement them universally across multiple regions or selected ones.
      • Create a PI data element type -- Create categories to help responders to identify personal data elements within specific categories. For example, for a PI data element type such as Personal information, the PI data elements can be Name, Age, Employer ID, Marital Status, Email, and so on.
      • Create PI data elements -- Create PI data elements based on residents' personal information collected during the business process, such as phone numbers and email IDs. Use pre-configured elements or create new ones. Customize for data elements for specific regions or map a single PI data element to multiple regions.
      • Create a region -- Create geographic regions based on the data of the residents that is collected as a part of your business operations. Examples of regions are America, Europe, Asia Pacific, and so on.
      • Create a jurisdiction -- Create jurisdictions for regions for data breach notification obligations as each obligation is broken down by jurisdiction. Jurisdiction can be created two levels below a region.
    • Use -- You can use the Privacy Case Management application to report privacy cases and manage the lifecycle of a privacy case.
      • Report a privacy case -- Any user can report a privacy case or an event that needs the attention of the privacy team.
      • Report a privacy case from the Employee Center -- Use the Employee Center to report any privacy breaches and complaints directly to the privacy teams. Reporting these cases helps to reduce and avert losses.
      • Create a privacy case in the Privacy Workspace -- Report any privacy breaches and complaints to help reduce and avert losses.
      • Report a privacy case through email -- Identify and manage issues related to the impacted areas for the reported privacy case. You can also create issues from the Privacy Case Management landing page.
      • Report a privacy case anonymously -- Use the Anonymous Reporting Center (ARC) to submit any suspected or confirmed privacy case without disclosing your identity.
        • Anonymous privacy case form fields -- The fields in the Report a privacy case form capture information about the suspected or confirmed privacy issue while keeping the reporter's identity confidential.
      • Initiate a breach assessment from a case -- Initiate a breach assessment from a privacy case to capture the details of breach, the type of data that is impacted, and so on. These details help the privacy analyst to identify if the breach must be notified to a regulator.
      • Work on a privacy breach assessment -- Accept the work of assessing a privacy breach assessment and work on the assessment.
      • Case task workflow -- Case tasks help you to collaborate with multiple teams to investigate, perform impact assessment to establish case criticality, and gather evidence to capture the details and responses for further review.
      • Create a case task -- Create case tasks to work on the various tasks such as investigations, assessments, inquiries, gathering evidence, and so on required to analyze and work on the case that has been reported. Each case can have multiple case tasks that can be assigned to different owners from various teams.
      • Work on a case task -- As a case task owner, accept the task, provide the details requested by the case analyst, and submit it for a review. If a case task is assigned to an assignment group, and not to a specific user, then any user who is a part of the assignment group can accept the task and work on it.
      • Add an impacted area to a privacy case -- Add the impacted areas or objects that are affected by the privacy case or event in the Privacy Case Management application.
      • Add PI information objects to a privacy case -- To identify the types of personal data compromised during a breach, add [PI] information objects to a privacy case.
      • Add key stakeholders to a privacy case -- Add key stakeholders to a privacy case to identify the key members who are responsible for the data that is lost during the breach. You can then send the respective breach assessments to the stakeholders based on their responsibilities.
      • Add a related area to a privacy case -- Add the related areas that are related to a privacy case or event reported in the Privacy Case Management application.
      • Add causes and consequences to a privacy case -- Define the root cause for the reported privacy case or event and its consequences on the organization using the Privacy Case Management application.
      • Cause and consequence form -- Learn about the fields on the cause and consequence form. Use this form to define cause and consequence in the Privacy Case Management application.
      • Add a privacy regulation related to a case -- Add the necessary regulations that are or can be impacted by the case that has been reported. In the ServiceNow platform, regulations are captured as authority documents. Adding the regulations to the case enables you to identify which regulations are breached or violated and prevents penalties and fines.
      • Add or create an issue for a privacy case -- Identify and manage issues related to the impacted areas for the reported privacy case. You can also create issues from the Privacy Case Management landing page.
      • Export a privacy case as a PDF -- Export a privacy case as a PDF to easily share it with various stakeholders.
      • Send an email from a privacy case -- Send emails from a privacy case to seamlessly communicate with various stakeholders and regulators and gather more information about the case. All the emails sent and received are stored in the Privacy Case Management application.
      • Perform smart assessment on privacy action task -- Use the Tasks page on the Employee Center for a consolidated view of all your privacy tasks, including all assessments, enabling you to access and complete them efficiently.
    • Integrate for RadarFirst -- RadarFirst specializes in privacy and incident response solutions, particularly in the context of data breach incidents. RadarFirst helps organizations manage and respond to data breaches and privacy incidents effectively.
    • Reference -- Reference topics provide additional information about the Privacy Case Management application including tables.
    • Personal Data Rights (PDR) -- The GRC: Personal Data Rights application enables you to exercise control over your personal data.
    • Explore -- Personal data rights (PDR) refer to the legal rights individuals have regarding the collection, use, storage, and protection of their personal data.
      • Workflow -- A personal data rights request is initiated by a requester and directed to the Personal data rights (PDR) agent. The agent then processes the request, assigns it to the appropriate task owners, the task owners work on their tasks, and then request is closed.
      • Workspace -- The Personal Data Rights Workspace offers you the ability to create new personal data rights request and view the requests by their type, due date, and status.
      • PDR external-facing form -- The Personal Data Rights (PDR) external-facing form enables secure submission of Data Subject Requests (DSRs) from a public website, without logging in. The form is customizable, supports jurisdiction-based privacy rights, and verifies requester identity via email before creating a case.
      • PDR fulfillment workflow -- After a requester successfully submits a privacy request and completes email verification, the request is routed to a Personal Data Rights (PDR) agent. The agent assigns action tasks to internal owners, reviews all completed tasks, closes the request, and notifies the requester by email with relevant details.
    • Configure -- Set up the Personal Data Rights to address various types of data rights request.
      • Configure request type -- Create a request type in the Personal Data Rights application to categorize and manage the personal data rights requests. After you create a request type, the personal data rights agents and the task owners can select the required request type on the request form while working on a personal data rights request.
      • Personal Data Rights request type form -- Use the Request Type form in the Personal Data Rights application to categorize the personal data rights requests by their type.
      • Configure request types and map jurisdictions -- Configure new privacy request types by adding a request type with relevant details, and then map it to a specific jurisdiction.
      • Create an action task template -- Create action task templates accessible to personal data rights administrators to align with various request types, such as the right to correct, delete, know, or opt-out. Using these templates for auto-generated action tasks ensures that each task meets the specific requirements of the request type. This alignment guarantees consistency, compliance, and efficiency in handling personal data rights requests.
      • Create a data registry -- Create a repository of the users and specify the owners of various applications. This repository helps to identify which user must be assigned the personal data rights (PDR) request tasks.
      • Generate action tasks for a request -- Automatically create action tasks for a personal data rights request. These action tasks are generated based on the data registry that is created by the personal data rights admin and are assigned to the right data owners.
      • Configure external-facing PDR form -- Privacy teams can tailor the external-facing Personal Data Rights (PDR) form per jurisdiction and data subject type. This customization allows them to control location specific content, authorized agent submission, and the available request types.
      • Create form configuration record -- Create the parent external form configuration record that anchors all location, data subject type, and request type rules for the external-facing Personal Data Rights (PDR) form.
        • New form configuration fields -- An external facing Personal Data Rights (PDR) form configuration record holds the form-wide content that the requester sees across regions.
      • Configure jurisdiction -- Configure the jurisdictions, authorized agent option, and per-location URLs for the external-facing Personal Data Rights (PDR) form. These settings determine what requesters in each jurisdiction see based on their local privacy rules.
        • New jurisdiction configuration form -- Populate a new location configuration record. Field choices determine whether requesters in the mapped jurisdictions see authorized agent paths, what URLs the form links to, and what introductory text appears at the start of the Personal Data Rights (PDR) form.
      • Map data subjects to jurisdiction -- Specify which data subject types the external-facing Personal Data Rights (PDR) form offers in each location, so the form presents only the data subject types that local regulation supports.
      • Map request types to data subjects -- Configure the request types available to each data subject type within a jurisdiction. Hide any requester or agent fields that don't apply on the external-facing Personal Data Rights (PDR) form.
    • Use -- Use the Personal Data Rights application to create new requests to manage your personal data.
      • Submit request using external-facing PDR form -- Submit a privacy request through your organization's external-facing Personal Data Rights (PDR) form, either for yourself or as an authorized agent acting on behalf of someone.
      • External-facing PDR form fields -- Use the field descriptions as reference when you fill the external-facing Personal Data Rights (PDR) form.
      • Create request from PDR Workspace -- Create a request regarding your personal data to request access to, correction of, or deletion of personal information held by an organization or entity.
      • Personal data rights request form -- Use the Personal data rights request form in the Personal Data Rights application to initiate a process to access, correct, or delete personal data.
      • Add action tasks to a request -- Create action tasks for a Personal Data Rights request and assign them to the appropriate task owners. Action tasks are tasks that are created to facilitate and complete a valid personal data rights request
      • New action task form -- Use the new action task form to create action tasks for the appropriate owners.
      • Accept and work -- Accept Personal Data Rights (PDR) tasks that are assigned to you. Unless you accept the work, you will not be able to work towards closing the task.
      • Modify email templates -- You can modify the email templates to align the messages with your organization’s branding, or to add disclaimers required by regional regulations.
    • Now Assist for Privacy Management -- Now Assist for Privacy Management is a GenAI‑powered capability that streamlines privacy workflows by summarizing risk assessments, condensing issue details, and identifying redundant control objectives for rationalization into a common control objective.
    • Install Now Assist for Privacy Management -- Install Now Assist for Privacy Management.
    • Use Risk assessment summarization skill to generate summary -- Use Risk assessment summarization skill to generate a risk assessment summary that is based on inherent risks, residual risks, target risks, and control effectiveness data. Your approvers get the key insights to understand the context quickly, and you can reduce the time involved in creating summaries manually.
    • Summarize an issue -- Use Issue summarization skill to summarize an issue, and obtain a quick context and awareness about an issue.
    • Use Recommendation of similar control objectives skill to generate suggestions -- The "Recommendation of similar control objectives" skill generates recommendations by identifying, deduplicating, and rationalizing similar control objectives within the compliance library. This enables identification of redundant control objectives, making it easier to maintain a clean and efficient compliance library.
      • Act on the recommendations -- Act on the recommendations, like accept as duplicate, retain as primary, or dismiss, to enable your compliance managers and analysts to streamline their processes by identifying, deduplicating, and rationalizing similar control objectives within the compliance library.
      • Review rationalization process -- After acting on the recommendations, the owner sends it for review to the configured reviewers. The reviewers then analyze the actions taken and either approve or reject them, providing proper justification for their decisions.
    • Case summarization for privacy cases -- The GRC case summarization skill uses a large language model (LLM) to generate a structured AI summary of a privacy case record. The summary is generated on demand from case data and can be saved to the record for future reference.
      • Summarize a privacy case -- Use the GRC case summarization skill to generate an AI summary of a privacy case. The summary provides a consolidated view of the case life cycle, including breach-related assessment activity.
    • Privacy content accelerator -- The privacy content accelerator provides prebuilt privacy content that you can activate directly from the Privacy Workspace.
    • Activate privacy content -- Activate an authority document or risk statement version to install the associated citations, control objectives, or risk statements into your privacy library.
    • Update content in the privacy library -- Update an installed authority document or risk statement version to add newer citations, control objectives, and risk statements to your privacy library.
    • Reporting -- The Privacy Management reports are available as overview pages in the various records.
    • Home page -- The Privacy Management home page provides an overview of the complete privacy risk and compliance posture with details, such as the processing activity criticality score, privacy risk assessment status, privacy impact assessment status, control attestations, issues-specific status, and privacy cases.
    • Processing activity overview page -- The processing activity overview page provides the privacy risk and compliance posture for a processing activity. This page contains details, such as compliance score, criticality score, risk posture and heatmap, privacy and risk assessment status, issues and policy exceptions, and control assurance status.
    • Reference -- Reference topics provide additional information such as tables, and roles that are installed with the Privacy Management application. These topics also provide supporting information.
    • Tables installed -- Tables are added with activation of GRC: Privacy Management.
    • Roles installed -- The GRC: Privacy Management application installs the roles for the privacy analyst, the privacy manager, and the privacy administrator to perform their respective tasks.
    • Roles and tables installed with PDR -- Reference topics provide additional information such as tables, and roles that are installed with the Personal Data Rights application. These topics also provide supporting information.
    • Email notifications -- Reminders enable relevant users to perform their assessments and complete the tasks associated with them.
    • Uses of a processing activity -- A processing activity is a record that processes personal data. Examples of such records are a business process or a business application of an organization. Processing activities enable the privacy management teams to understand how personal information is being processed or used.
      • Workflow -- A processing activity workflow helps the privacy analysts to manage the life cycle of a processing activity.
    • Domain separation -- This is an overview of domain separation and the Governance, Risk, and Compliance application Privacy Management. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
  • Regulatory Change Management -- The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application verifies the overall regulatory compliance for your organization.
    • Explore -- The Regulatory Change Management application provides a framework that your organization can use to integrate with third-party regulatory intelligence providers to keep up with the regulatory changes and external regulations.
    • RCM in the Compliance Workspace -- Starting with GRC: Regulatory Change Management, version 13.0.1, the Regulatory Change Management application is available in Compliance Workspace. Compliance Workspace provides your users with a single-pane view so that they can check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes for the organization.
    • Differences between regulatory event alert and source document alert -- A regulatory event alert informs you of a regulatory change, while a source document alert signals the release or update of the related official document.
    • Regulatory process flow and tasks -- The Regulatory Change Management process flow includes the tasks that different users can perform to help your organization manage and comply with regulatory changes.
      • Source document import tasks -- The Regulatory Change Management application processes external alerts that may include citation titles, citation numbers, and references to legislative or regulatory materials relevant to compliance.
      • Impact assessments for the regulatory alerts -- A regulatory event alert may result in a regulatory change to an organization. You can evaluate the impact of the regulatory change on your organization by performing impact assessments.
      • Regulatory assessment for a regulatory alert -- Utilize the Smart Assessment Engine to perform smart assessments on regulatory alerts. This ability enhances regulatory decision-making by enabling impact assessments directly at the regulatory alert level, streamlining processes through a unified core assessment framework, and assigning analysis to multiple stakeholders for improved collaboration and efficiency.
    • Next Experience Discuss and Chat Collaboration -- On a regulatory change management case, select Discuss from other options. Collaborate with virtual agents by using Next Experience Chat Collaboration and Discuss.
    • Now Assist in RCM -- With Now Assist in Regulatory Change Management, part of the Now Assist for Integrated Risk Management (IRM) application, you can use agentic workflows and generative AI skills that streamline the analysis, summarization, and impact assessment of regulatory alerts. These capabilities empower compliance teams to act swiftly and accurately on regulatory changes.
    • Configure -- Configure the Regulatory Change Management application to manage your compliance needs and integration with regulatory intelligence content providers.
    • Download and install -- Download the GRC: Regulatory Change Management application from the ServiceNow Store and run it in your ServiceNow instance.
    • Setup checklist -- Complete the tasks that are required to set up the Regulatory Change Management application. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance Regulatory Change Management application functionality.
    • Set up the RSS feeds infrastructure -- To ensure you can obtain all the necessary Really simple syndication (RSS) feeds in your ServiceNow instance, you must set up the infrastructure required to seamlessly obtain the feeds.
      • Activate and pull RSS feeds -- Use the Workflow Studio to pull RSS feeds from the defined RSS sources after you activate the workflow. Regular pulling of RSS feeds ensures that you to stay on top of all your regulatory compliance needs. By default, the schedule to pull the feeds runs daily.
      • Set up RSS feed sources -- Set up RSS feed sources to efficiently aggregate and monitor updates from multiple websites or content providers in one centralized location. This saves time, ensures you stay informed, and enables automated data retrieval.
      • Map the taxonomy -- Create an internal taxonomy when you are setting up the Regulatory Change Management application. Map the external taxonomy to the internal taxonomy so that the Regulatory Change Management application refers to only one taxonomy.
      • Configure a provider taxonomy configuration record -- Align the provider with the appropriate taxonomy profile to categorize regulatory intelligence data and feeds for informational reporting purposes. This approach is particularly useful when integrating multiple feed sources, as it ensures consistent naming conventions across systems or applications.
      • Manage feed request responses -- When the job to pull RSS feeds runs at the scheduled time, the responses are automatically fetched from the configured feed sources.
    • Admin module -- Use the Administration module to manage third-party providers and the configuration of entity classes.
    • Integrate -- Extend the capabilities of RCM.
    • Overview of RSS feeds -- A Really simple syndication (RSS) feed in Regulatory Change Management is like a subscription service for updates about new or changed rules and regulations. Instead of visiting multiple websites to check for updates, you can subscribe to feeds from regulatory bodies or industry news.
      • General guidelines -- When an RSS feed isn't working, common errors or issues often stem from improper formatting, server issues, or misconfiguration. An RCM administrator can remediate some of the common errors that users may encounter.
      • Overview of regulatory taxonomy -- Regulatory taxonomy simplifies identifying necessary changes in a customer’s regulatory library by enabling algorithms to match incoming regulatory intelligence to existing content using taxonomy terms.
    • Use -- You can use the classic environment to perform all Regulatory Change Management application activities.
    • Create an action task -- Create an action task that is related to the regulatory change tasks and source document import tasks so that you can complete the regulatory tasks.
    • Create an issue related to regulatory tasks -- Create an issue as part of the regulatory change tasks and source document tasks workflow to capture any problems or exceptions that are observed during the workflow. You can create and view issues related to regulatory tasks using the issues related list.
    • Regulatory Change Management Core UI -- The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application ensures overall regulatory compliance.
      • Regulatory alerts -- Regulatory alerts are an aggregation of different regulatory events and documents that are sourced from multiple regulatory intelligence providers. Similar to web feeds, a regulatory alert is a record of these regulatory changes. Such changes are frequently updated, and the alerts help you stay informed about the regulatory landscape.
      • Perform actions on regulatory alerts -- Perform various actions on unassigned and other types of regulatory alerts. For example, you can assign an unassigned alert, initiate impact assessment on an alert, and mark an alert as applicable, among other actions.
      • Add an AI-recommended citation to a regulatory alert -- Add an AI-recommended citation to a regulatory alert by using the GRC: Predictive Intelligence application.
      • Manage and assign regulatory event alerts -- Assign regulatory event alerts that are received from the regulatory intelligence provider to an appropriate user. You can review other properties of the regulatory event alert.
      • Train and use the similarity solution to recommend citations on regulatory alerts -- Train and use the machine learning solution by activating the Governance, Risk, and Compliance Predictive Intelligence plugin. The solution enables the system to automatically recommend correct citations on regulatory alerts to associate.
      • Manage and assign source document alerts -- Assign source document alerts that are received from the regulatory intelligence provider to an appropriate user. You can review other properties of the source document alert.
      • Regulatory change tasks -- When a manager or user marks an unassigned regulatory alert as applicable, a regulatory change task is created to analyze the impact of the regulatory change and coordinate the required compliance activities.
      • Users and associated actions for the regulatory change tasks -- Managers with the sn_grc_reg_change.manager role and the users with the sn_grc_reg_change.user role can view and perform certain tasks in the Regulatory Change Tasks module.
      • Manage the regulatory change tasks -- Manage the regulatory action tasks in the Regulatory Change Tasks module so that you can use these tasks to identify and comply with the regulatory changes.
      • Source document import tasks -- The Regulatory Change Management application processes the alerts that are externally sourced. Source document import tasks are automatically created whenever a source document alert record is marked as applicable. The source document can refer to the legislative and regulatory materials.
      • Users, associated actions, and states for the source document import tasks -- Managers with the sn_grc_reg_change.manager role and the users with the sn_grc_reg_change.user, or sn_grc_reg_change.admin role can view and perform certain actions on the source document import tasks.
      • Manage the source document import tasks -- Manage the source document tasks, the associated source document alerts, and other relevant details in the Regulatory Change Tasks module. Use these tasks to identify and comply with the source document changes.
    • Manage regulatory tasks -- You can perform various regulatory tasks in the Regulatory Change Management application in Compliance Workspace and receive granular information on the tasks and alerts using the data visualization widgets.
    • Regulatory alerts -- The List view in the Regulatory Change Management application in the Compliance Workspace displays all the regulatory alerts received under the Regulatory alerts option in the menu. The Unassigned alerts list displays all the new and unassigned regulatory alerts. The Type column in the Unassigned alerts list displays the type of the regulatory alert.
      • Link Change tasks -- Link Change tasks directly from the Impacted areas tab of a regulatory alert.
    • Change tasks -- When a regulatory alert is marked as applicable by the alert coordinator, manager, or administrator, the system initiates the creation of a regulatory change task. This task serves as a central point for stakeholders to determine the necessary modifications to organizational compliance practices.
      • Link Action tasks -- Link Action tasks for existing impacted areas from within a regulatory change task or directly through the regulatory alert.
    • Regulatory event alerts view -- When you select a regulatory event alert in the List view in the Compliance Workspace, it displays the details of the alert on a new page. The details include the title of the alert, provider of the alert, its state, and other important information in the Overview tab and Details tab.
    • Impact radius for regulatory events -- Impact radius typically refers to the extent to which a regulatory change affects an organization. Adding impacted areas to a regulatory alert of type regulatory event helps to calculate the impact radius of a regulatory alert.
    • Source document alerts -- When you select a source document alert in the List view in the Compliance Workspace, it displays the details of the alert on a new page. The details include the title of the alert, provider of the alert, its state, and other important information in the Overview tab and Details tab.
    • Respond to a regulatory assessment -- Utilize the Smart Assessment Engine to respond to regulatory assessments from the Employee Center.
    • Respond to a regulatory alert risk assessment -- Respond to a classic risk assessment on a regulatory alert to determine which entities are impacted and what actions must be taken to mitigate the risks.
    • Assess the impact of a regulatory alert -- Evaluate the risk of a regulatory alert by initiating either a risk assessment or a regulatory assessment.
    • Create regulatory event alerts manually -- Create a manual entry of the regulatory changes or updates so that they can be routed to the correct subject matter experts for further analysis.
    • Assign a regulatory event alert to a coordinator -- Log in to the GRC: Regulatory Change Management application, review the regulatory event alert, update the details, and assign it to a coordinator.
    • Assess the impact of a regulatory event alert -- Assess the impact of a regulatory event alert by creating an assessment on the regulatory event alert. Assign the impact assessment to the owner of the business entity that is affected by the alert.
    • Update a regulatory assessment template -- Publish a new version of assessment templates in Regulatory Change Management (RCM) to revise its questionnaire and response options. Each version maintains a change history of the templates used in regulatory assessments.
    • Manage regulatory change tasks -- Manage the regulatory change tasks that are associated with the regulatory event alert. When a business entity owner completes the impact assessment on the regulatory event alert, the user with the sn_grc_reg_change.user role reviews the assessment summary and marks the alert as applicable.
    • Manage a source document import task -- Manage the source document import tasks that are associated with the source document alerts. When a source document alert is marked as applicable, a source import document task is created automatically.
    • Assign a source document alert to a coordinator -- Log in to the GRC: Regulatory Change Management application, review the source document alert, and assign it to a coordinator. The coordinator then assesses the applicability of the alert and completes the associated regulatory tasks.
    • Create a new action task for the alert -- Create a new action task for the alert so that you can assign the action tasks to the compliance and risk users and mark a due date for the action tasks.
    • Complete the action task associated with the alert -- Complete the action tasks that are related to the regulatory event alerts and source document alerts. The compliance and risk users complete the action tasks that are assigned to them. The compliance and risk managers track the progress on the action tasks.
    • Create or add an issue related to a regulatory task -- Create or add an issue related to a regulatory task to document the observations, changes in the citation, discrepancies, or to notify about any problems. You can also identify the source of the issue to analyze and classify the issues.
      • Create New Issue form -- Use the Create New Issue form in Compliance Workspace to create an issue or add an existing issue to a regulatory task in Regulatory Change Management (RCM).
    • Associating an AI-recommended citation to an open regulatory alert -- Associate a citation to an open regulatory alert by using the GRC: Predictive Intelligence application and a similarity solution model that uses an AI-recommended citation. Your compliance team can check the incoming regulatory alerts to determine if the citations or requirements apply to your organization.
    • Action tasks in Regulatory Change Management -- The action tasks facilitating the change management process are associated with Regulatory Change. The ownership of these action tasks is managed by the respective business owners affected due to the regulatory change.
    • Import the regulatory event alerts in bulk -- Populate the Workspace with your own regulatory event alerts. You can then import multiple alerts in the Regulatory Change Management application.
    • Manage the taxonomy -- Manage the taxonomy when you are setting up the Regulatory Change Management application in the Compliance Workspace. Create an internal taxonomy and map the internal taxonomy to the external taxonomy so that the Regulatory Change Management application refers to only one taxonomy.
    • Export a report to PDF -- Create Portable Document Format (PDF) reports for compliance cases or requests using predefined or customized templates in the Compliance Workspace. This feature enables the stakeholders who may not have access to the application can still access the data.
    • Overview page and dashboard views -- The Regulatory Change Management overview page provides a high-level view of the regulatory activities in your organization. If you have the sn_grc_reg_change.manager role, you can view this page in the Compliance Workspace.
    • Tasks page in the Compliance Workspace -- The Tasks page within the Compliance Workspace provides a centralized, task-centric interface for managing all activities related to regulatory events, source documents, and compliance workflows. It helps you stay organized, ensures timely and accountable action, and promotes overall regulatory readiness.
    • Reference -- Reference topics provide additional information such as tables, roles, and properties that are installed with the Regulatory Change Management application.
    • User roles -- Stakeholders in the Regulatory Change Management (RCM) application have different roles and responsibilities.
    • Types of alerts, user roles, and states of regulatory alerts -- Different users perform various actions on the alert records based on the type of the alert.
    • Email notifications in Regulatory Change Management -- A number of email notifications are sent by the Regulatory Change Management application.
    • Roles and tables installed with Regulatory Agency Library -- Several types of components are installed with activation of the Regulatory Agency Library application, including tables and user roles.
  • Risk Management -- Use the Governance, Risk, and Compliance: Risk Management application to continuously monitor to identify high-impact risks, improve your risk-based decision-making, and reduce reaction time effectively. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.
    • Explore -- The Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.
    • GRC Risk Workspace -- Starting with version 13.0.5, the GRC Risk Workspace provides a new and simplified user experience with a single-pane view. In the workspace, you can perform the same functions as the classic environment, but with more intuitive functionality. These functions include risk assessments, risk events processing, and so on.
      • Risk Workspace for the operational risk manager -- Operational risk managers manage operational risks such as losses due to errors, breaches, or damages that are caused by people, internal processes, systems, or external events. Operational risks range from the small, such as the risk of loss due to minor human errors, to the large, such as the risk of bankruptcy due to serious fraud.
      • Risk Workspace for the business operational risk manager -- Business operational risk managers are the first lines of defense for each individual line of business. They are responsible to manage the risk posture of their specific business units.
      • Risk Workspace for the IT risk manager -- Information technology or IT risk is any threat to your business data and critical systems. It is the risk associated with using and operating IT within an organization. An IT risk manager is the primary person responsible for establishing and maintaining the organization-wide IT risk management program.
      • User experience enhancements in the Risk Workspace -- In the new workspace, several enhancements have been made to ease the way you perform your daily tasks. The user experience enhancements are useful for new GRC users or users who do not have the complete experience of GRC.
      • GRC Risk Portal -- The GRC Portal is a simplified interface that enables the GRC business users to view their tasks and their group's tasks. The GRC Portal also enables users to report risk events.
      • Advanced Risk Assessments in the Risk Workspace -- The Risk Workspace offers an enhanced and a simplified user experience for users to perform Advanced Risk Assessments. You can quickly access the risk assessments assigned to you or your group from the GRC Risk Portal or the Risk Workspace.
    • Advanced Risk Assessment -- Use the ServiceNow Governance, Risk, and Compliance (GRC) Advanced Risk Assessment feature to create an integrated risk platform. This integrated platform supports various kinds of risk assessment methodologies. It enables you to integrate risk assessment as part of your overall decision-making process.
      • Workflow of Advanced Risk Assessment -- To use Advanced Risk Assessment, you must set up the risk assessment methodology (RAM), define the assessment scope, and perform the assessment.
      • Factors in Advanced Risk Assessment -- Factors are questions that you can use to analyze risks. Factors appear on a risk assessment instance.
      • Types of risk rating methodologies -- Risks are scored during an assessment and then a rating is derived. Ratings are of three kinds: qualitative, semi-quantitative, and quantitative.
      • Transformation criteria -- After the risk scores are calculated, you can transform the scores into a rating and then easily report the ratings to senior management and to other stakeholders.
      • Any object assessment using Advanced Risk Assessment -- If you don't have the complete GRC setup for entities, risk statements, controls, and so on, even then, you can still assess the risks on any ServiceNow record or object. An example of object assessment is assessing change management or assessing a citation.
      • Delegation of risk assessment -- If a risk assessor is unavailable to perform a risk assessment, the assessor can appoint a delegate to perform the risk assessment for a specified time period. The ServiceNow AI Platform enables you to appoint your delegates.
      • Understanding the risk assessment instance -- A risk assessment instance is where a risk assessor can assess risks and objects by responding to questions or factors.
      • Managing risk responses -- A risk response is the strategy used to deal with risks after the risks are assessed.
      • Risk score rollup in Advanced Risk Assessment -- In Advanced Risk Assessment, risk scores are calculated across risk statement hierarchy, entity hierarchy, or a combination of both. These methods enable stakeholders to monitor their risk posture and provide visibility of the overall aggregated risk score.
      • Privacy risk management -- As users of Privacy Management, you can perform advanced risk assessments with a limited set of features even if you do not have the complete license for Integrated Risk Management.
      • Risk score rollup in Privacy Management -- When users of Privacy Management perform advanced risk assessments, they get the risk scores automatically rolled up.
      • Manage risk assessment scheduler -- Create a risk assessment scheduler and assign it to the risk manager. A risk manager can then identify the entities and the risks within the entities for bulk initiation of risk assessments.
      • Integration of advanced risk assessments with risks and controls -- When customers migrate to advanced risk assessments, the system replaces the legacy risk life cycle and shows a new section called Assessment Summary on the Risk form. This section is useful for the risk managers as it provides the overall visibility of the assessment results.
      • Risk appetite and tolerance in Advanced Risk -- You can define a risk appetite and tolerance within your organization by using the Advanced Risk application. A risk appetite and tolerance enable your organization to define the boundaries for acceptable and unacceptable risks.
      • Target risk assessment in Advanced Risk -- You can perform a target risk assessment to define your desired future risk level using the Advanced Risk application. The target risk assessment enables you to assess your target risk posture and monitor progress toward its achievement.
    • Manage risk events -- Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.
      • Risk events life cycle -- Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.
      • Relationship between risks, risk events, and risk statements -- Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.
      • Risk event response template -- Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.
      • Associate similar risk events -- Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.
    • Business process management -- A business process is an activity or a set of activities that can accomplish a specific organizational goal.
    • Exploring the entities -- Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications or objects that are examined for risks.
      • Entities -- An entity is a person, process, department, application, or other object whose compliance exposure is tracked in GRC. Each entity has an owner, so non-compliant items and their owners can be identified individually.
      • Entity types in GRC -- Entity types enable you to find and create entities that match a set of filter conditions. Entity types also enable you to create risks and controls for each entity without spending much time.
      • Entity classes in GRC -- Entity classes are used to tag your entities and to provide a complete view of the risk status in your organization.
      • Entity tiers in GRC -- By creating entity tiers, you can prioritize the entity classes.
    • Manage risks, risk statements, and risk frameworks -- The risk library contains all risk frameworks and risk statements. Risk frameworks are used to group risk statements into manageable categories, while risk statements group the individual risks. The risk register is the central repository for all potential risks that could occur at any time, anywhere in the organization.
      • Workflow of a risk using Advanced Risk -- When you migrate to advanced risk assessment, you can view the various states of the risks take the necessary actions. This ability simplifies your view of the risk form.
      • Manage risks linked to the same risk statement -- You can create and associate multiple risks to the same risk statement and entity combination. This association benefits the risk managers and the entity owners.
      • Risk hierarchy and scoring -- Starting with New York, risk managers can create hierarchies that include different types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are assessed, the risk scores are automatically rolled up across the risk statement hierarchy, providing better tactical and strategic decision-making.
      • Association of entities at any level of a risk statement -- You can associate entities, entity types, and indicator templates, at any level of the risk statement hierarchy. Creating this association is useful for risk managers while assessing risks.
    • Manage classic risk assessments -- Risk assessments are surveys to determine risk. The Risk Assessment Designer provides a single interface that users can use to create, and edit attestations, as well as change scoring parameters.
    • Risk indicators, control indicators, and indicator templates -- Indicators are an important tool used to manage your organization's risks. Indicators collect data to monitor controls and risks, and to collect audit evidence. Indicators monitor a single control or risk. They are used to enhance and facilitate the monitoring, mitigation, and reporting of risks.
    • Manage risk issues and remediation -- Issues can be created manually to document audit observations or remediations, or to accept any problems. They are automatically generated from indicator results, attestation results, or control test effectiveness.
    • Reporting views from Risk Assessment Methodology -- The reporting view provides an overview of all completed assessments under a specific Risk Assessment Methodology (RAM). It consolidates assessment data such as factor responses, scores, issues, controls, and associated risks into a single structure.
    • Configure -- Configure the Risk Management application to use the features it provides for the complete risk management of your organization.
    • Risk Management implementation -- Use the steps in the Risk Management application checklist to download the Risk Management from the ServiceNow Store, and get it ready for operation. Mandatory and optional setup steps, as well as an implementation checklist are provided to simplify the setup.
      • Download Risk Management -- Before you run GRC: Risk Management (sn_risk) in your instance, you must download it from the ServiceNow Store.
      • Install Risk Management -- You can install the Risk Management application (com.sn_risk) if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
      • Setup checklist for the Risk Management application -- This checklist includes the set up tasks that you are required to complete in your ServiceNow AI Platform instance. When you have completed these tasks, the base system is ready for operation.
      • Setup checklist for GRC Advanced Risk -- Use the following checklist to get a high-level overview of the basic configurations available with the Advanced Risk application.
      • Download Advanced Risk -- Before you run Advanced Risk in your instance, you must download it from the ServiceNow Store.
    • Risk Management detailed setup -- Set up Risk Management so that you can use the features such as risk assessments, risk events, and other capabilities of the GRC Risk Management application.
      • Quick start tests for GRC Advanced Risk -- Validate that Advanced Risk still works after you make any configuration change, such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
      • Configure Risk Management -- Administrators in the global domain can set properties to determine how the system defines the Risk Management application.
      • Risk Management Administration -- Using the Risk Management application, administrators can customize risk categories, risk criteria, risk management properties, and risk assessment types.
      • Quick start tests for Risk Management -- Validate that Risk Management still works after you make any configuration change, such as apply an upgrade or develop an application. Copy and customize these quick start tests to pass when using your instance-specific data.
    • Set up checklist for the GRC Mobile application -- The following checklist includes the set up tasks that you're required to complete in your ServiceNow AI Platform instance and on your mobile device. Complete these set up tasks before using the GRC Mobile application to view the Risk Management application on your mobile device.
    • Risk appetite setup -- You can configure the risk appetite feature in the Advanced Risk application.
    • Modify Advanced Risk messages -- Modify the messages displayed on the risk assessment form using the Advanced Risk application. Modifying system messages enables personalized and consistent messaging for users, aligning with their preferences and specific requirements.
    • Create related list groupings in Advanced Risk -- Simplify the groupings of related lists on a record page and customize them to your specific needs, assigning meaningful names in the process. This configuration enhances readability and user experience when interacting with the forms.
    • Integrate -- Extend the capabilities of Risk Management such as Advanced Risk Assessment and help other applications with risk identification and risk assessments.
    • Project Risk Assessment using Advanced Risk Assessment -- Manage your project risks by using the Project Risk Assessment capability. Risk administrators, projects managers, and risk owners can manage the complete project risk life cycle by using the Project Risk Assessment capability.
    • Application risk assessment using Advanced Risk Assessment -- Manage digital risks of business applications easily by integrating GRC with business applications. By integrating, you get real-time insights into the digital risk posture of business applications, have improved communication between application owners and IT risk managers, and can reduce workloads.
    • Integration of advanced risk assessment with other applications -- As an administrator, you can embed risk assessments within other workflows and define rules for when risk assessments must be initiated. The key benefit of embedding risk assessments is the digitization of the workflow so that assessments are initiated automatically without manual effort.
    • Integration of Employee Center and GRC -- The integration of GRC tasks with the Employee Center makes it easier for employees to complete the GRC tasks easily and effectively. This integration allows them to report risk events or request policy exceptions and makes GRC more useful in the organization.
    • Manage continuous monitoring for risks between Risk Management and Vulnerability Response -- Continuous monitoring for risks is a feature integration between the GRC: Risk Management and the Security Operations Vulnerability Response products, which uses indicators to quickly identify high impact vulnerabilities based on business impact.
    • Integrating Microsoft 365 with Management Reporting of Risk -- The Management Reporting of Risk (sn_grc_mgmt_report) integration provides reporting capabilities to Risk reporting managers to report ServiceNow Risk Management system data, list reports, charts, pivot, and multi-pivot reports using Microsoft Word.
    • Use -- You can use the features and capabilities of the Risk Management application perform various activities such as creating issues, reporting risk events, performing risk assessments and so on.
    • Mobile experience for GRC Risk Management -- As a risk manager, use your Android or iOS mobile device to manage your work.
    • Use Risk Events -- Report risk events and monitor their workflow to prevent losses in your organization.
      • Configure risk event integration -- Configure risk event integration with other upstream ServiceNow applications. This integration enables all users in an organization to report and track the risk events.
      • Create a risk event response template -- Automatically assign the risk event owner, create and assign issues, and route approvers based on entity, event type, category, and impact thresholds in the risk event response template.
      • Risk Event Response Template form -- Use the Risk Event Response Template form to define assignment rules. Rules automatically assign owners, approvers, issues, and Root Cause Analysis (RCA) tasks to risk events based on entity, event type, category, and impact thresholds.
      • Define a threshold amount for the risk event response template -- Define a threshold limit for assigning risk event approvers. A threshold limit is defined to determine if a risk event needs an approver.
      • Financial Impact Approval Thresholds -- Use the Financial Impact Approval Thresholds form to define monetary thresholds that trigger approval requirements for risk events and to configure how approvers are determined when those thresholds are met.
      • Report risk events from the Service Portal -- When you identify any event that might have a financial or non financial impact on your organization, report it from the ServiceNow, Inc. Service Portal. You can also report any event that has already occurred with a financial or non financial impact.
      • Report a risk event from Employee Center -- When you identify any event that might have a financial or non financial impact on your organization, report it from the ServiceNow, Inc. Employee Center. You can also report any event that has already occurred with a financial or non financial impact.
      • Report a risk event from an incident -- If risk event integration is configured, users can report risk events from any upstream application such as IT Incidents. This ability to report risk events saves the time of users and helps to prevent losses for organizations.
      • Create a risk event task -- A risk event might require associated tasks. Unless these tasks are created and eventually closed, the risk event cannot be closed.
      • Analyze a risk event -- Analyze user-submitted risk events to determine if the risk event is valid and needs further processing.
      • Create a risk event entry -- Create a risk event entry to determine the monetary or non-monetary impact of the risk event. A risk event can have multiple risk event entries.
      • Approve a risk event -- A user with the sn_risk.manager role must approve a valid risk event. If any risk approver rejects the event, the state of the risk event changes to rejected.
      • Close a risk event -- Close a risk event to complete the risk events life cycle. A user with the sn_risk.manager role must close the risk event after verifying that all associated open issues and remedial tasks are closed.
      • Reopen a closed risk event -- Reopen closed risk events to identify and address overlooked or underestimated risks, updating existing risk events instead of creating another risk event.
      • Add a risk event cause to the cause library -- A cause library is a centralized library of the possible causes that can lead to a risk event. Adding causes helps to identify the reason for a risk event and prevent future events.
      • Add a risk event consequence to the consequence library -- A consequences library is a centralized library of the possible consequences of a risk event.
      • Set up GRC Virtual Agent to report risk events -- Use a Virtual Agent chatbot to report risk events from the Service Portal. A virtual agent chatbot helps customers to quickly report a risk event. The chatbot assists the customers by saving their time. The information exchanged during the conversation flow enables the chatbot to fulfill a user request or assist the user in completing a task.
    • Perform Advanced Risk Assessment -- Use the ServiceNow Governance, Risk, and Compliance (GRC) Advanced Risk Assessment feature to create an integrated risk platform.
      • Create a manual factor -- Create manual factors to evaluate and assess risks on a risk assessment instance.
      • Create a group factor -- Create group factors to evaluate and assess risks on a risk assessment instance.
      • Scoring logic for predefined formulas for group factors -- Group factors have multiple predefined formulae and each of them has a specific contribution to the scoring logic.
      • Create an automated factor -- Create automated factors to automatically fetch data from other data sources such as tables or database views.
      • Create a scripted automated factor -- Create scripted automated factors that use a script to fetch data from ServiceNow records or from external sources. During risk assessment, scripted automated factors automatically calculate and provide the responses for factors.
      • Copy a factor -- Create a copy of a published factor to make minor modifications and then reuse the factor.
      • Configure a risk assessment methodology -- Configure a risk assessment methodology (RAM) in the Advanced Risk application so that you can assess the risks or objects in your organization.
      • Risk Assessment Methodology form -- Use the Risk Assessment Methodology form in the Advanced Risk application to specify the types of risk assessments and the entities on which the risk assessment is performed.
      • Copy a risk assessment methodology -- Modify your risk assessment methodology (RAM) and factors by creating a copy of the record. The option to copy allows the system to create a true copy of the underlying record including all the related lists. This action saves the time of risk administrators as they do not have to create the records from the beginning each time.
      • Retire a risk assessment methodology -- Retire a risk assessment methodology (RAM) that is no longer used. Retiring unused RAMs makes it easier to manage the active RAMs for the risk administrator.
      • Configure an inherent assessment -- Configure and publish an inherent assessment in the Advanced Risk application to assess the inherent risks in your organization.
      • Inherent Assessment form -- Use the Inherent Assessment form in the Advanced Risk application to assess the inherent risks in your organization.
      • Configure a control effectiveness assessment -- Configure and publish a control effectiveness assessment to assess the effectiveness of controls in mitigating risks.
      • Control Assessment form -- Use the Control Assessment form in the Advanced Risk application to assess the effectiveness of controls in mitigating risks.
      • Configure a residual assessment -- Configure and publish a residual assessment in the Advanced Risk application to assess the residual risks in your organization.
      • Residual Assessment form -- Use the Residual Assessment form in the Advanced Risk application to assess the residual risks in your organization.
      • Configure a target assessment -- Configure and publish a target assessment in the Advanced Risk application to assess your desired future risk level. By configuring a target assessment, you enable the assessors and approvers to perform a target risk assessment in the Next Experience.
      • Target assessment form -- Use the Target Assessment form in the Advanced Risk application to assess the desired future risk level in your organization.
      • Create risk color styles -- Create a library of risk color styles to use for different assessment types and matrixes. A risk color style is a combination of a background color and a text color. The color styles help maintain consistency when you configure risk assessments.
      • Configure risk heatmaps -- Within a risk assessment methodology (RAM), configure the heatmap visualization for inherent and residual assessments. Use different heatmaps for different risk assessment methodologies.
      • Create a risk assessment scope and initiate assessments -- Create a risk assessment scope to define and identify risks for an entity. Identify assessors and approvers for assessments, and define the frequency of assessments.
      • Simulate a risk assessment -- Simulate a risk assessment to verify the associated risk assessment methodology (RAM) configuration when it is in the draft state.
      • Assess risks and objects on an assessment instance -- Assess the risks that you have configured and reassign the risks to relevant approvers.
    • Assess risks -- Use the classic risk assessment and assess the risks in your organization.
      • Create a risk assessment using the Risk Assessment Designer -- Use the Risk Assessment Designer to create and edit metric types, use different metric types for different risks, select multiple respondents for a risk assessment, as well as change scoring parameters. The Question Bank offers a library of questions for various categories, so you do not have to build each questionnaire from scratch.
      • Create an assessment type -- The risk manager can create a set of questions for each risk assessment.
      • Assess risk for a policy exception -- After the review of a policy exception request and before deciding to approve or reject a request, the compliance manager may choose to request a risk assessment by the risk manager.
      • Assess a risk -- Risks start in a Draft state then move to the Assess state.
    • Manage a business process -- Create and manage business processes in your organization.
      • Create a business process -- Create a business process and define the owners, approvers, business criticality, and review frequency for the process.
      • Approve, reject, or delete a business process -- If a new business process has identified approvers, then the approvers must review and approve the process before it can be published. The approvers can also reject or delete the process as necessary.
    • Create a risk framework and associate risk statements to it -- Risk managers create risk frameworks to group risk statements into manageable categories.
    • Define risk statement hierarchy -- Risk managers establish parent and child relationships on the risk statement form.
    • Create a risk statement -- Risk managers create risk statements to group risks into manageable categories.
    • Visualize risk hierarchies using the GRC: Workbench -- Risk users can see the hierarchy of risk statements using the GRC: Workbench.
    • Generate a risk from a risk framework -- Making associations with risk frameworks automatically creates risks.
    • Generate a risk from a risk statement -- Making associations with risk statements automatically creates risks.
    • Relate risks to each other -- Create relationships between risks to better understand how risks affect each other and how they affect the enterprise.
    • Create a risk manually -- Risk administrators can create risk records when they see a potential for a gain or loss of value.
    • Follow a risk -- Connect integrates with Risk Management providing an overlay to the standard interface, allowing users to participate in conversations while they work and collaborate on the risk record.
    • Add a control to a risk -- Controls are added to the risks for the on-going review of processes.
    • Manually create issues -- As a GRC user, you can manually create issues to document policy, risk, or audit observations, or to accept any GRC problems. You can also identify the source of the issue to help analyze and classify the issues.
    • Use entity and risk dependencies using the GRC: Workbench -- The GRC: Workbench utilizes CMDB information to show the upstream and downstream relationships across all applications. CMDB information is one of the sources. These relationships enable consistent risk mapping and modeling across the enterprise.
    • Monitor risks using GRC Performance Analytics Indicators -- You can link Risk Management risk statement and risks to Performance Analytics indicators, breakdowns and thresholds. You can associate Performance Analytics indicators with risk statements, and risks to view scorecards and trends and analyze current conditions and trends.
      • Activate performance analytics integration -- The GRC: Performance Analytics Integration plugin provides an integration between Performance Analytics and the Risk Management and Policy and Compliance Management applications. This plugin provides more insight into organizational risk and compliance performance.
      • Associate PA indicator with risk or control objective -- You can associate Performance Analytics indicators with risk statements and policy statements to analyze trends related to the risk or policy.
      • Associate PA indicator with risk or control -- You can associate Performance Analytics indicators with risks and controls to analyze trends related to the entity that risk or control belongs to.
      • Update associated indicators -- You can update all the items belonging to a GRC content record so each item is individually related to the PA indicator.
    • Create GRC indicator template -- Compliance or risk managers create indicator templates from which many indicators can be created.
    • Create a risk indicator -- Create a risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system, and they enable you to take preventative action on the risks.
    • View the Risk Overview -- The Risk Overview is contained in the Risk Management application and provides an executive view, allowing risk managers to quickly identify areas of concern by pinpointing entities with known high risk.
    • Use Risk Workspace -- Starting with Version 13.0.5, a new workspace has been introduced for the Risk Management application. The new workspace provides you with an improved User Experience (UX) and a simplified user journey.
    • Create a risk framework in the Risk Workspace -- Create risk frameworks to group risk statements into manageable categories and generate risks. After the risks are generated, you can identify methods to mitigate them.
    • Associate a risk statement with a control objective in the Risk Workspace -- Associate risk statements to control objectives in the Risk Workspace. This association helps you to manage your risks by ensuring that the risks have mitigating controls.
    • Common controls in Risk Management -- By linking the risks to a common control in the Risk Management application, you can reduce the time and effort that is needed to manage and apply these centralized controls to your reliant entities. For example, a fire sprinkler system can be a common control for multiple business units (BUs), such as finance, security, and human resources (HR).
    • Create and run a manual risk indicator in the Risk Workspace -- Create and run a manual risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system and they enable you to take preventative actions on risks. In a manual indicator, the results are manually gathered using task assignments.
    • Create and run a basic risk indicator in the Risk Workspace -- Create and run a basic risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system and they enable you to take preventative action on the risks. Basic indicators are automated indicators based on an indicator source.
    • Create and run a scripted risk indicator in the Risk Workspace -- Create and run a scripted risk indicator to identify the possibility of a future adverse impact on your organization. A scripted indicator enables you to write your own script to run the indicators. Indicators are an early warning system and they enable you to take preventative action on the risks.
    • Issue management in the Risk Workspace -- The issues landing page in the Risk Workspace provides logged-in managers and users with all the information they need to manage issues on a single page. The landing page features actionable insights, quick action buttons, filters, and access to open issue triages.
    • Create a risk assessment scope in the Risk Workspace -- Create a risk assessment scope to identify risks for an entity, define assessors and approvers, set assessment frequency, and initiate assessments using the Risk Management application.
    • Schedule risk assessments in the Risk Workspace -- Schedule risk assessments automatically for multiple entities. The risk assessment scheduler helps the risk managers save time by automatically initiating the assessments based on the defined frequency.
    • Perform advanced risk assessment in the Risk Workspace -- Conduct risk assessments to assess inherent risks, effectiveness of controls, residual risks, and target risks in the Risk Workspace application. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
    • Perform any object assessment in the Risk Workspace -- Assess the risks on any object or record in ServiceNow. An example of object assessment is assessing change management or assessing a citation.
    • Workflow of risk response task -- The risk response task workflow is a structured process to manage assessed risks by defining plans of action to either accept, mitigate, avoid, or transfer those risks.
    • Workflow of action item in risk response task -- The action item workflow is a structured process for managing the granular tasks associated with risk response tasks, which are assigned to multiple stakeholders.
    • Create a risk response task in the Risk Workspace -- Create a risk response task to define plan of actions, assign responsibilities, set priorities, and establish deadlines to ensure effective management of the assessed risks.
      • Create an action item in the risk response task -- Create multiple strategies with various action items for each risk response task. Action items help you to understand and focus on specific steps needed to manage risks.
      • Create New Action Item form -- Use the Create New Action Item form to define the plan of action, assign responsibilities, set priorities, and establish milestones for the action item.
    • Workflow for risk identification in the Risk Workspace -- Workflows provide step-by-step guidance for completing the risk identification process in the GRC Risk Workspace.
    • Create a risk event in the Risk Workspace -- Create a risk event in the Risk Workspace. Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization.
    • Associate similar risk events -- Train a similarity solution definition that uses machine learning by activating the Governance, Risk, and Compliance: Predictive Intelligence plugin. The solution enables the system to display similar risk events automatically.
    • Categorizing risks with the Governance, Risk, and Compliance: Predictive Intelligence plugin -- By using the Governance, Risk, and Compliance: Predictive Intelligence plugin, you can predict the risk statements for your orphan risks (the risks that don't have risk statements) on the risk records for your organization. You can then identify the correct risk statement for the risks and then aggregate them into manageable categories.
    • Analyze a risk event in the Risk Workspace -- Analyze user-submitted risk events. You can add additional details to the risk event, request more information from the submitter, or reject the risk event if the event is not valid.
    • Create a risk event entry in the Risk Workspace -- Create a risk event entry to determine the monetary or non-monetary impact of the risk event. A risk event can have multiple risk event entries.
    • Create an ORX external event -- Create an Operational Riskdata eXchange (ORX) external risk event to share the risk event of your company with other organizations. This exchange of risk events information acts as a learning for other organizations in the industry and prevents them from making the same errors.
    • Report a risk event from the Risk Portal -- Report a risk event from the Risk Portal. The Risk Portal provides an easy method to quickly report risk events.
    • Chart colors for risk data -- You can view your risk data visualizations in different colors for a quick overview of your risks.
    • Create a business process in the Risk Workspace -- Create a business process in the Risk Workspace and define the owners, approvers, business criticality, and review frequency for the process.
    • Create a test plan in Risk Workspace -- Create a test plan to document the control testing procedure. You can create a test plan from scratch or based on a test template to describe how a feature is to be tested.
    • Filter data in the risk heatmap workbench -- As a risk user, filter data in the risk heatmap workbench to get a granular view of your risks.
    • Define the risk appetite for an entity -- Define the risk appetite on the entity records in the Risk Management application to evaluate all the possible risks and to set the boundaries for the acceptable and unacceptable risks for your business.
      • Risk appetite fields on the Entity form -- Learn about the risk appetite fields on the Entity form. Use these fields to define the risk appetite, evaluate all the possible risks, and set the boundaries for the acceptable and unacceptable risks in the Risk Management application.
    • Define the risk appetite for a risk -- Define the risk appetite on the risk records in the Risk Management application to evaluate all possible risks and to set the boundaries for acceptable and unacceptable risks.
      • Risk appetite fields on the Risk form -- Learn about the risk appetite fields on the Risk form. Use these fields to define the risk appetite, evaluate all the possible risks, and set the boundaries for acceptable and unacceptable risks in the Risk Management application.
    • Define the risk appetite for a risk statement -- Define the risk appetite on the risk statement records in the Risk Management application to evaluate all the possible risks and set the boundaries for the acceptable and unacceptable risks.
      • Risk appetite fields on the Risk Statement form -- Learn about the risk appetite fields on the Risk Statement form. Use these fields to define the risk appetite, evaluate all the possible risks, and set the boundaries for the acceptable and unacceptable risks in the Risk Management application.
    • Parallel Review and Feedback in Advanced Risk -- The Parallel Review and Feedback workflow enables second-level and third-level line managers to review records and provide feedback at any stage, facilitating collaboration across management lines and ensuring feedback is tracked through closure.
      • Parallel Review and Feedback workflow -- The Parallel Review and Feedback workflow outlines the systematic process by which the solution facilitates the submission of feedback on a record or specific fields within a record. Feedback could be related to any improvement or recommendation at a record level, such as data integrity, compliance, and operational procedures.
      • Feedback dashboard -- Use the Feedback dashboard to track and manage feedback using the Risk Workspace. The Feedback dashboard organizes feedback according to its status, importance, type, and other specific factors.
      • Configure a feedback integration -- Configure a feedback integration setup in the Advanced Risk application to define the table on which you want to use Parallel Review and Feedback. This setup enables you to define the workspace, reviewer, and respondent for creating feedback on the table records.
      • Feedback integration configuration form -- Use the Feedback integration configuration form to define a setup for the Parallel Review and Feedback.
      • Create feedback in Advanced Risk -- Create feedback on a record or fields in a record in the Advanced Risk application. The feedback enables you to recommend improvements related to data integrity, compliance, operational procedures, and other pertinent areas.
      • Create feedback in the Risk Workspace -- Create feedback on a record or fields in a record, to recommend improvements related to data integrity, compliance, operational procedures, and other pertinent areas, such as disposition and accountability.
      • Create Feedback from the record side panel -- Create feedback on a record or fields in a record from the record side panel using the Advanced Risk application. The feedback enables you to recommend improvements related to data integrity, compliance, operational procedures, and other pertinent areas.
        • Feedback Details form -- Use the Feedback Details form to provide feedback on a record or fields in a record from the record side panel.
      • Initiate a chat from Sidebar in Parallel Review and Feedback -- Initiate a Sidebar chat to collaborate among different stakeholders to brainstorm solutions, clarify details, or coordinate actions regarding the feedback received.
      • Respond to the feedback -- Provide comments or explanations regarding the submitted feedback using the Advanced Risk application. You can either remediate or reject the feedback, provided that there’s proper justification.
      • Review and close the feedback -- Review the feedback response and take further actions using the Advanced Risk application.
      • Roles for Parallel Review and Feedback -- When you integrate Parallel Review and Feedback with other applications, users must have the necessary roles to review records, capture feedback, and track the closure of feedback.
    • Risk assessment project -- You can perform assessments on multiple risks and controls simultaneously by creating a risk assessment project. Risk assessment project enables assessors to review multiple risks and controls to understand their potential impact, likelihood, and associated mitigation strategies.
      • Workflow of risk assessment project -- The risk assessment project workflow is a structured process to assess multiple risks and controls simultaneously using Risk Workspace.
      • Create a risk assessment project -- Create a risk assessment project to perform assessments on multiple risks and controls simultaneously using Risk Workspace. You can define the project context, including the assessable entity, Risk assessment methodology (RAM), project name, description, and identify and add stakeholders.
      • Perform assessment on a risk assessment project in stacked view -- Perform assessments on multiple risks and controls simultaneously in a risk assessment project using Risk Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
      • Perform assessment on a risk assessment project in grid view -- Perform assessments on multiple risks and controls simultaneously in a risk assessment project using the grid view. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
      • Reassess a risk assessment project -- Reassess a risk assessment project to assess any completed risk assessment project. It verifies that risks are reviewed and updated to reflect new insights or changing conditions, maintaining alignment with organizational goals.
      • Reassign assessor for a risk assessment project -- Reassign assessors for multiple in-progress risk assessment projects simultaneously to minimize disruptions during stakeholder transitions.
    • Matrix report in Risk Workspace -- Matrix report is a structured report that you can configure to view in a grid or table format in the Risk Workspace. You can use the matrix report to access and analyze the risk posture of your organization using entity-related data, such as risks, controls, KRIs, and events.
      • Configure Matrix report registry -- Configure the Matrix report registry to select the base table. You can create a relationship of the base with the target table to configure the details of the report for an entity-related record or a landing page.
      • Create Matrix report configuration for Risk Workspace -- Create the Matrix report configuration by naming the report, choosing a display type (Landing page or Record page), and setting filter conditions on the base table.
      • Matrix report configuration form -- Use the Matrix report configuration form to configure the Matrix report in the Risk Workspace.
      • View matrix report in the landing page and record page of Risk Workspace -- Access and analyze the risk posture of your organization using entity-related data, such as risks, controls, KRIs, and events in a centralized, configurable grid-based view. The Matrix report reduces time spent switching views and helps risk managers assess data more easily, leading to more proactive and streamlined risk management.
    • GRC: Metrics in Integrated Risk Management -- Risk metrics are defined as a quantifiable measure that is used to track and assess the status of a specific risk. Metrics help in tracking the exposure of a risk over time.
    • Explore -- A metric is used to measure and evaluate the effectiveness of your organizational processes. A metric or a combination of metrics can provide an insight into a system, component, or process.
      • Components of GRC: Metrics -- A metric consists of several components such as metric definition, metric data, metric definition data, metric data tasks. All of these elements or parts contribute to the metric collection process in various ways.
      • Metric definition types -- A metrics manager defines the metrics by creating a metric definition. A metric definition is a template-level record. In the metric definition, you set the core properties of the metric, such as unit, direction, nature, precision, and category. The metrics collect the scores, and these scores get rolled up into the metric definition.
      • Thresholds in Integrated Risk Management -- In the context of metrics, thresholds refer to predetermined values or limits used to assess the performance of a metric. These thresholds are typically defined based on specific criteria or objectives and serve as reference points to determine whether the measured value or performance meets, exceeds, or falls below the desired level.
      • Metric data table -- The metric data table enables data collection for metrics across the organization using an easy-to-use interface like a spreadsheet with multiple filters and a task management workflow.
    • Configuring metrics -- You can configure GRC: Metrics to meet the needs of your organization.
    • Using GRC: Metrics to provide data -- Using the GRC: Metrics application you can track your business goals, define your key risk indicators (KRIs) and key performance indicators (KPIs), and generate reports for the management to provide insights into the progress.
    • Reference -- Several properties, tables, and roles are installed with the GRC: Metrics application.
    • Analytics and reporting solutions for Risk Management -- Platform Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.
    • Operational risk heatmap for Advanced Risk Assessment in the Risk Workspace -- As an operational risk manager, you can configure and manage your risk heatmaps in the Risk Workspace.
    • Risk heatmap for classic risk assessment -- As an operational risk manager, if you opt to use the classic risk assessment to assess the risks in your organization, you can view the risk heatmap to get an overview of the risk posture for your organization.
    • Risk heatmap workbench -- As an operational risk manager, you can visualize the risk details and better understand the risk posture of your entity by using the risk heatmap workbench in the Advanced Risk application.
    • Operational Risk Management dashboard -- The Operational Risk Management dashboard enables an entity owner, with the role sn_risk.user, to view the complete risk posture for the enterprise in a single consolidated report. This dashboard makes it easy to analyze the risk posture efficiently and take necessary corrective actions to ensure that there are no losses.
    • Project Risk Overview dashboard -- The project risk dashboard is useful for project managers and the enterprise risk managers. Using this dashboard, the project managers and enterprise risk managers can view the risk performance and the overall risk posture. This dashboard helps risk managers to reduce the overall risks in an organization.
    • Risk Identification Overview dashboard -- The risk identification dashboard is useful for risk managers and helps them to keep a track of various records or objects which are in transit in the risk identification workflow.
    • Basel dashboard -- The Basel dashboard is a medium to share the Basel reports with external regulators for Basel regulations. This dashboard is useful for banking and financial domains where it is compulsory to share the Basel reports.
    • GRC Risk Overview dashboard -- The Risk Overview dashboard provides an executive view into the status and workflows of inherent and residual enterprise and IT risks. The user can drill down into risks by framework, response, and exception.
    • Advanced Application Risk dashboard -- The GRC Application Risk and Compliance Overview Dashboard provides the latest view of risk and compliance aspects for the business applications that are used in an enterprise.
    • Performance Analytics dashboards for risk events and risk hierarchy -- Use the Performance Analytics (PA) dashboards to view the comprehensive data for risk events and risk hierarchy. Use the Analytics Hub to view data for any time period.
    • Advanced risk assessment dashboard -- Use the Advanced Risk Assessment Overview dashboard for an overview of the performance of any risk assessment methodology based on the risk assessment instances.
    • Reference -- Reference topics provide additional information such as tables, roles, and properties that are installed with the Risk Management application.
    • Components installed with Risk Management -- Several types of components are installed with activation of the Risk Management plugin, including tables, user roles, and scheduled jobs.
    • Components installed with Advanced Risk -- Activating the GRC: Advanced Risk (sn_risk_advanced) plugin adds or modifies several tables, user roles, and other components. The Advanced Risk plugin enables you to perform advanced risk assessments and manage risk events.
    • Business process roles -- Various roles are available for business process users and managers.
    • Domain separation in Risk Management -- Domain separation is supported for Risk Management. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
  • Smart Assessment Engine -- The ServiceNow Smart Assessment Engine (SAE) application helps you to reduce the manual burden and costs of your assessment processes through automation.
    • Exploring Smart Assessment Engine -- The ServiceNowSmart Assessment Engine (SAE) helps you reduce the manual burden and costs of your assessment processes through automation.
    • Accessing templates in the Assessment Workspace -- You can see all your assessment template-related information on the Assessment Workspace landing page. You can review the published and unpublished assessment templates and create assessment templates by using the Smart Assessment Engine application.
    • Domain separation and Smart Assessment Engine (SAE) -- If any conkeyrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file.Domain separation is supported for Smart Assessment Engine. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Configure -- You can activate or upgrade the Smart Assessment Engine application by downloading it from the ServiceNow Store and then configuring the settings in the initial setup checklist to meet your needs.
    • Triggering assessments -- You can trigger a Smart Assessment Engine assessment from the Workflow Studio or from a script. With either method, you specify a published assessment template, the assessors who respond, and other optional inputs.
      • Configure the Trigger Smart Assessment Flow action -- Configure the Trigger Smart Assessment flow action to initiate the Smart Assessment Engine assessments and send them to the specified assessors. You then add the action to your flow.
      • Trigger assessments from a script -- Use a script to execute the Trigger Smart Assessment flow action to generate Smart Assessment Engine assessments and assign them to the assessors.
      • Scope items in an assessment -- The scope of an assessment is the specific record that the assessment targets — such as a control, vendor, or entity. Scope items keep that record in view for responders and reviewers, and other SAE features use scope to behave intelligently.
    • Creating an assessment template from legacy assessment metric types -- You can use the assessment designs that you have already created by migrating the metric types to the Smart Assessment Engine assessment templates. You can leverage the existing assessment designs to support SAE assessment automation, analysis, and reporting.
    • Manage -- Use template designer to create assessment templates. After the templates are published, assessors can respond to assigned assessments, track progress, and save their input automatically.
    • Use template designer -- You can create assessment templates and add instructions, questions, and reference information by using the template designer in the Smart Assessment Engine application. Smart assessments can help you to evaluate various situations, aspects, or records.
      • Create an assessment template -- Create an assessment template by using the Smart Assessment Engine application by naming it, specifying its categories, and optionally, specifying the tables that have the records as the assessment target or scope. You can then add questions and other attributes to the template. Alternatively, you can also copy an existing template including all questions, sections, instructions and existing configurations.
      • Create assessment template form -- In Smart Assessment Engine, the Create Assessment Template form contains the following fields for creating an assessment template.
      • Add instructions and questions to an assessment template -- Add instructions and questions to an assessment template by using the Smart Assessment Engine application. You can use instructions and questions to help gather precise and relevant information from designated responders.
        • Create a text question -- Enable the assessors to respond to a question by using simple text in an assessment. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a drop-down list question -- Enable the assessors to respond to a drop-down list question by making one or more selections from a list. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a radio button question -- Enable the assessors to respond to a radio button question by making a selection from a limited list of options. Only one selection is allowed for this question type. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a check box question -- Enable the assessors to respond to a check box question by selecting one or more options in a specified list of options. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a number question -- Enable the assessors to respond to a number question with a numerical value. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a reference question -- Enable the assessors to respond to a reference question by selecting an item from a list. The list is generated dynamically from the data in the table that you specify. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create an attachment question -- Enable the assessors to respond to an attachment question by adding one or more files as a response. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a date question -- Enable the assessors to respond to a date question by specifying a date or a date and time. Specify any of several attributes to qualify the question, for example, whether a response is required or an attachment is requested as part of your assessment template by using the Smart Assessment Engine application.
        • Create a code question -- Enable the assessors to respond to a question by using entering a barcode number or scanning a QR code in an assessment.
      • Add reference information to an assessment template -- Add reference information to an assessment template so that assessors can access the information they need while responding to assessments by using the Smart Assessment Engine. With an assessment template, you can minimize the need for external references and can improve the efficiency of the assessment process.
      • Create an assessment template category -- Create an assessment template category in the Smart Assessment Engine application so that you can organize and grant access to the assessment templates that are related.
      • Copy an assessment template -- Make a copy of an existing assessment template in the Smart Assessment Engine to help reduce the amount of manual input needed. The copied template includes all questions, sections, instructions, and existing configurations from the original template, which you can then customize to meet new requirements or scenarios.
      • Scoring assessments -- Scoring in Smart Assessment Engine is a systematic way to evaluate responses to various questions within an assessment. By attributing scores to answers, you can translate qualitative responses into quantitative data, offering a measurable and comparable outcome for each assessment.
      • Scoring results -- After an assessment is completed, scores are calculated and stored based on the scoring configuration defined in the template.
      • Configure scoring for an assessment -- Set up scoring for your assessment responses to calculate meaningful scores at the assessment, section, or subsection level.
        • Scoring forms -- Learn about the fields of the scoring forms. Use this form while configuring scoring for an assessment.
      • Normalization in assessment -- Normalization in Smart Assessment Engine refers to adjusting assessment question scores to a common scale to promote fair comparison and prioritization.
        • Score normalization -- In Smart Assessment Engine normalization maps the actual scores to a standardized scale, typically from 0 through 100, enabling for a unified evaluation framework.
        • Configure normalization in assessment -- In Smart Assessment Engine, set up normalization to adjust assessment response scores to a common scale at the assessment, section, or subsection level.
        • Create a normalization strategy -- You can create a custom normalization strategy as required.
        • Edit a normalization strategy -- You can edit a normalization strategy only if it is in a draft state and not being used by any category.
        • Retire a normalization strategy -- You can retire a normalization strategy to confirm it is no longer active. Once retired, it cannot be reactivated or changed back to draft or published. However, any purposes currently using this strategy will continue to do so.
        • Delete a normalization strategy -- You can delete a normalization strategy only if it is in draft state. Deleting a strategy removes it permanently, so confirm it is no longer in use before proceeding.
      • Automate response -- Set up default responses for questions so that assessors can complete assessments quickly and provide quality results.
      • Configure an automatic response for a question -- Set up automatic responses for assessment questions using either static responses or script-based responses based on specific conditions. You can configure default responses for text, drop-down list, radio button, check box, date, code and number question types. This feature helps save assessors time and effort by reducing the number of questions that require answers.
      • Post-assessment automations -- Post-assessment automations, also known as post-assessment actions, in Smart Assessment Engine are actions that happen automatically after an assessment is complete. These actions use the responses from an assessment to automate tasks. Using action sets, automated actions, trigger conditions, and evaluation criteria, post-assessment actions can help your assessments be efficient, consistent, accurate, and scalable.
      • Configure post-assessment actions -- Automate actions based on assessment responses in Smart Assessment Engine. Template designers can predefine actions using a rule engine, such as updating fields, creating follow-up assessments, or generating other records.
      • Link subflow to template category -- Linking a subflow to action categories ensures that this action becomes available in the action set. Template designers can configure these actions based on specific criteria to trigger automatically once the assessment is completed.
      • question-bank --
      • Template versioning -- Template versioning in Smart Assessment Engine enables organizations to maintain multiple versions of assessment templates over time. The ongoing assessments continue to exist even if their related version is retired or superseded by new versions.
      • Create a template version -- In Smart Assessment Engine, create a new template version when you must update the questions, instructions, or structure of a published template without disrupting assessments that are already in progress. Existing assessments continue to use the version they were triggered from, and new assessments triggered after you publish the new version use the new template.
      • Quick edit for published templates -- Quick Edit lets template managers make minor corrections to published templates without creating a version, enabling rapid fixes for typos and formatting issues while assessments remain in progress.
      • Modify a published template using quick edit -- Use Quick edit to make limited changes to a published template which has an assessment associated with it without creating a version. Quick edit is intended for small corrections, such as fixing typos or updating text, while preserving the published state of the template.
      • Embedded assessments -- Upstream applications can embed the Smart Assessment Engine responder experience directly within their workspace and control which interface components are visible.
      • Embed an assessment in a record page -- Configure SAE to let an upstream application (an application that hosts or triggers the assessment) surface the Smart Assessment Engine responder experience inside its own UI rather than as a separate page.
    • Respond to assessments -- Use the Smart Assessment Engine application to help assessors complete assessment requests. Track your progress and let the system automatically save your information.
      • Respond to an assessment -- Respond to an assessment that has been assigned to your queue. Your responses to the assessment help with making informed decisions and taking targeted actions by using the Smart Assessment Engine application.
      • Submit an assessment -- You must have the assessment actor role to complete and submit the assessment. The submit button becomes enabled once all required questions are answered.
      • Reassign an assessment -- Reassign assessment to redirect them to different users, enabling for flexible task management.
      • Filtering questions in an assessment -- In SAE, narrow the question list in an assessment by selecting one or more filters from the filter dropdown. Filters can be combined to focus on questions that match every selected criterion.
      • Filter questions in an assessment -- In SAE, narrow the question list in an assessment by selecting one or more filters from the filter dropdown. Combine filters to focus on questions that match every selected criterion.
      • Adding attachments to assessment -- You may have documents or image files that provide additional information for the assessment, you can attach these documents to assessments in the open state. These documents and image files can be added as attachments to the assessment for reference.
      • Add comments to an assessment -- In SAE, add comments and work notes to an assessment to clarify questions or other aspects of the assessment. Owners, contributors, readers, and administrators can add comments while the assessment is active. After the assessment is cancelled, existing comments and work notes remain visible but read-only.
      • Cancel assessment -- If an assessment is no longer needed, you can cancel it to terminate its progress. Once canceled, the assessment becomes read only.
      • Add a comment or work note to a question -- In SAE, post a comment or a private work note on a specific question in an assessment so that reviewers and contributors can discuss the question.
      • Flag or resolve a question -- In SAE, flag a question on an assessment to indicate that it needs attention. After the response is updated, mark the question as resolved or remove the flag.
      • Copying responses from previous assessments -- You can copy responses from previous assessments to save time and reduce repetition.
      • Combining assessments and copying responses -- You can combine multiple assessments assigned to you into a single, streamlined view, enabling you to submit or reassign them all at once. You can also copy your response from one assessment and apply it to the other assessments. This feature enables you to work on all the assessments together more efficiently.
      • Submit combined assessments -- Combine your Smart Assessment Engine assessments so you can respond to all of them together. You can also configure your responses to replicate automatically across all applicable assessments so you don't need to fill them in manually.
      • Collaboration in assessments -- Collaboration in Smart Assessment Engine enables you to add multiple contributors to an assessment and support live collaboration with real-time updates. It also displays presence indicators to show who is active on the assessment.
      • Manage assessment contributors -- The assessment owner can add or remove contributors to an assessment, assign them either full assessment access or section-specific access based on their responsibilities and expertise. Contributors can work simultaneously on the assessment, enabling real-time collaboration and efficient progress.
    • Now Assist -- Use the ServiceNowNow Assist for Smart Assessment Engine application to empower your teams to draft assessment responses by reusing previously answered questions from classic and smart assessments along with supporting documents. Quickly understand record context, reduce manual effort, and respond to assessments faster.
    • Explore -- The Now Assist for SAE application uses generative AI to streamline key Smart Assessment Engine tasks such as automatically drafting assessment responses by analyzing context, reusing previously answered questions, and supporting documents.
      • Smart assessment response assist skill -- The GenAI-powered Smart Assessment Response Assist skill automatically drafts answers by using past smart assessments, classic assessments, and supporting documents.
    • Configure -- Configure Now Assist for SAE to enable generative AI skills for the assessment response assist workflow.
      • Activate smart assessment response assist skill -- Activate and configure the smart assessment response assist skill in Now Assist to automatically draft responses for assessment questionnaires by using previously answered questions, contextual data and supporting documents, enhancing accuracy, reducing redundancy, and maintaining consistency across assessments.
      • Create an assessment template category -- Create an assessment template category in the Smart Assessment Engine application so that you can organize and grant access to the assessment templates that are related.
      • Customizing AI Response Assist sources with a scripted extension point -- The Smart Assessment Response Assist skill refers to previous assessments and documents to generate suggestions. By default, the skill uses scope-based matching for previous assessments and the files attached to the assessment instance for documents. To use different sources for a specific template category, implement the Smart Assessment Response Assist scripted extension point.
    • Use generative AI skills -- Use the generative AI skills that are supported by the Now Assist for SAE application for quickly drafting the assessment responses.
    • Reference -- Reference topics provide the detailed descriptions of tables, properties, forms, and roles that are installed with the Smart Assessment Engine application.
    • Components installed with Smart Assessment Engine -- Several types of components are installed with activation of the Smart Assessment Engine plugins, including tables, user roles, and scheduled jobs.
    • Trigger Smart Assessment flow action -- Use the Trigger Smart Assessment flow action in Workflow Studio to generate and assign assessments from a published Smart Assessment Engine template.
    • Settings in the Test action pop-up window -- You can select Test on the Trigger Smart Assessment action form to test the design of an Smart Assessment Engine assessment. You then specify the settings for the test in the Test action pop-up window.
    • Trigger Smart Assessment action form -- Use the Trigger smart assessment action form to add assessment actions to a flow or to obtain a code snippet for a script as part of the process for triggering Smart Assessment Engine assessments.
    • How legacy metric types are migrated to sections in templates -- Legacy metric types are migrated to specific sections in the assessment templates in the Smart Assessment Engine application.
    • Results of migrating a metric category to an assessment template -- You can view the data that was migrated from the metric type to the Smart Assessment Engine assessment template in the related lists on the Assessment template migration form.
  • Third-party Risk Management -- The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.
    • Explore -- The Third-party Risk Management application centralizes and standardizes the processes, source materials, responsible persons, and methods of your third-party risk management program. You can improve your operations by managing your portfolio of third parties and by identifying, tracking, and mitigating the issues that arise with third parties.
    • Risk profile -- A risk profile is a comprehensive assessment of the potential risks that are associated with a particular third party. To generate a risk profile, you evaluate and document several aspects of the third party's operations, practices, and relationships. The aim is to understand the level of risk they may pose to your organization.
    • Why conduct due diligence -- Conducting due diligence on third parties is a crucial component of your comprehensive third-party risk program. You conduct due diligence to become aware of the risks that are associated with a third party so that you can confidently decide how to form your relationship.
      • Types of due diligence -- In the due diligence process, you typically conduct several types of due diligence to gather relevant information and assess various aspects of the third party. The particular types of due diligence that you conduct vary depending on the nature and criticality of the engagement and the risks involved.
    • Reasons for multiple engagements with one third party -- While onboarding a particular third party, you might conduct a separate engagement for each distinct type of relationship that you have with the third party. One engagement is to assess the risk involved in the third party's development of software for your organization and a separate engagement is for the facilities management service that they provide.
      • Types of engagement with third parties -- The particular third-party engagements that you might have depend on your industry, size, and operational requirements. Each engagement brings its own set of risks and requires appropriate risk management measures (due diligence) to protect your interests.
    • Regulations that affect third-party risk -- When implementing your third-party risk management program, you must carefully consider the regulations. Applicable regulations vary depending on your industry, geographic location, jurisdiction, and nature of your operations.
    • Benefits of your TPRM program -- A third-party risk management program can help you to proactively identify, assess, and mitigate the risks that are associated with your relationships with third parties. By effectively managing third-party risks, you can enhance your overall resilience, protect your interests, and create sustainable and trustworthy business relationships.
    • Onboarding third party example -- Acme, a large manufacturing company, is in the process of onboarding a new third party to supply critical components for their production line. To help ensure the third party's reliability and to mitigate potential risks, Acme starts a thorough third-party risk management onboarding process.
    • Due diligence workflow -- The Third-party risk management (TPRM) processes provide a consistent framework for your third-party risk management program. You can customize the workflow processes to meet your organization's needs.
    • Smart Assessment Engine -- With the integration of Smart Assessment Engine (SAE), TPRM now supports both the Classic assessment engine and SAE. You can create questionnaire templates and add instructions, questions, and reference information by creating templates using SAE in the Vendor Management Workspace.
    • Software bill of materials (SBOM) -- Third-party Risk Management (TPRM) collects software bill of materials (SBOM) files through engagement-level due diligence. This topic covers the users and workflow involved.
    • AI-assisted questionnaire pre-fill -- Use the Document Management System (DMS) with the Smart Assessment Engine (SAE) to automatically generate draft responses for third‑party risk assessment questionnaires using vendor documents and previously answered assessments.
    • Configure -- You can activate or upgrade TPRM, by downloading the applications from the ServiceNow Store and then configuring the settings to meet your needs.
    • Assign roles to users and groups -- Assign roles to users before you implement or use the Third-party Risk Management application. Assigning roles in a well-organized manner simplifies and improves process management and helps to ensure that users are promptly notified of tasks in their areas of responsibility.
    • Add users to groups -- Assign users to groups before you implement or use the Third-party Risk Management application. Each group contains users with particular roles. Well-organized user groups simplify and improve process management and help to ensure that users are promptly notified of tasks in their areas of responsibility.
    • Configure properties -- Configure property settings for a variety of TPRM operations.
    • Enable risk concentration map -- After you install the Risk concentration map feature, you must install a Google license to enable the feature.
    • Enable email with third-party contacts -- Configure email communication with third-party contacts to enable email notification of assessments and issues.
    • Update email notification header and footers -- Update the header and footer images used in email notifications by modifying image records for Third-party Risk Management.
    • Import existing data -- Import existing data (third parties, engagements, assessments, questionnaires, issues, and so on) from other systems (like the Aravo platform, the ProcessUnity platform, and so on). You aren’t charged for importing the data.
    • Configure related lists for vertical navigation on record pages -- Configure the related lists that appear in the vertical navigation layout on record pages in the Vendor Management Workspace.
    • Run quick start tests -- Verify that TPRM still works after you make configuration changes such as applying an upgrade or developing an application. Copy and customize the quick-start tests to pass when using your instance-specific data.
    • Classic assessments -- The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure additional settings that enable and enhance everyday risk-assessment tasks.
      • Risk rating scales for scoring -- The risk rating scale helps business users better understand risk assessment results. For example, in the default settings, risk scores in the 20 through 39 range indicate high risk, while scores in the 60 through 79 range indicate low risk.
      • Third-party risk domains -- A risk domain defines the type of risk to assess for a third party. For example, you might want to assess a data-management third party in terms of security risk and a bank in terms of financial risk. Security risk and financial risk are risk domains. Some platform applications refer to risk domains as "risk areas."
      • Third-party risk area criteria -- A third-party risk area criteria is a group of risk domains (sometimes called risk areas in other platform features) that applies to a particular type of third party.
      • Component criteria -- Components are the entities for which you can assess risk (for example, subsidiaries or engagements). A component criteria is a group of components that should apply to a particular type of third party or engagement.
      • Third-party risk scoring rules -- Define criteria, based on risk scores, that determine which third parties require assessments. Third-party risk scoring rules apply to subsidiaries and engagements and to third-party risk areas.
      • Engagement risk scoring rules -- An engagement risk-scoring rule specifies component criteria that determine which engagements are selected for assessment. For example, a rule could enable assessments for engagements that involve more than $40,000 annual business. Engagement scoring rules apply only to engagements.
      • Event-driven management rules -- Use the Event-driven management feature to configure rules that auto-generate and send questionnaires and doc requests to engagements and third parties. For engagements and third parties that meet the criteria you define, you specify the schedule and the assessment templates. You can automate all assessment types except onboarding.
      • View the run history -- When an event-driven management rule runs, it auto-generates and sends questionnaires and doc requests to third parties. You can view the current state (running, successful, or recalled) of all runs of rules. Select a record number to view details and to view the set of assessments generated by the rule.
      • View generated assessments -- When an event-driven management rule runs, it auto-generates and sends questionnaires and doc requests to third parties. You can view the current state (running, successful, or recalled) of all runs of rules. Select a record number to view details and to view the set of assessments generated by the rule.
      • Recall event-driven questionnaires and doc requests -- You can recall third-party risk assessments (questionnaires and document requests) that were sent by an event-driven management rule. The items are removed from the Third-party portal for all third parties or engagements that haven’t yet responded.
      • Normalize scores for metrics -- You can use the Maximum normalization input setting to use normalized values to calculate assessment scores for questions (metrics).
      • Set up a question bank -- After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system.
      • Define a question -- After you add a question to a question bank, you can reuse it in any assessment by dropping it into the assessment. You can create custom questions, add existing questions, or add and customize the sample questions that are included with the base system.
      • View the sample questions -- TPRM includes sample questionnaires that you can use to define questionnaire templates for your organization.
      • Create an external assessment template -- When defining an assessment template, the third-party risk manager provides scheduling information for the third-party risk assessment.
      • Configure a scheduled risk assessment -- Configure a third-party risk assessment to recur on a schedule to regularly update risk results for a third party or an engagement.
      • Import a questionnaire from a spreadsheet -- If you maintain questionnaires using Microsoft Excel spreadsheets, you can save time and effort by importing your spreadsheet data directly into TPRM tables. You can then create questionnaires automatically from templates.
      • Create a questionnaire or document request template -- You can reuse questionnaire templates and document-request templates to speed up the creation of new questionnaires and document requests.
      • Create templates using the designer -- Use the Questionnaire Template Designer to create and edit questionnaire or document request templates that you can use as the basis for other templates.
      • Create an issue generation rule -- Create an issue generation rule that will automatically create an issue based on question responses to external assessments. Issues help ensure that your concerns about a third party or engagement are remediated.
      • Set up internal responses to attach external questionnaires to assessments -- Set up an internal questionnaire's responses to automatically attach questionnaires to external assessments that are based on the responses, the calculated risk tier, or both by using Third-party Risk Management. By setting up this configuration, you can help to improve your ability to respond to risk tier changes and internal questionnaire responses.
    • Smart Assessment Engine assessments -- The TPR manager and TPR admin roles involve a broad variety of responsibilities. After the TPRM base system is set up, you configure Smart Assessment Engine specific settings as well as other assessment settings that enable and enhance everyday risk-assessment tasks. TPRM admins can enable SAE and work with SAE templates.
      • Migrating from Classic Assessment Engine to Smart Assessment Engine -- Learn what changes when you migrate from the Classic Assessment Engine to the Smart Assessment Engine, including feature differences, limitations, and setup requirements. This overview can help you and your team evaluate the impact before enabling the new engine.
      • Migrate templates to SAE format -- Migrate an existing questionnaire or document request template to a TPRM SAE questionnaire template. You must migrate all classic templates to TPRM SAE templates or create new ones before you can use SAE in TPRM.
      • Create a TPRM SAE questionnaire or document request template -- Create a TPRM SAE questionnaire or document request template that supports SAE for risk identification. After integrating SAE, new users must create SAE templates, and existing users can create additional templates after migrating their existing ones.
      • Managing TPRM SAE templates with Unified Content Management -- Use Unified Content Management (UCM) as a centralized, managed repository of pre-built smart assessment templates for Third-party Risk Management. With UCM installed, TPR managers can browse, preview, and activate templates for assessments, and update templates when newer versions are released.
      • Activate or update Smart Assessment templates -- Manage SAE templates for TPRM from the Unified Content Management page in the Vendor Management Workspace. You can view available templates, select template versions, activate or update templates for use in Third-party Risk Management assessments, and update templates when newer versions are released.
      • Activate SBOM -- Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).
      • Configure AI-assisted questionnaire pre-fill for TPRM -- Turn on AI-assisted questionnaire pre-fill for a smart assessment template category by selecting the Is AI response enabled check box.
    • Integrate -- Extend the capabilities of TPRM.
    • TPRM with Policy and Compliance Management -- The GRC: Policy and Compliance Management integration updates the compliance status of controls and control objectives based on the questionnaire responses from a third party or engagement. Compliance managers [sn_compliance.manager] can associate controls and control objectives with specific questions, third parties, and engagements used in Third-party Risk Management.
      • Add a control -- If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate controls with third parties and engagements. Controls can be marked as compliant or non-compliant.
      • Create new control form -- Use the create new control form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application.
      • Add a control objective -- If you’re using both Policy and Compliance Management and Third-party Risk Management, you can associate control objectives and controls with questions. Controls can be marked as compliant or non-compliant based on the response to the question.
      • Control objectives form -- Use the control objectives form to capture all the information that you need to associate a control objective with a question using the Third-party Risk Management application.
    • TPRM with Risk Management -- Integrating Risk Management with Third-party Risk Management lets you model enterprise risks and use third‑party assessments to dynamically update risk posture and scores for third parties and engagements. Optional TPRM rules can trigger assessments or remediation work when risks change.
      • Add a risk -- If you’re using both Risk Management and Third-party Risk Management, you can associate risks and risk statements with third parties and engagements. These associations influence risk posture and scoring.
      • Create new risk form -- Use the create new risk form to capture all the information that you need to associate a control with a third party or engagement using the Third-party Risk Management application. As a third-party risk admin, you can create a control.
    • Scores from risk intelligence providers -- Risk intelligence providers generate risk scores for a variety of third-party risk domains. Your organization can purchase services from providers that return data that is analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.
      • Register a risk intelligence provider -- Create a record for each risk intelligence provider from which you’ll request reports. The risk scores and ratings that risk intelligence providers generate are analogous to personal credit scores. The scores provide insight on how trustworthy and safe a particular third party can be.
      • Set up a risk intelligence provider service -- After you register a risk intelligence provider, you specify which of the provider's scoring or rating services you’ll use. You also specify how their scores or ratings map to your TPRM ratings.
      • Set up a provider request type -- After you register a risk intelligence provider and service, you specify the available request types that you and your organization will use.
      • Add a risk intelligence score to a third party -- You add a raw score from a provider to the provider service record for a third party. The system uses the mapping that you specified to normalize the value to the appropriate TPRM rating.
      • Automate actions upon risk intelligence updates -- A provider-based submission rule is a set of conditions and actions. In a rule, you can specify that an update to a rating from a risk intelligence provider is the condition that triggers the action that is specified in the rule. The action might be to create and send a third-party risk assessment, issue, task, or email.
    • TPRM with EcoVadis -- Integrating EcoVadis into your third-party risk management program can enhance your ability to assess and mitigate risks associated with sustainability and corporate social responsibility (CSR). By leveraging EcoVadis' comprehensive sustainability ratings, you can gain detailed insights into the environmental, ethical, and social practices of your third parties.
      • Create an EcoVadis connection and configuration -- Create a connection to fetch and update scores from EcoVadis to help ensure that your risk and theme scores remain current when using Third-party Risk Management.
      • Customize EcoVadis system properties -- You can optionally customize the default values of the sn_ecovadis.token_uri and sn_ecovadis.score_uri system properties. These properties manage tokens and access risk scores from EcoVadis when using Third-party Risk Management.
      • View EcoVadis scores -- Retrieve current scores and scorecards from EcoVadis on demand or at a set frequency of time using Third-party Risk Management. Customizing settings for the EcoVadis Fetch Score Scheduler can help you get the latest scores when you need them.
    • Risk intelligence providers -- The Third-party Risk Management application includes support for risk intelligence provider integrations. These guidelines can help your organization to develop a risk intelligence provider integration for Risk intelligence report (RIR) requests for third parties and due diligence requests.
    • Request due diligence -- Request third-party risk due diligence to determine the level of risk for interactions with a third party, engagement, or fourth party by using Third-party Risk Management. You conduct due diligence to become aware of the associated risks so that you can make informed decisions, establish appropriate controls, and mitigate the potential negative impact when working with external parties.
    • Request engagement due diligence -- Request due diligence to assess the risk that is associated with doing business with an engagement. By conducting due diligence, you gain access to the most up-to-date, comprehensive, and accurate information before making a decision on entering into a business relationship.
    • Offboarding engagements without due diligence -- Request that an engagement be permanently terminated when an engagement ends or you want to switch to a different third party for other reasons. In this case, you typically don't need to conduct additional due diligence. The process does, however, include the normal Inherent Risk Questionnaire (IRQ) process to confirm that the services provided by the engagement will no longer continue.
    • Assess third-party risk -- Use Third-party Risk Management to identify and assess potential risks that are associated with your third-party relationships. The information gathered from internal questionnaires, external questionnaires, and documentation requests helps you to understand the third party's risk profile, determine the appropriate risk mitigation strategies, and determine whether the third party or engagement meets all necessary compliance requirements.
    • Create internal assessments -- Create an internal assessment as part of a due diligence request or ongoing risk monitoring using Third-party Risk Management. An internal assessment can affect which questionnaires are later sent to the third party or engagement.
    • Respond to internal assessments -- Respond to an Inherent Risk Questionnaire (IRQ) or internal assessment that has been assigned to your queue. Your responses to the questionnaire help determine if the process moves forward and can affect which questionnaires are sent to the third party or engagement.
    • Create external assessments -- Create an assessment and initiate the third-party risk assessment life cycle using Third-party Risk Management. An external assessment specifies the details for the third party or engagement and defines the plan for completing the assessment.
    • Respond to questionnaires for a third party or engagement -- Answer questions, modify responses, or submit external questionnaires for a third party or engagement by using Third-party Risk Management. You can save valuable time by responding for a third party or engagement when they have already provided the required information for a previous questionnaire.
    • Generate AI-assisted draft responses in a TPRM assessment -- Use the Smart Assessment Response Assist skill to generate draft responses for assessment questionnaires using vendor documents from the Document Management System (DMS) and previously completed assessments.
    • Review responses to external questionnaires -- Third-party contacts use the Third-party portal to complete assessments and collaborate with the TPR manager in the comments section for each question. When assessments reveal gaps, the TPR manager or the TPR assessor can generate an issue or task. In addition, the Vendor Management Workspace application can auto-generate issues.
    • Reopen an assessment -- Reopen an assessment to send out more questionnaires and document requests to collect required additional information from the third party or engagement.
    • Create an issue -- Create an issue to help ensure that your concerns about a third party or engagement are remediated.
    • Manage issues -- Verify that an issue that is associated with a risk assessment is understood, communicated to the appropriate persons, and is acted on as needed.
    • Create a task -- Create a task to help ensure that a user at your organization or the third-party contact responds to your concerns about questionnaire responses or requested documents during the due diligence process.
    • Manage a task -- Verify that the Assigned to user at your organization or the third-party contact responds to a task and update the state of the task as needed.
    • Export responses to a spreadsheet -- Export received or returned questionnaires to Microsoft Excel spreadsheets. This option enables you to use the spreadsheet environment to review questions and answers.
    • Collecting software bill of materials -- A software bill of materials provides an inventory of the components, libraries, and dependencies included in a vendor's software. Third-party Risk Management (TPRM) supports collecting SBOM files as part of the due diligence process.
      • Request SBOM -- Turn on SBOM collection on a due diligence request and send the external assessment to collect SBOM data from an engagement contact.
      • Review SBOM submission -- Track processing status and review the outcome of a SBOM submission from an engagement, including successful upload, failed upload, and decline.
    • Monitor third-party risk -- You can monitor the potential risks that are associated with your third-party relationships by using the Third-party Risk Management application. An ongoing monitoring process can help you regularly assess the third party's performance and adherence to the agreed-upon terms.
    • Overview of a third party -- Use the third party page to access all current information and status for a third party.
      • Viewing summarized third party risk information -- The Risk overview tab displays third-party name and process information, summary reports, risk intelligence scores, and tracking data for issues and tasks. On most reports, you can select an item to view the underlying data.
      • Viewing general third party information -- The Details tab displays overview and process tracking information and offers actions for managing the third party or engagement. On most reports, you can select an item to view the underlying data.
      • Viewing third-party subsidiary risk information -- The Subsidiaries tab displays overview information on subsidiaries of the third party. On most reports, you can select an item to view the underlying data.
      • Viewing fourth-party information -- The Downstream suppliers tab displays overview information on fourth parties that the third party engages with. On most reports, you can select an item to view the underlying data.
      • Viewing risk intelligence scores -- For DD requests, risk intelligence scores appear in a list. For an individual third party, a card displays the most recent score or rating and a link for each risk intelligence report.
    • Overview of an engagement -- Use the engagement page to access all current information and status for an engagement.
      • Viewing summarized engagement risk information -- The Risk overview tab displays engagement name and process information, summary reports, risk intelligence scores, and tracking data for issues and tasks. On most reports, you can select an item to view the underlying data.
    • Viewing third-party risk reports -- Use the Risk tab on the Vendor Management Workspace to access and prioritize activities such as managing your portfolio of third parties, assessing third-party risk, and completing the remediation life cycle. The workspace enables automation that reduces the manual burden and costs of risk assessment.
      • TPRM Home page -- The home page displays reports of important risk information and provides quick access to actions for TPR managers and TPR assessors.
      • TPRM Due diligence management reports -- TPR managers and assessors use the due diligence management reports to track, prioritize, and manage their responsibilities.
      • TPRM Risk activity page -- The Risk activity page enables you to quickly identify assessments, issues, and tasks that need attention.
      • TPRM Dashboards page -- The dashboards page displays the Third-party insights dashboard and TPRM custom analytics dashboard as well as any other dashboards you and your team create.
      • TPRM Risk concentration map -- The Risk concentration map page pinpoints the geographical locations of active third parties and engagements. You can configure filters to view particular risk ratings and engagement types.
      • TPRM Task page -- The task page gives you access to tasks that are assigned to you and to members of your group. You can further filter the lists of tasks by due diligence requests, type of third-party action, and by risk or tiering assessment.
      • TPRM Unified content management page -- The unified content management page provides access to a centralized library of smart assessment templates. You can use this library to activate ready‑to‑use questionnaires aligned with global regulations and industry standards, helping ensure consistent and comprehensive assessments.
      • TPRM List page -- The List page is a general-purpose page that enables access to all items that you can view or act on in TPRM.
    • Monitor data using dashboards -- You can monitor and analyze assessment data at various levels in the Third-party Risk Management application using the Third-party insights dashboard and TPRM custom analytics dashboard. These dashboards provide you and your team with tailored insights and deliver relevant information at a glance, improving your decision-making process.
      • Create a TPRM dashboard -- You can create dashboards with data visualizations, filters, and other elements that you can share with others. You can create elements and add existing elements from the in-line editor.
      • Edit TPRM dashboard details -- You can change a dashboard name, add a description, certify it, configure visibility, and specify the requester, the owner, the owner group.
      • Edit TPRM dashboards -- You can edit dashboard and dashboard tab information in the in-line editor. If the dashboard has been shared, any changes you make are applied globally.
      • Edit TPRM dashboard elements -- You can edit the contents of a dashboard or dashboard tab, including data visualizations and filters. Because dashboards are shared, any changes you make are applied globally.
      • Share a TPRM dashboard -- Share a dashboard with other users, groups, or roles to create a shared view of data that you can use to collaborate. You can grant viewing permissions or both viewing and editing permissions.
      • Delete a TPRM dashboard -- You can delete a dashboard that is no longer useful. The Analytics Overview invokes the Workflow Studio to remove the dashboard from your instance.
    • Monitoring the due diligence request process -- TPR managers and TPR admins can perform a wide variety of tasks from the due diligence management dashboard. They can work on all processes in the workflow for a due diligence request: IRQs, external due diligence, approval, contract risk, and closed requests.
    • Monitoring your fourth-nth parties -- You can identify and manage the third-party risks that depend on the services of the fourth-nth parties by using the Third-party Risk Management application. By monitoring your fourth-nth parties, you can help to ensure that they adhere to the same security and compliance standards as the primary third party.
      • Register a fourth-nth party -- Register fourth-nth parties after collecting responses from a third party by using the fourth-party registration questionnaire in the Third-party Risk Management application. With the fourth-party registration questionnaire, you can create multiple fourth-nth party records at a time.
      • Create a fourth-nth party record -- Create a fourth-nth party record by using the Third-party Risk Management application. You can create fourth-nth party records manually as an alternative to using a fourth-party registration questionnaire.
      • Promote a fourth-nth party to a third party -- Promote a fourth-nth party record to a third party by using the Third-party Risk Management application. If you’re now working with a fourth-nth party at the third-party level, you can keep relevant information current by promoting a fourth-nth party record to a third-party record.
    • Monitoring third-party elements -- You can monitor third-party elements through scalable scoring models, relationship analysis, and due diligence workflow integration by using the Third-party Risk Management application. Monitoring third-party elements and leveraging that information can help with conducting more informed risk assessments as part of your third-party risk program.
      • Create a third-party element record -- Create a third-party element record after you collect the responses from a third party by using a collection template questionnaire in the Third-party Risk Management application. Third-party element records are assessed directly as part of the due diligence workflow.
      • Add a third-party element record to an engagement -- Assign a third-party element record to an engagement by using the Third-party Risk Management application. After you assign the element record to an engagement, the third-party risk manager and internal stakeholders can assess it as part of the due diligence process.
    • Tracking a managed activity -- View managed activities in the usage analytics activities table for tracking and verification purposes in the Third-party Risk Management application.
    • Approve or reject due diligence requests -- Set up the approval levels and rules for due diligence requests in the Third-party Risk Management application to use while approving or rejecting requests after reviewing questionnaire responses and due diligence process results.
    • Set up the approval levels for DD requests -- Assign one or more approval levels to the users or groups that approve your due diligence requests in the Third-party Risk Management application. Because the approval levels are applied iteratively and each level contains different rules, you can help to ensure that the correct user or group is assigned as an approver.
    • Set up the approval rules for DD requests -- Set up the rules at each approval level for your due diligence requests by selecting an approver type and the number of approvals that you require in the Third-party Risk Management application. You can also filter the table conditions that apply to each rule so that you can help ensure that the correct user or group is assigned as an approver.
    • Manage the contract process -- Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.
    • Accessing DD requests in the contract risk process -- You can view the contracts associated with each engagement or third party and alongside detailed information such as the expiration, start date, end date, and state. You can also manage and update contract processes.
    • Now Assist -- Use the ServiceNow Now Assist for Third-party Risk Management (TPRM) application to empower your risk management teams with generative AI-powered capabilities to automate and streamline data collection enabling teams to efficiently gather, validate, and report on third-party risk information.
    • Exploring -- With the Now Assist for Third-party Risk Management (TPRM) application, you can use skills to automate the collection of TPRM risk data.
      • Issue summarization skill -- The issue summarization skill in Now Assist for Third-party Risk Management (TPRM) uses generative AI to create concise summaries of vendor-related issues, helping assessors quickly review risk details, improve consistency, and accelerate remediation.
      • Issue recommendation skill -- The issue recommendation skill in Now Assist for Third-party Risk Management (TPRM) uses generative AI to suggest potential issues based on historical assessment data, helping assessors and reviewers identify relevant risks more efficiently while retaining control over which issues are created.
      • Supporting information -- Get a quick overview of the important information that is related to the Now Assist for Third-party Risk Management (TPRM) application.
    • Configure -- If you have the admin role, you can configure the Now Assist for Third-party Risk Management (TPRM) application so that agents can use the generative AI capabilities in Vendor Management Workspace and Core UI.
      • Activate issue summarization skill -- Activate the TPRM summarization skill from Now Assist for TPRM to generate a brief summary of a TPRM issue by selecting the specific fields that you would like included in the summary.
      • Activate issue recommendation skill -- Activate the TPRM issue recommendation skill from Now Assist for TPRM to generate recommendations for TPRM issues.
    • Use generative AI skills -- If you have the TPR assessor [sn_vdr_risk_asmt.vendor_assessor] role, you can summarize a TPRM issue by using the Now Assist for Third-party Risk Management (TPRM) application.
      • Generate a summary of a TPRM issue -- Generate a summary of a TPRM issue to support efficient triaging, remediation, and reporting using the TPRM issue summarization skill. Summarized issues help risk assessors and analysts quickly review issue content and take informed action.
      • Generate TPRM issue recommendations -- Use generative AI to identify and recommend potential Third-party Risk Management issues based on assessment responses. The TPRM issue recommendation skill presents recommended issues with rationalized summaries for reviewer confirmation.
      • Act on the recommendations for issues -- Accept recommendations to create issues based on historical assessment data, or dismiss recommendations that aren’t relevant. Accepting or dismissing issue recommendations helps reviewers efficiently act on AI‑predicted findings while retaining control over which issues are created.
    • DMS system -- Learn how the enhanced Document Management system supports third-party collaboration and internal workflows in Third-party Risk Management (TPRM).
    • Create a document -- Use the Document Management system to create document records in Third-party Risk Management.
    • Create a document version -- Use the document management system to version documents in Third-Party Risk Management (TPRM).
    • Define document sharing permissions -- Controls who can view, edit, or manage a document using the Document Management system in Third-party Risk Management (TPRM).
    • Link documents to a TPRM record -- Use the Document Management system to link documents to assessments, engagements, issues, and tasks for traceability in Third-party Risk Management (TPRM).
    • Use digital resilience third-party registers -- Use the Digital Resilience Third-party Information Register application in the Vendor Management Workspace to create, update, and track assessments, branches, legal entities, and so on, and maintain registers of contractual arrangements with ICT third-party service providers.
    • Create a legal entity and enhance digital resilience data -- Create a legal entity record in Digital resilience third-party registers using Third-party Risk Management. You can then configure digital resilience information for the legal entity such as its name, type, country, and hierarchy.
    • Create a branch and enhance digital resilience data -- Create a branch record in Digital resilience third-party registers using Third-party Risk Management. You can then enhance its digital resilience information for compliance with DORA regulation.
    • Create a function and enhance digital resilience data -- Create a function record in Digital resilience third-party registers using Third-party Risk Management where you can configure details of the function such as function identifier, license activity, function name, criticality, or importance assessment details. You can then enhance its digital resilience information for compliance with DORA regulation.
    • Create a third party and enhance digital resilience data -- Create a third-party record in Digital resilience third-party registers using Third-party Risk Management. Add the details of the third-party company such as its name, address, phone number, vendor manager. You can then enhance its digital resilience information for compliance with DORA regulation.
    • Create an engagement and enhance digital resilience data -- Create a third-party engagement record in Digital resilience third-party registers using Third-party Risk Management. Add details of the third-party engagement such as the name of the third party, its type, annual spend, engagement tier. You can then enhance its digital resilience information for compliance with DORA regulation.
      • Create New Third-party engagement form -- Use the create new third-party engagement form to capture all the information that you need to create a third-party engagement record in Digital resilience third-party registers using Third-party Risk Management. As a third-party risk assessor you can create a third-party engagement record.
      • Add Digital resilience information to engagements -- Add Digital resilience information to third-party engagements by creating ICT third-party service provider records in Digital resilience third-party registers using Third-party Risk Management. Add details such as name of the service provider, its identification code, type of ICT services, currency, and so on. This enhances the digital resilience information of its associated third-party engagement for compliance with DORA regulation.
    • Create a contract and enhance digital resilience data -- Create a contract record in Digital resilience third-party registers using Third-party Risk Management where you add details of the contract such as vendor name, start and end dates, state, substate. You can then enhance its digital resilience information for compliance with DORA regulation.
    • Create a supply chain and enhance digital resilience data -- Create an Information and Communication Technology (ICT) service supply chain record in Digital resilience third-party registers using Third-party Risk Management. You can then configure details of the supply chain such as the type of the ICT services, Legal Entity Identifier (LEI) of the entity that provides the ICT services.
    • Create an assessment and enhance digital resilience data -- Create an assessment of the Information and Communication Technology (ICT) service in Digital resilience third-party registers using Third-party Risk Management. Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.
    • Create a Microsoft Excel download request -- Create a Microsoft Excel download request to download the records from the Digital resilience third-party registers using Third-party Risk Management for auditing purposes.
      • Create New Excel download/upload request form -- Use the Create New Excel download/upload request form to capture all the information that you need to create a download/upload request for Digital resilience third-party registers using the Third-party Risk Management application. As a third-party risk manager or third-party risk assessor you can create an Excel download/upload request record.
    • Create records in bulk -- Create records in bulk from the Digital resilience third-party registers using Third-party Risk Management rather than creating one record at a time for single or multiple entities. You can save time and effort by working on multiple records at a time.
    • Update existing records in bulk -- Update existing records in bulk from the Digital resilience third-party registers using Third-party Risk Management.
    • Register of information regulatory packages -- The Register of Information (RoI) is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.
      • Generate a RoI package -- Use the CSV report option in the download page to generate regulator-ready Register of Information (RoI) packages.
    • Validation framework for RoI -- The validation framework helps ensure that RoI packages meet regulatory requirements defined by the DORA.
      • Validate Register of Information packages -- Run real-time validation on Register of Information (RoI) packages to help ensure compliance with DORA requirements.
      • Validate LEI codes -- Review and resolve Legal Entity Identifier (LEI) validation results for DORA Register of Information reporting. LEI validation runs automatically during Plain-CSV Reporting Package generation and Microsoft Excel upload to verify that LEI codes in the digital resilience registers exist in the GLEIF database and have an active and issued status.
      • Level 4 LEI Validation Report columns -- The Level 4 LEI Validation Report (Level4_LEI_Validation_Report.csv) is generated during Plain-CSV Reporting Package download and lists the validation result for each Legal Entity Identifier (LEI) code found in the reporting package.
    • Currency conversion and third-party total expense aggregation -- During report generation, the Register of Information (RoI) can standardize contract annual expenses by converting amounts to a base currency and aggregating totals per eligible third-party provider or engagement. The RoI is a regulatory reporting requirement under the Digital Operational Resilience Act (DORA) and is supported by the Digital Resilience Third-party Information Register application in the Vendor Management Workspace application.
    • Manage the third-party portal -- Third-party contacts respond to questionnaires, requests for documentation, tasks, and issues on the Third-party portal. The portal is the point of interaction between third parties and risk assessors.
    • Set up third-party contacts -- Set up your third-party contacts so that you can send assessments, address issues, and communicate any additional required information with these contacts using Third-party Risk Management.
    • Manage the access for your third-party contacts -- View your existing third-party contacts and adjust their information and access permissions as needed by using Third-party Risk Management. When you keep the contact details up to date, you can help to avoid your third-party contacts from getting unauthorized access or losing authorized access to the third-party portal.
    • E-signatures on questionnaires or document requests -- Questionnaires or document requests might require electronic signatures of third-party contacts and/or reviewers.
    • Upload and manage documents in the portal -- Use the third-party portal to upload and manage documents for assessments, engagements, issues, and tasks in Third-Party Risk Management (TPRM).
    • TPRM and the Explicit Roles plugin -- Activating the Third-party Risk Management plugin also installs the Explicit Roles plugin. Administrators assign the snc_internal and snc_external roles to provide internal and external users access to the instance.
    • Using a Microsoft Excel spreadsheet template for external questionnaires -- Third parties and engagements can use a Microsoft Excel spreadsheet to respond to questionnaires by downloading the template, completing it, and importing the final version into the Third-party portal. This enables respondents to provide information outside the third-party portal.
      • Respond using a Microsoft Excel template -- Use a Microsoft Excel template to respond to questionnaires by downloading the template, completing it, and importing the final version into the Third-party portal. The Microsoft Excel questionnaire template contains instructions for filling out the template.
    • Using the SIG questionnaire for a risk assessment -- Third parties can use the Shared Assessments Standardized Information Gathering questionnaire (SIG) to provide assessment documentation in the Third-party Risk Management application. The third-party contact can upload the pre-filled SIG spreadsheet or respond to a form-based questionnaire that is imported to the instance.
      • Respond using the SIG -- Use the Shared Assessments Standardized Information Gathering questionnaire (SIG) to provide assessment documentation on the third-party portal. You can upload the pre-filled SIG spreadsheet or import a form-based questionnaire.
    • Use risk intelligence reports and scores -- Request risk intelligence reports or scores directly from your external risk intelligence content providers by using the Third-party Risk Management application. This information can be requested and managed based on the importance or risk level of the individual third party.
    • Request a RI report -- Request a risk intelligence report (RIR) or score to gain insight on how trustworthy a particular third party can be using the Third-party Risk Management application.
    • Request a RI report associated with a DD request -- Request a risk intelligence report (RIR) or score to gain insight on how trustworthy a particular third party can be as part of the due diligence request process by using the Third-party Risk Management application. By associating your RIR request with a due diligence request, all activity, scores, reports, and details are available for you to see.
    • Track sanctions-related information -- Track sanction-related information as part of requesting risk intelligence reports and scores by using the Third-party Risk Management application. Logging and updating sanctions-related information for third parties keeps your team informed as you conduct due diligence as part of your third-party risk program.
    • Reference -- Reference topics provide detailed descriptions of tables, properties, forms, and roles that are installed with the Third-party Risk Management application.
    • Terminology -- Learn more about the key concepts and terms that are used in the TPRM application.
    • Roles in TPRM -- Roles determine permissions and access in TPRM.
    • Unique ID numbers for TPRM records -- When you create (or the system generates) a new record (for example, a request for due diligence or a task), the system auto-assigns a unique ID number that helps to identify the type of data in the record. You can use the ID number to search for or filter the item you want to work on.
    • Results of migrating a template to a TPRM SAE template -- You can view the templates that were migrated to Smart Assessment format.
    • Guidelines for importing spreadsheet data -- Before you try to import the questionnaire data from a Microsoft Excel spreadsheet into Third-party Risk Management tables, you must verify that its format meets particular guidelines.
    • Sample questionnaires -- The questionnaire that you use can depend on your industry, geographic area, jurisdiction, or the particular nature of your operations. These questionnaires are provided as part of the base system and are samples that shouldn’t be implemented into your risk management program without first being reviewed and approved by your legal team.
    • Due diligence request process management -- From the Details tab, you can view and adjust the due diligence request information for a third party. You can also log external-facing comments and private work notes, attach files, and track request updates in the activity stream.
      • Request third-party risk due diligence request form -- The due diligence request form captures all the initial information that you need to start the due diligence process. Any employee within your organization can request due diligence. If you’re selecting an existing third party, a significant portion of the information is automatically filled in.
    • IRQ process management -- The first internal step after an engagement request is approved is to start the IRQ process to scope the risk by determining the third party's risk score.
      • Create new internal assessment form -- Use the internal assessment form to capture all the information that you need to create an internal assessment. As a third-party risk assessor, you can create an assessment template.
    • Third-party (external) risk assessment management -- After the IRQ process is complete, you send questionnaires and document requests to the third-party contact. You manage the third-party risk assessment by working with the contacts to help ensure that the responses are complete and accurate.
      • External assessment lifecycle states -- The process of collecting assessment data from a third party moves through several states. For example, during the Submitted to third party state, the third party responds to tasks, issues, and works to complete the questionnaires.
      • Assessment metric type form -- Use the assessment metric type form to capture all the information that you need to create a questionnaire template using the Third-party Risk Management application. As a third-party risk admin, you can create a questionnaire template.
      • Create new external assessment template form -- Use the external assessment template form to capture all the information that you need to create an external assessment template. As a third-party risk manager, you can create an assessment template.
      • Create New TPRM SAE questionnaire template form -- Use the Create New TPRM questionnaire template form to capture all the information that you need to create a TPRM SAE questionnaire template using the Smart Assessment template designer. As a third-party risk admin, you can create a questionnaire template.
      • Third-party risk assessment form -- Use the third-party risk assessment form to capture all the information that you need to create an assessment using the Third-party Risk Management application. As a third-party risk assessor or manager, you can create an external assessment.
      • Third-party element form -- Use the third-party element form to capture all the information that you need to create a third-party element record using the Third-party Risk Management application. As a third-party risk manager, third-party risk assessor, or due diligence request owner, you can create a third-party element record.
    • Approval process management -- You can view the list of users who can approve or reject a DD request and also view the details of their approval actions. In addition, you can view the approval levels for a request.
      • Approval rule form -- The approval rule form captures all the information needed to create an approval rule. An admin or third-party risk admin can create an approval rule.
    • Risk intelligence report requests management -- You can view a list of risk intelligence report (RIR) requests, their associated providers, scores, and report URLs. In addition, you can create requests and make updates by using the Third-party Risk Management application.
      • Risk intelligence report request form -- Use the risk intelligence request form to capture all the information that you need to request risk intelligence using Third-party Risk Management. As a third-party risk manager, third-party risk assessor, and contract negotiator that is assigned to the due diligence request, you can request risk intelligence.
    • Scoring calculations using the classic assessment engine -- Perform a comprehensive external risk assessment when calculating multiple ratings and scores by using the Third-party Risk Management application. You can gain a deeper understanding of the overall calculation process and learn how user-defined parameters and configurations influence the results of the questionnaires.
      • Verifying scoring calculations using the classic assessment engine -- You can review scores and risk ratings in your questionnaires to help ensure the accuracy and consistency of risk scoring by verifying the correct application of weights, normalized values, scoring methods, and risk rating scales. Based on the different weights you assign, Third-party Risk Management aggregates these values and produces a composite score.
    • Third-party risk management data model -- Use the Third-party Risk Management (TPRM) data model to assess, monitor, and mitigate the risks for your risk management program.
    • Domain separation and Third-party Risk Management -- Domain separation is supported for TPRM. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Vendor Risk Overview reports — Legacy view -- The Vendor Risk Overview page is replaced by the third-party risk reports on the Vendor Management Workspace.
  • Common GRC features -- Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.
    • Now Assist -- Use the Now Assist for Integrated Risk Management (IRM) plugin to summarize issue records, identify potential risks, and review controls using generative AI. It helps you quickly understand the context of records, reduce manual effort, and make faster, more informed decisions by delivering relevant insights directly within your existing workflows.
    • Explore -- With the Now Assist for Integrated Risk Management (IRM) application, you can use generative AI to support key IRM tasks such as summarizing issues, identifying risks, and reviewing controls. These capabilities are integrated into IRM records and help streamline how you work with issues, risks, controls, policy exceptions, and more.
      • AI-driven regulatory alert summarization skill -- The AI-driven summarization feature is designed to provide concise, AI-driven overviews of regulatory alerts directly within the regulatory alert record in the Compliance Workspace. It offers contextual information, including important dates, regulatory authority details, and key changes, helping users to better respond to new alerts.
      • AI-generated recommendations for a regulatory alert skill -- The recommendations framework is designed to deliver actionable, AI-driven insights directly within the user interface. It provides rich contextual information about recommendations, empowering users to make well-informed decisions and take follow-up actions seamlessly. The scalable and flexible design supports multiple recommendation types and complex business scenarios.
      • Control Objective Impact Analyzer skill -- Explore the Control objective impact analyzer skill that evaluates citation updates and determines which associated control objectives require attention.
      • Control Objective Change Agent -- Learn how Control Objective Change Agent automates and streamlines updates to control objectives, ensuring compliance data remains accurate and consistent with user oversight.
      • Issue Summarization skill -- Use the Issue Summarization skill to view a concise summary of an issue based on its life-cycle data. The skill analyzes the issue’s context and generates a short, readable overview that includes key details such as status, actions, and relevant metadata. This helps you quickly understand the issue without reviewing the full record.
      • Get regulatory analysis workflow -- The get regulatory analysis workflow provides AI-driven insights into regulatory alerts, identifying impacted areas, compliance gaps, and recommended actions for risk mitigation.
      • Generate regulatory action plan workflow -- The generate regulatory action plan workflow uses generative AI to create actionable compliance steps for regulatory alerts. It supports organizations in organizing risk mitigation activities and maintaining alignment with regulatory requirements.
      • Suggest potential risks workflow -- The Suggest potential risks workflow uses AI to identify and consolidate risks from multiple sources. It replaces manual, workshop-based risk discovery with a faster, consistent, and data-driven process that stays current with new regulations and trends.
      • Report a GRC issue AI agent -- The report a GRC issue AI agent enables employees to report GRC issues through the Employee Center using a guided, conversational experience. It organizes the information provided by the user, facilitates review, suggests relevant details, and streamlines submission, reducing barriers to reporting issues.
      • Case summarization for compliance cases -- The GRC case summarization skill uses a large language model (LLM) to generate a structured AI summary of a compliance case record. The summary is generated on demand from case data and can be saved to the record for future reference.
      • Supporting information -- Get a quick overview of the important information that is related to the Now Assist for Integrated Risk Management (IRM) application.
    • Configure -- If you have the admin role, you can configure Now Assist for IRM so that your agents can use the generative AI skills in the IRM workspace.
      • Activate skills -- Activate a skill before you can use the generative AI capabilities for the Now Assist for Integrated Risk Management (IRM) application.
      • Activate the rationalization skill for control objective -- Activate and then configure the recommendation for a similar control objective skill under rationalization from Now Assist to generate recommendation which are similar to the selected control objective.
      • Activate common control objective creation skill -- When activating the common control objective creation skill, the system uses generative AI to analyze the accepted duplicate control objectives and to generate a common control objective.
      • Activate Control Objective Impact Analyzer -- Enable the Control Objective Impact Analyzer skill from Now Assist Skills page. When this skill is activated, the system uses Generative AI to identify control objectives that should be updated based on the modified citation details.
      • Activate the Control Objective Change Agent -- Enable the Control Objective Change Agent in AI Agent Studio to automate compliance workflows using generative AI.
      • Activate regulatory alert summarization skill -- Activate and then configure the summarization skill from Now Assist to generate a brief summary of a regulatory alert by selecting the specific fields you would like included in the summary.
      • Choose input data form -- The Choose input data form for the Regulatory alert summarization skill defines how data is structured and transmitted to the LLM, helping ensure integrity and relevance. It uses rule-based input templates and related taxonomy tables to provide contextual information for Default and New states.
      • Activate regulatory alert recommendation skills -- Configure the recommendation skill from Now Assist to generate the recommendations of the impacted areas for a regulatory alert.
      • Customize a skill -- If you have the admin role, you can customize a Now Assist for Integrated Risk Management (IRM) skill so that agents can use the generative AI skills in Service Operations Workspace for Now Assist for IRM and in Core UI.
      • Customize Issue summarization skill -- If you have the admin role, you can customize the issue summarization skill so that users can use the generative AI skills in Risk Workspace and in Core UI.
      • Activate agentic workflows -- You must activate agentic workflows that contain a set of LLM instructions with one or more AI agents to execute tasks.
      • Activate the get regulatory analysis agentic workflow -- Configure and activate the get regulatory analysis agentic workflow that uses AI agents to enrich regulatory alerts with external context, classification, summarization, and recommended potential impacted items.
      • Activate the generate regulatory action plan agentic workflow -- Configure and activate the generate regulatory action plan agentic workflow. This workflow uses AI agents to transform regulatory insights into actionable compliance strategies by analyzing impacted areas and historical alerts, then generating structured tasks with clear ownership and timelines.
      • Activate the Report a GRC issue AI agent -- Configure and activate the report a GRC issue AI agent to guide employees in reporting GRC issues from the Employee Center with clarity and context.
      • Post activation indexing and customization -- After activating the report for a GRC issue AI agent, the system performs indexing to ensure optimal functionality. Users can also choose to customize the issue definition, enabling the AI agent to provide more tailored suggestions and align with organizational standards.
      • Activate GRC case summarization -- Activate the GRC case summarization skill from the Now Assist Admin console to generate AI-powered summaries of privacy and compliance case records.
      • Case summarization configuration fields -- Review the skill details on each configuration tab before activating the GRC case summarization skill. Even after activation, these fields can be edited to refine the AI-generated summary.
    • Use agentic AI -- Use agents within an agentic workflow or as standalone agents to achieve specific automated outcomes.
      • Agentic workflows in Risk & Sustainability -- Use the Integrated Risk Management AI agent collection to help complete tasks autonomously.
      • Optimize issue resolution -- Optimize a GRC issue resolution plan by using the Optimize GRC issue resolution agentic workflow in the Now Assist panel. This agentic workflow generates an action plan for the issue and suggests remediation tasks to resolve the issue.
      • Get regulatory analysis -- Analyze and enrich regulatory alerts by using the get regulatory analysis agentic workflow in the Now Assist panel. This agentic workflow uses web search to enhance alert context and recommends potential impacts on citations, policies, and control objectives to support faster and more accurate compliance decisions.
      • Generate regulatory action plans -- Generate regulatory action plans by using the generate regulatory action plan agentic workflow in the Now Assist panel. This agentic workflow analyzes impacted areas and similar historical alerts to create change tasks and action tasks that help implement regulatory change.
      • Suggest potential risks for an entity -- Identify and consolidate risks using the Risk Suggestion AI agent through a conversational assistant. This feature helps streamline risk discovery, eliminate duplicates, and provide a comprehensive list of risks relevant to the entity.
      • AI agents in Now Assist for IRM -- Use AI agents in Governance, Risk, and Compliance to complete IT-related tasks autonomously.
      • Use Control Objective Change Agent to update control objectives -- Use the Control Objective Change Agent to review and update impacted Control Objectives based on latest citation details. Users can interact with the Now Assist panel to review and finalize the updates.
      • Report a GRC issue -- Report GRC issues by using the Report a GRC issue AI agent in Employee Center. The AI agent guides you, structures your input, and suggests relevant controls, entities, and policies before submission.
    • Use generative AI skills -- Use the generative AI skills that are supported by the Now Assist for Integrated Risk Management (IRM) application for quick actions with issues.
      • Summarize an issue -- Summarize an issue by using the Now Assist for Integrated Risk Management (IRM) application. Use a summary to get quick context and awareness about an issue.
      • Generate a regulatory alert summary -- Generate a summary of a new regulatory alert for a quick analysis of the alert using the regulatory alert summarization skill. Summarized alerts help compliance officers, regulatory managers, and legal teams quickly understand the impact of new regulations.
      • Generate recommendations for regulatory alert impacted areas -- Generate recommendations to identify and mark potential impact areas, such as citations, control objectives, controls, and policies for regulatory alerts using the corresponding regulatory alert impacted skill. Recommendations simplify the process of associating impacts and creating action tasks.
      • Act on the recommendations for citations -- Accept recommendations to mark specific business areas as impacted, helping compliance practitioners capture and address relevant regulatory alerts for citations. Dismiss recommendations to filter out irrelevant or unnecessary information.
      • Act on recommendations for control objectives -- Accept recommendations to mark specific business areas as impacted, helping compliance practitioners capture and address relevant regulatory alerts for control objectives. Dismiss recommendations to filter out irrelevant or unnecessary information.
      • Act on recommendations for controls -- Accept AI-generated recommendations in Regulatory Change Management to mark specific business areas as impacted so that you can help compliance practitioners capture and address the relevant regulatory alert for controls. You can also dismiss recommendations to filter out irrelevant or unnecessary information.
      • Act on recommendations for policies -- Accept AI-generated recommendations in Regulatory Change Management to mark specific business areas as impacted so that you can help compliance practitioners capture and address the relevant regulatory alert for policies. You can also dismiss recommendations to filter out irrelevant or unnecessary information.
      • Add impacted areas manually to a regulatory alert -- Add impacted areas such as citations, control objectives, policies, and more to your regulatory alerts. Adding impacted areas to a regulatory alert captures additional impacts that you identified and impacts that weren’t initially recommended.
      • Generate a risk event summary in the classic UI -- Generate a risk event summary using the Now Assist for IRM application. The approvers get the key insights to understand the context quickly, and reduce the time involved in creating summaries manually.
      • Generate a risk event summary in the Risk Workspace -- Generate a risk event summary using the Now Assist for IRM application in the Risk Workspace. The approvers get the key insights to understand the context quickly, and reduce the time involved in creating summaries manually.
      • Generate a risk assessment summary -- Generate a risk assessment summary that is based on your inherent risks, residual risks, target risks, and control effectiveness data by using the Now Assist for IRM application. Your approvers get the key insights to understand the context quickly, and you reduce the time involved in creating summaries manually.
      • Generate recommendation for similar control objective -- Generate recommendations by identifying, deduplicating, and rationalizing similar control objectives within the compliance library. This enables identification of redundant control objectives, making it easier to maintain a clean and efficient compliance library.
      • Act on the recommendations -- Act on the recommendations by identifying, deduplicating, and rationalizing similar control objectives within the compliance library.
      • Review actions taken on rationalization process -- After acting on the recommendations, such as accepting as duplicate, retaining as primary, or dismissing during the rationalization process, the owner sends them for review to the configured reviewers. The reviewers then analyze the actions taken and either approve or reject them, providing proper justification for their decisions.
      • Use Control Objective Impact Analyzer skill to identify control objectives -- Identify and manage control objectives impacted by latest citation updates by using the Control Objective Impact Analyzer generative AI skill.
      • Summarize a compliance case -- Use the GRC case summarization skill to generate an AI summary of a compliance case. The summary provides a consolidated view of a compliance case record.
    • Assignment Configurator for non-regulatory alerts -- Assignment rules help in automating organization’s task records such as action tasks, and non-task records such as issues, incidents, regulatory alerts, and so on.
    • Configure assignments -- Assignment configuration rules help in automating organization’s task records such as action tasks, and non-task records such as issues, incidents, regulatory alerts, etc.
    • Regulatory Agency Library -- Regulatory Agency Library is a new application available in the ServiceNow Store for download and activation.
    • Download and activate plugin -- You can activate the GRC: Regulatory Agency Library application if you have the admin role. This application includes demo data and provides you access to regulatory body profiles.
    • Add a regulatory agency -- Add a regulatory agency in Compliance Workspace to identify the relevant regulatory authorities that are responsible for overseeing the industries or sectors within each jurisdiction.
      • Create New Agency form -- Use the Create New Agency form in Compliance Workspace to create a regulatory agency. The regulatory agency is a new record type that handles regulatory changes or compliance case management.
    • Add a regulatory contact to an agency -- Add a regulatory contact to a specific regulatory agency or within a jurisdiction in Compliance Workspace. By mapping a regulatory contact to a specific agency, this contact is notified about your case reporting, case audit, and case closures as they occur.
      • Create New Regulatory Contact form -- Use the Create New Regulatory Contact form in Compliance Workspace to create a regulatory contact to either a regulatory agency or a jurisdiction.
    • Add a jurisdiction to an agency -- Add a jurisdiction to a regulatory agency in Compliance Workspace to define the geographical scope for regulatory applicability.
    • Add an authority document to an agency -- Add an authority document to a regulatory agency in Compliance Workspace to maintain traceability between regulations and their source documents.
    • Compose and send an email -- Compose and send an email about a regulatory agency record to multiple stakeholders within or outside your organization by using the Compliance Workspace.
    • Recommendation contexts and templates -- By using the Governance, Risk, and Compliance recommendations framework, you can use recommendation contexts and templates to deliver AI-driven insights directly to your users within the user interface. With these insights, your users can make informed decisions and take prompt actions.
    • User roles -- Users with different roles can read, create, or edit recommendation contexts for a regulatory alert.
    • Extension points -- Use extension points to extend the functionality of an application without altering the original application code. Recommendation contexts use extension points to enable additional functionality while configuring the recommendation contexts or templates.
    • Create a recommendation context -- Create a recommendation context to define a configuration that builds a template for recommending relevant records.
    • Create a recommendation template -- Create a recommendation template to train the AI models with a data set for identifying your key business operations. Key business operations include managing regulatory changes, assessing risks, and adhering to compliance guidelines.
    • Mobile experience for GRC -- Manage your work, task assignments, requests, approvals, and other follow-up actions for GRC applications directly from your mobile device. Receive timely notifications for current alerts, as well as risk and compliance status for your critical assets, vendors, and impacted essential business services.
    • GRC notification redirection -- When you receive notifications for GRC records, you're directed to either the workspace view or classic view based on your access permissions and role. This feature enables you to work directly in the appropriate interface without manual navigation.
    • Configure -- Create notification routing rules that automatically direct users to workspace view or classic view based on their access permissions.
    • Modify email notifications -- Update email notifications to use the notification redirection framework so users are automatically directed to the appropriate view based on their workspace access.
    • GRC application nomenclature -- The following terms are used within GRC applications and/or within the GRC industry.
    • GRC content packs -- Content packs may include pre-defined scopes, specific policies, controls, risks, audit, test plans, dashboards, and reports that provides customers an operational head-start when adopting various regulations and frameworks.
    • SOX content pack -- The Sarbanes-Oxley (SOX) Content Pack provides basic SOX content for an organization to commence and manage activities towards attaining operational SOX compliance using the ServiceNow GRC application. A content pack may include pre-defined scope, specific policies, controls, risks, audit, test plans, dashboards, and reports providing users of ServiceNow GRC a head-start in using the applications towards SOX compliance-related activities.
      • Install -- Install the SOX Content Pack for use with the core GRC applications.
      • Verify in Policy and Compliance Management -- After importing the SOX Content Pack, verify and edit the profile types, profiles, policies, policy statements, controls, policies, indicator templates, and indicators, within the Policy and Compliance Management application.
      • Verify in Risk Management -- After importing the SOX Content Pack, verify and edit the entity types, entities, risk statements, risks, and assessments within the Risk Management application.
      • Verify in Audit Management -- After importing the SOX Content Pack, verify and edit the entity types, entities, audit engagements, audit tasks, test templates, and test plans within the Audit Management application.
      • Dashboard and reports -- The SOX Content Pack dashboards display multiple SOX reports on a single screen. Various GRC roles have read or edit access to these dashboards.
    • GRC integrations -- Integrations enhance the ServiceNow GRC product offering, providing users the ability to integrate with third-party applications.
    • Integration with Thomson Reuters Regulatory Intelligence (TRRI) -- The ServiceNow Regulatory Change Management application helps you to gather, monitor, and analyze regulatory data and track developments in a complex regulatory environment.
      • Install application -- Install the GRC integration with Thomson Reuters Regulatory Intelligence application (com.sn_grc_int_tr). The application includes demo data. It installs related ServiceNow Store applications and plugins if they are not already installed.
      • Establish an SFTP or REST API connection -- Establish an SFTP or REST API connection for the GRC integration with Thomson Reuters Regulatory Intelligence application. You can create an SFTP or REST API connection with the SFTP server by using the Connection & Credential aliases that are shipped with the Thomson Reuters platform.
      • Modules in Thomson Reuters Regulatory Intelligence (TRRI) -- The GRC integration with Thomson Reuters Regulatory Intelligence application includes various modules.
    • GRC: integrations with third-party content -- The GRC: integrations with third-party content application helps you to standardize the content integration process across various GRC applications by providing a common framework for your content providers.
      • User roles for the integration process -- You must assign the user roles that are required for the overall integration process that is associated with the GRC: integrations with third-party content and GRC: Policy and Compliance integrator applications.
      • Create a user -- Create a user with the sn_grc_cim.admin role to perform the tasks that are related to the content integration and import process.
    • Standardized Information Gathering (SIG) Questionnaire Integration -- The Shared Assessments Standardized Information Gathering Questionnaire (SIG) is used to obtain required assessment documentation from a third party. The third party contact can upload a pre-filled SIG spreadsheet or take a form-based questionnaire that gets imported to the instance.
      • Install -- The GRC: SIG Questionnaire Integration plugin installs the SIG questionnaire templates for use with the GRC: Third-party Risk Management application.
      • Verify in Third-party Risk Management -- After installing SIG Questionnaire Integration, verify that the SIG questionnaire templates are available within the Third-party Risk Management application.
    • GRC use case accelerators -- Use case accelerators may include pre-defined scopes, specific policies, controls, risks, audit, test plans, dashboards, and reports that provides customers an operational head-start when adopting various regulations and frameworks.
    • Cyber Risk Institute accelerator -- The Cyber Risk Institute (CRI) is focused to collaborate with the financial sectors and regulators to streamline standardization across risk management. For better cyber compliance management, CRI provides a CRI Profile with the financial sector consensus.
    • Cybersecurity Controls Accelerator -- The Cybersecurity Controls Accelerator enables users to easily adopt the CIS Controls from The Center for internet Security to enhance their overall security preparedness and cyber-defense posture.
      • Download -- The Cybersecurity Controls Accelerator enables users to easily adopt the CIS Controls from The Center for internet Security to enhance their overall security preparedness and cyber-defense posture.
      • Monitor cybersecurity controls -- The Cybersecurity Controls Accelerator enables users to easily adopt the CIS Controls from The Center for internet Security to enhance their overall security preparedness and cyber-defense posture.
      • UCF controls mapped to indicator templates -- The Cybersecurity Controls Accelerator enables users to easily adopt the CIS Controls from The Center for internet Security to enhance their overall security preparedness and cyber-defense posture.
    • Financial Services Control accelerator -- The Financial Services Control Accelerator gives customers an operational head-start when adopting the Financial Services Control. When the accelerator is downloaded and activated in the GRC applications, pre-configured authority documents, citations, and control objectives.
    • NIST CSF Use Case Accelerator -- The NIST CSF Use Case Accelerator gives customers an operational head-start when adopting the NIST CSF. When the accelerator is downloaded and activated in the GRC applications, pre-configured policies, scopes (profiles, profile type recommendations), indicators, risks, and other GRC elements appear.
      • Install -- The NIST Cybersecurity Framework (CSF) Use Case Accelerator is used with the GRC core applications: Policy and Compliance Management, Risk Management, and Audit Management applications.
      • Verify -- After installing the GRC: NIST Cybersecurity Framework (CSF) Use Case Accelerator, review the NIST CSF application structure, core content, and demo data, if selected during installation.
      • Supporting concepts -- Familiarize yourself with these concepts, developed from the NIST CSF guidance.
      • Tables -- A few tables are impacted by the NIST CSF guidance.
      • Dashboards and reports -- The contains various reports. The NIST Cybersecurity Framework (CSF) Use Case Accelerator contains a variety of reports displayed on different dashboards, available within each of the sections in the NIST CSF process:
      • Process overview -- The NIST CSF navigation structure facilitates the management of the NIST cybersecurity through activities of identification and prioritization, as described in the NIST Framework for Improving Critical Infrastructure Cybersecurity version 1.1 and version 2.0 special publications.
      • Identify the core framework -- Within the NIST CSF application, the Framework Core section is used to identify categories and subcategories as cybersecurity policies and their statement policies.
      • Align and prioritize cybersecurity activities -- Within the NIST CSF application, the Framework Profiling section is used to help an organization to align and prioritize its cybersecurity activities with its requirements, risk tolerances, and resources.
        • Generate a target for an entity -- Generate a target record for an entity to track NIST CSF attributes for that entity.
        • Set up target for NIST CSF framework -- Set up a target record to use with NIST CSF framework after you've identified a target.
        • Orient target -- After you've identified a target, orient the target to use with the NIST CSF framework.
        • Create activity -- Create a cybersecurity activity for a target.
        • Perform gap analysis -- Perform a Gap analysis of cybersecurity activities.
        • Review action plan -- Review the remediation tasks created for the controls or risks associated with cybersecurity activities. You can only edit or update action plans if you have sufficient privileges for the GRC suite.
    • NIST RMF Use Case Accelerator -- The NIST RMF Use Case Accelerator gives customers an operational head-start when adopting the NIST RMF. When the accelerator is downloaded and activated in the GRC applications, pre-configured policies, scopes (profile, profile type recommendations), indicators, risks and other GRC elements appear.
      • Install -- The NIST RMF Use Case Accelerator is used with the GRC core applications: Policy and Compliance Management, Risk Management, and Audit Management applications.
      • Verify -- After installing the GRC: NIST RMF Use Case Accelerator, review the NIST RMF application structure, core content, and demo data, if selected during installation.
      • Supporting concepts -- Familiarize yourself with these concepts, developed from the NIST RMF guidance.
      • Dashboards and reports -- The NIST RMF Use Case Accelerator contains various reports displayed on different dashboards, available within each of the sections in the NIST RMF process: Categorize, Select, Implement, Assess, Authorize, and Monitor.
      • Process overview -- The NIST RMF navigation structure facilitates the management of the NIST security controls through activities of categorization, selection, implementation, assessment, authorization, and monitoring. These security controls are described in the NIST 800-37.r1 special publication.
      • Categorize targets -- Within the NIST RMF application, the Categorize section facilitates the categorization of targets through a preliminary risk assessment and an impact analysis.
      • Select baseline control definitions -- Within the NIST RMF application, the Select section focuses on the review of the initial set of baseline control definitions. You can also tailor the control definitions, by tagging them based on organizational requirements.
      • Implement security controls -- Within the NIST RMF application, the Implement section focuses on the physical implementation of the baseline security controls. The NIST RMF application may also include other standard security controls, already used by the targets or its environment of operation.
        • Manage and implement controls -- From a list of security controls stemming from NIST 800-53.r4 policy statements, review the controls and update implementation details.
        • Manage and implement control tests -- From a list of security controls stemming from NIST 800-53.r4 policy statements, review the control tests and update implementation details.
      • Assess controls, risks, issues, and remediation tasks -- Within the NIST RMF application, the Assess section involves performing security control attestations, evaluating the control effectiveness, managing associated risks and issues, and performing remediation tasks.
      • Authorize targets -- Within the NIST RMF application, the Authorize section involves the authorization of targets based on their compliance and risk posture.
      • Monitor security controls -- Within the NIST RMF application, the Monitor section involves the on-going monitoring of the security controls for targets documenting changes to them or their environments of operation, conducting security impact analyses of the associated changes, and reporting their security state to designated officials.
    • Technology Controls Monitoring Accelerator -- The Technology Controls Monitoring Accelerator is a collection of pre-defined indicator templates designed to ease collection of data, and aid validation and continuous monitoring of technology controls. This application can be run with the Cybersecurity Controls Accelerator or as a standalone application.
      • Download -- Before you run the Technology Controls Monitoring Accelerator application in your instance, you must download it from the ServiceNow Store.
      • Ensure all appropriate indicator templates are activated -- When you download the GRC: Technology Controls Monitoring Accelerator application, all indicator templates are available, but they are not yet active. Before activating them, you need to ensure that you have the necessary applications activated and can access the tables that are mapped to the indicator templates.
      • View your operational status -- View the Operational Status modules for a list of the CIS Controls and technology Controls. Each control also includes the technology used to validate compliance, type of indicator template available, and the control's source table.
      • View the Cybersecurity Controls module -- View the Cybersecurity Controls module for a list of the Authority documents, Controls, Control Objectives, and CIS Indicator Templates mapped to specific CIS controls classified by domain, implementation group, and ISO controls.
      • Use indicator templates -- Indicators collect data to monitor a single control or risk. Indicator templates allow you to create multiple indicators for similar controls or risks. The Technology Controls Monitoring Accelerator application provides a collection of 171 predefined indicator templates for monitoring cybersecurity controls.
      • Indicator templates for controls -- The Technology Controls Monitoring Accelerator includes 273 indicator templates (94 Basic, 174 Manual, and 5 Scripted) for CIS v7 and includes new 67 indicator templates (64 Basic and 3 Scripted) for CIS v8.
    • 360° Relationship Visualization -- The 360° Relationship Visualization application allows you to visually explore the relationships between the different types of critical data that affect your business, such as controls, risks, and issues. The visualization also facilitates quick actions upon the information, such as adding a relationship, closing an issue, or approving a policy exception.
    • Download and activate -- Before you can run the GRC: 360º Relationship Visualization (com.servicenow_sn_grc_360_degree_visualization) and Data Registry (com.sn_app_grc_data_registry) applications in your instance, you must download them from the ServiceNow Store.
    • Set up -- To effectively use the 360° Relationship Visualization application, you need to register existing relationships between the types of data you want to view, and then configure how the 360º view displays that data.
      • Register 360º relationships -- To effectively use the 360° Relationship Visualization application, you need to register existing relationships between the types of data you want to view, and then configure how the 360º view displays that data.
      • Examples of 360º relationship -- To effectively use the 360° Relationship Visualization application, you need to register existing relationships between the types of data you want to view, and then configure how the 360º view displays that data.
      • Configure 360º views -- To effectively use the 360° Relationship Visualization application, you need to register existing relationships between the types of data you want to view, and then configure how the 360º view displays that data.
    • Explore -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
      • Launch -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
      • Drill-down -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
      • Navigate using breadcrumbs -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
      • Select different 360º views -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
      • Enhancements -- After you have successfully set up your data registries for the tables you use, you can use the 360º view feature to view the relationships between a selected record and related objects, such as controls, risks, and entity types.
    • Tag records with functional domain -- Functional domain tagging is a mechanism that allows you to classify risk records based on the specific business function, process, or use case they support. A functional domain represents a logical grouping, such as Cybersecurity and risk, IT risk and compliance, Compliance, Third-Party Risk, or Operational Risk.
    • Functional domain bulk update -- The functional domain feature enables users to efficiently filter and sort records within a workspace based on domain-specific tags. For instance, when working in the Privacy Workspace, users can exclude records that are not tagged with privacy, allowing for a more focused view and reducing potential confusion.
    • Bulk update functional domain for multiple records -- Update the functional domain for multiple records at once to save time and ensure efficiency.
    • Use the item generation process -- The ServiceNow GRC suite of applications can automatically generate controls and risks for your organization with the enhanced item generation process. The enhanced item generation process (v2) in version 13.x.x fixes the stalling and performance issues from the item generation process (v1) in version 12.x.x and earlier releases.
    • Components installed -- Several types of components are installed with the item generation process, including tables, scheduled jobs, and action handlers.
    • Operational changes of common controls -- Operational changes are made in item generation mainly because item generation either creates a control or activates an existing standard control. When it comes to associating a control to an entity, then associating a reliant entity to a common control takes precedence over creating a control for that entity.
    • Use Approver Configurator for setting up approvals for setting up approvals -- The GRC: Approver Configurator application provides you with capabilities to define multiple levels of approvals based on the business assignment rule configurations.
    • Set up an approval configuration record -- Set up an approval configuration record to enable multiple levels of approvals and select approvers for each level based on approval rules.
    • Assign an approval level -- Assign one or more approval levels for the approval configuration record to support each step of approval.
    • Set up an approval rule -- Set up an approval rule for the approval level. You can define the source, filter conditions on the source table to which the approval rule is applied, approver type, and approvers in the record.
    • Base system tables configured with GRC: Approver Configurator -- GRC: Approver Configurator enables you to configure approvals for any record that exists in specific tables.
    • Roles installed with GRC: Approver Configurator -- Various roles are installed with the activation of the GRC: Approver Configurator application.
    • Confidential records -- You can mark sensitive GRC records as confidential. You can then make sure that the right people have access to these records.
    • Create -- Create a record and mark it as confidential so that you can make sure that only the users with a specific role can access it.
    • Configure confidentiality in GRC tables -- You can create a confidentiality configuration record in your GRC tables.
    • Configure confidential inheritance -- You can set up confidentiality inheritance in the tables that are already configured in the confidentiality configuration module. In the GRC application, whenever a parent record is marked or unmarked as confidential, its related table records are also marked or unmarked as confidential.
      • Create confidentiality inheritance -- Create confidentiality inheritance in the tables that are already configured in the confidentiality configuration module. In the GRC application, whenever a parent record is marked or unmarked as confidential, its related table records are also marked or unmarked as confidential, if an inheritance record is also set up.
      • Confidentiality Inheritance Configuration form -- Use the Confidentiality Inheritance Configuration form in the GRC application to create the inheritance configuration record.
    • User hierarchy -- With a user hierarchy, your managers can see the records of those users who report to them.
    • Create a user hierarchy configuration record -- Create a user hierarchy configuration record for a table so that you can enable your managers to view the records of the users who report to them.
    • User group-based access on the GRC tables -- You can allow a set of users to access only specific records by creating user groups on the GRC tables. When you have created the user groups, you can segregate your data based on a specific criteria and allow only those users who belong to a user group to view the data.
    • Content references in GRC -- You can add tags to virtually any type of record defined in GRC applications that reference GRC content packs, integrations, use case accelerators, or any new regulations that use those records. After the records have been tagged, you can filter the content reference tags to identify which records are used within each application.
    • Add content reference tags to records -- You can add tags to virtually any type of record defined in GRC applications that reference GRC content packs, integrations, use case accelerators, or any new regulations that use those records. After the records have been tagged, you can filter the content reference tags to identify which records are used within each application.
    • Create content reference tags -- You can add tags to virtually any type of record defined in GRC applications that reference GRC content packs, integrations, use case accelerators, or any new regulations that use those records. After the records have been tagged, you can filter the content reference tags to identify which records are used within each application.
    • Entity Based Access -- The Entity Based Access (EBA) application enables you to segregate data on the records that are based on entities. Entity-based access administrators can use this tool to set up secure, controlled access to various objects.
    • Sample use case scenarios -- Use case scenarios offer a clear and comprehensive explanation of why you would use the Entity Based Access application.
    • User roles -- Users with specific user roles have access to read or update the Entity Based Access configuration or the bulk access update configuration.
    • Entity based record access update utility -- The entity based record access update utility is a guided assistance, designed to simplify the application of enabling or disabling access restrictions across large volumes of records.
    • Entity-based record access rules -- The entity-based record access rules let admins apply restrictions automatically to new and changed records. This configuration ensures that access settings stay enforced. No manual updates are needed when records are created, modified, or when users are added to user fields or user group fields.
    • Deactivate entity-based access configuration -- Deactivating entity-based access (EBA) not only disables the configuration but also streamlines admin workflows by automating record-level access evaluation.
    • Configure Entity Based Access -- Configure the Entity Based Access application by installing it from the ServiceNow Store and by setting up Entity Based Access properties in the instance.
      • Install -- Install the GRC: Entity Based Access application.
      • Set up properties -- Enable or disable the Entity Based Access properties to control access to the objects that are associated with an entity.
    • Manage Entity Based Access -- You can manage access to the objects or record types in a system by using the Entity Based Access application. You can restrict access by using an entity, entity class, or entity type configuration.
      • Configure access to an entity's related records -- Configure access to an entity for your users or user groups so that they can access the entity's related records.
      • Entity configurations form -- Use the Entity configurations form to configure access to the objects through an entity.
      • Configure an entity class for a linked object -- Configure an entity class for a linked object by using the Entity Based Access application. You can define an entity class, such as Business Process, Business Service, or Database, and manage the object access for the entity that is linked to that entity class.
      • Entity Class Configurations form -- Use the Entity Class Configurations form to set up access control to all the entities that are linked to the entity class.
      • Configure an entity type for a linked object -- Configure an entity type by using the Entity Based Access application. You can specify an entity type, such as Company or Vendors, and manage the object access for the entity that is linked to that entity type.
      • Entity Type Configurations form -- Use the Entity Type Configurations form to create an entity type configuration within the Entity Based Access application.
      • Set access restrictions using an entity based record access update utility -- Set access restrictions for the existing records in bulk by using the Entity based record access update utility guided-experience. Use the workflow to enable or disable access to record types.
      • Configure entity-based record access rules -- Configure entity-based record access rules on record types to apply access restrictions to new records automatically.
      • Deactivate -- Deactivate an entity-based access (EBA) configuration to disable access restrictions from associated records, confirming only active and relevant configurations control data access.
    • Reference -- Entity-based access restriction can be applied on some GRC tables.
    • Manage issues -- You can measure the effectiveness of your company's risk management program by how quickly and completely it identifies and reacts to risk and compliance issues.
    • Issues in the Workspace -- You can track all your issues or one specific issue from the Workspace. Issues are listed under the Issues module in the list view of the Workspace.
      • Configure an issue relationship -- If an issue isn't reusable and you know that multiple similar issues were created for different controls, risk statements, or control objectives, you can still configure the issue relationship to reuse the issue in the GRC application.
      • Steps to configure an issue relationship -- Enable or disable an issue relationship configuration record so that you can automatically link an issue with its related objects in the GRC application.
        • Issue Relationship Configuration form -- Use the Issue Relationship Configuration form in the GRC application to automatically link a destination record with an issue when it’s linked to the source record.
    • Group issues -- Group issues within your workspaces to organize and manage related issues. Grouping similar issues can streamline your workflow and save time.
    • Domain separation in GRC -- This is an overview of domain separation and the Governance, Risk, and Compliance applications. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Create a domain -- You can create a domain by creating a record in the [domain] table.
    • Breadcrumb navigation -- The ServiceNow Australia release supports breadcrumb navigation for all GRC modules including workspaces. Breadcrumbs provide a browser path to navigate a hierarchy of linked pages with related content.
    • Taxonomy management in GRC -- Taxonomy is used to organize, classify, and label the elements of the unstructured content. The content is organized into granular elements that provide more information about the context of the content.
    • Landing Page Configurations module -- GRC administrators can now configure the Tasks and Issues overview landing pages in the workspaces by using the GRC Landing Page Configurations module in the classic user interface. The role required to configure the tasks, issues, and other items in the Landing Page Configurations module is the sn_grc_workspace.task_admin role. GRC administrators are assigned the sn_grc_workspace.task_admin role by default.
    • Tasks Page Configuration module -- The Tasks Page Configuration module in the classic user interface displays the configurations related to the Tasks section in the landing pages of the workspaces. The configurations in the Tasks Page Configuration module help the users to view the data in different workspaces.
    • Update the Tasks Page Configuration record -- Update the Tasks Page Configuration record in the classic user interface to display the task configurations in various workspaces. The Tasks Page Configuration record displays the configurations that an end user can view in the My Tasks landing page in each workspace.
    • Issue Page Configuration module -- The Issue Page Configuration module displays the configurations related to the Issues overview landing pages in various workspaces. The data displayed in the Issues overview landing page is configured using the Issue Page Configurations module in the classic user interface. The Issues overview landing page includes the Issues, Issue triages, Tracking status of the issues, and Audit observations pages.
      • Create a record -- Create a new issue page configuration record in the Issue Page Configuration module in the classic user interface. The Issue Page Configuration module displays the configurations related to the Issues section in the landing pages of the workspaces. The newly created issue is displayed in the Issue overview landing page in the selected workspace.
      • Link a record to a workspace -- Create a new Issue Page Configuration record and link it from the classic user interface to the desired workspace. After linking the Issue Page Configuration record, the workspace view displays the new settings in the Issues overview landing page.
      • Update a record -- Update an existing Issue Page Configurations record in the classic user interface to update the issue page configurations that are displayed in the Issues overview landing page in the workspace. After modifying the configurations in the Issue Page Configuration record, the issues, issue triages, and tracking status of the issues are displayed for the users in the desired workspace.
    • My tasks in the workspace -- GRC administrators can configure the tasks for the individual users and user groups in the GRC Landing Page Configurations module. Based on these configurations, the workspace users can view the individual user tasks, user group tasks, my items, and watchlist on the Tasks page in the workspace view.
    • Monitor my tasks -- Configure and monitor the tasks that are related to an assigned user in the workspace. Configure the landing pages and the widgets that are displayed in the workspaces using the Landing Page Configurations module. The configurations performed using the Landing Page Configurations module help you to filter the data that is displayed in different workspaces.
    • Explore entities -- Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications, or objects that are examined for risks.
    • Entities -- An entity is a person, process, department, application, or other object whose compliance exposure is tracked in GRC. Each entity has an owner, so non-compliant items and their owners can be identified individually.
    • Composite entity -- Composite entity in Governance, Risk, and Compliance is a combination of two or more entities created from different entity classes. The Composite Entity Management application enables you to create multidimensional entities and manage them in a more granular level.
      • Create a composite entity -- Create multidimensional entities by combining two or more entities from different entity classes using the Composite Entity Management application. In Governance, Risk, and Compliance, entities can be people, processes, departments, applications, or objects.
      • Create new composite entity form -- Use the Create New Entity form to create a composite entity by combining two or more entities from different entity classes using the Composite Entity Management application.
    • Entities in workspace view -- The Entity form in the workspace provides a complete view of an entity across your organization. The Entity form is listed under the Library menu of the List view in the workspace. Select an entity in the list view so that you can display its overview, details, hierarchy, entity types, or downstream risks.
      • Create -- Create an entity for your enterprise. In Governance, Risk, and Compliance, entities can be people, processes, departments, applications, or objects. These entities have controls that are defined to mitigate their exposure, and their audits must be completed.
    • Functionality enhancements -- You can configure some functionality enhancements for the entities as part of the GRC updates.
    • Entity scoping -- Entity scoping is permitted in each of the core GRC applications. Scoping provides a way to allocate risks and controls at different levels. Dependencies are created using the dependency map in the GRC Workbench.
      • Generate risks and controls from entity types -- Create and edit entity types and map them to existing ServiceNow tables for which you must track compliance (applications, departments, regions, processes, systems, etc.). Entities are assigned to control objectives and risk statements, which generate controls and risks for every entity type.
      • Create independent entities -- Entities can be created manually, rather than generating them from the entity types. Entities can also be created without needing to refer to an existing ServiceNow table, like assets, applications, business services, or processes.
      • Relate entities -- Create relationships between entities to understand how controls and risks affect each other and how they affect the enterprise.
    • Entity classes -- Entity classes are used to add a conceptual information about the entity or to tag the entity. They are used to classify the entities and they represent a collection of entities that have the same attributes.
      • Create -- Create an entity class that is associated with an entity. Entity classes are used to add a conceptual information about the entity and classify the entities. They represent a collection of entities that have the same attributes such as Department, Business Unit, or Business Service. You can gather data about the entities based on the entity class.
      • Update -- Provide an entity class for multiple entities where the class field is empty. Entity classes are used to add a conceptual information about the entity and classify the entities. As an administrator, you can update the entity classes for multiple entities with a single click.
      • Scheduled jobs -- Scheduled jobs are automated pieces of work that can be performed at a specific time or on a recurring schedule. GRC administrators run the scheduled jobs on demand to automate the tasks such as setting an entity class on the entities depending on the entity class rule.
    • Entity class rules -- Entity class rules help to assign classes to the entities at the table level. Any new entity created on the table gets that entity class automatically. Entity classes are used to tag your entities.
      • Create -- Create a rule for an entity class. Entity class rules provide the classification of the entities at the class level. You can create a new entity class rule for an entity class that is associated with a table. After creating the new entity class rule, the Entity class rules table is updated with the new record.
      • Create an entity class rule filter -- You can create an entity class rule filter to assign classes at the filter level on the same table that is defined on the class rule.
      • Entity class rule filter fields -- You can create an entity class rule filter by filling out the fields that display after you click the New option in the entity class rule filters related list.
    • Entity types -- Entity type is a grouping of the entities that match a set of filter conditions. You can create a hierarchy of the entity types within the entity classes. The Entity types option is displayed under the Lists view in the workspace. Click an entity type to display its details.
      • Create -- Create an entity type for the entities in your system. Entity types enable you to find and create new entities that match a set of filter conditions. You can create a hierarchy of the entity types within the entity classes.
      • Entity filters -- Entity types enable you to find and create entities that match a set of filter conditions. Entity types include predefined entity filters that define the data to be displayed in the user interface. The entity filter defines the table from which data is pulled into each entity type for display.
      • Create -- Create an entity filter under an entity type in the workspace view. Entities in entity type are created based on the conditions set in the Entity Filter. The entity filter defines the table from which data is pulled into each entity type for display.
      • Create an entity filter in the Core UI -- Create an entity filter under an entity type in the classic user interface. The entity filter defines the table from which data is pulled into each entity type for display. If the entities belong to an application, the users who have access to the entity class that is associated with the entity can only view those entities.
    • Entity tiers -- When you create entity tiers, you can apply a level or hierarchy to the entity classes. This level applies to all the entities that are associated with the entity classes. Entity tiers enable you to select and view the status of the most critical items in the business.
      • Create -- Create an entity tier for the entity classes in your organization. When you create entity tiers, you can apply a level or hierarchy to the entity classes. The hierarchy level applies to all the entities associated with the entity classes.
    • View and update exceptions -- Report exceptions as it is critical for businesses to quickly identify and address key business process issues before they become a problem. Using exceptions to manage errors has advantages over traditional error-management techniques.
    • Cybersecurity Executive dashboard -- The Cybersecurity Executive Dashboard gives the Chief Information Security officer a comprehensive overview of the security posture score of an organization. However, the compliance and risk users can use the risk and compliance page to get an all-inclusive picture of all the GRC metrics.
    • Advanced Application Risk dashboard -- The GRC Application Risk and Compliance Overview Dashboard provides the latest view of risk and compliance aspects for the business applications that are used in an enterprise.
    • Licensing summary dashboard -- Use the GRC licensing summary dashboard to track license usage trends and next month's projected usage. You can see the aggregated counts of license consumption across different product families. You can also search for roles to identify their combined GRC license treatment when these roles are assigned to a user.
    • Role hierarchy of a user -- The role hierarchy node map displays the relationship between the license contributing roles for role-based users and provides insights into the licensing treatment of a user.
    • Microsoft Word based audit report templates using Document designer -- The Microsoft Word based audit report is accessible and user-friendly for audit administrators. Even users without technical expertise can easily configure the template to meet their specific needs.
    • Explore audit report templates -- Create and customize audit report templates using a Word template. You can configure this template to match your specific needs. Once the template is set up, it can be applied to one or more audit engagements, automatically generating audit reports in Word format.
    • Configure document templates using Document Designer -- Configure the audit report templates using the ServiceNow Document Designer with Word add-in.
      • Configure templates -- Configure the template to specify the fields from which data must be obtained and displayed on the audit report.
      • Create data relationships -- Create a path to go from a record in the template configuration to any table that you require. When you create these paths, you can get the necessary data from each of these paths in your audit report template.
      • Create content configurations -- Define the data that you want to view or fetch, whether it's a list of records or an aggregation when creating an audit report. For example, specify if you want to see a list of remediation tasks or the list of the top five high priority issues. A maximum of 200 records can be fetched from any table.
      • Configure Data columns -- Configure data columns to choose which fields from the selected table appear in your report. This helps confirm that only relevant information is displayed, making reports clear and actionable.
      • Configure Intermediate filters -- Set up filters for intermediate data relationship nodes based on the selected data relationship in the content configuration. This confirms only relevant information is displayed, making reports clear and actionable.
      • Define the scripted variables -- Define data for the scripted variables using the Template Configurations module for creating a report template in the Audit application. You can configure the data in either text or HTML format.
      • Create an audit report template -- Use the template configurations to create placeholders for an audit report template tailored to your needs.
    • Install the add-in -- Install the ServiceNow Document designer add-in to your Microsoft Word document to create audit and CAM report templates and generate report content using the AI Reporting Assistant.
      • Reference information -- There are several properties that get installed with the Document designer plugin. These properties help to control the various aspects of how the plugin works.
    • Create a business domain -- Create a business domain to define the context in which data is imported into a Microsoft Word document using Document designer.
    • Configure business domain roles for Document designer -- Configure role mappings on a business domain to control which users can select the domain when importing data into a Microsoft Word document.
    • AI reporting assistant -- The AI reporting assistant uses prompts to generate reports from ServiceNow instance data directly in a Microsoft Word document.
    • Workspace page -- A common record page can be used and configured within all the GRC applications.
    • Configure -- You can configure and customize your workspaces so that all the GRC applications have a similar appearance.
    • GRC reference -- Reference topics provide information about tables, roles, and properties installed with the GRC application.
    • Components installed -- Reference topics provide additional information about components that are installed with the activation of the GRC plugin. These components include tables, user roles, and properties.
    • Common roles -- Certain common roles are used in multiple GRC modules.
    • Tables installed -- Tables are added with activation of GRC plugin.
    • GRC properties -- The following are the common GRC properties under Policy and Compliance and Risk Management.
    • Anonymous Reporting Center -- The Anonymous Reporting Center (ARC) enables employees to submit compliance, privacy, or AI‑related concerns without revealing their identity. Employees are automatically signed out of the Employee Center when ARC opens.
    • Submit an anonymous case -- Use Submit a report anonymously on the Anonymous Reporting Center (ARC) landing page to raise suspected compliance, privacy, or AI-related issues confidentially.
    • Follow up on an anonymous report -- Check the status of your case on the Anonymous Reporting Center using the Report key and Report number. You must download a copy of your anonymous report after submitting a case to record these values.