Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Setup checklist for the GRC Audit Management application

This checklist includes the setup tasks that you're required to complete in your ServiceNow AI Platform® instance. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance the Audit Management functionality.

Before you begin

Role required: admin

Consider creating and printing a PDF of this checklist topic. You can then check off tasks as you complete them.

To generate a PDF of this topic, select the download icon at the top of the topic, and then select Save as PDF.

Procedure

  1. Select the Selected topic.

    ItemDescription
Image omitted: checkbox.png
check box.|As an audit administrator or audit manager, create engagements to manage audit information and include entities, controls, and control tests that are relevant to the audit. For details, see [Create an engagement](t_CreateEngagement.md).|
|
Image omitted: checkbox.png
check box.|As an audit administrator or audit manager, after you have created engagements, define which entities are scoped in the audit engagement. For details, see [Add entities to an engagement scope](add-profiles-to-engagement-scope.md).|
|
Image omitted: checkbox.png
check box.|After defining a control, audit managers create control tests that run periodically and provide documented evidence of whether the associated control is operating correctly. For details, see [Create a control test from an engagement](t_CreateControlTest.md). You can also generate control tests automatically. For details, see [Automatically generate control tests from an engagement](automatically-generate-control-test.md)|
|
Image omitted: checkbox.png
check box.|After defining a control, audit managers create activities that explore and provide documented evidence of whether the associated control is operating correctly. For details, see [Create an audit task activity](t_CreateAnActivity.md).|
|
Image omitted: checkbox.png
check box.|After defining a control, audit managers create interviews with control owners to discuss and provide documented evidence of whether the associated control is operating correctly. For details, see [Create an interview](t_CreateAnInterview.md)|
|
Image omitted: checkbox.png
check box.|After defining a control, audit managers create walkthroughs that will be conducted to observe and provide documented evidence of whether the associated control is operating correctly. For details, see [Create a walkthrough](t_CreateAWalkthrough.md).|
|
Image omitted: checkbox.png
check box.|As an audit manager, generate an audit report that summarizes the findings of an engagement so report findings can be communicated to executives. For details, see [Generate an audit report from an engagement](generate-an-audit-report.md)|